Afrikaans
Akan
Albanian
Amharic
Arabic
Armenian
Azerbaijani
Basque
Belarusian
Bemba
Bengali
Bihari
Bosnian
Breton
Bulgarian
Cambodian
Catalan
Cebuano
Cherokee
Chichewa
Chinese (Simplified)
Chinese (Traditional)
Corsican
Croatian
Czech
Danish
Dutch
English
Esperanto
Estonian
Ewe
Faroese
Filipino
Finnish
French
Frisian
Ga
Galician
Georgian
German
Greek
Guarani
Gujarati
Haitian Creole
Hausa
Hawaiian
Hebrew
Hindi
Hmong
Hungarian
Icelandic
Igbo
Indonesian
Interlingua
Irish
Italian
Japanese
Javanese
Kannada
Kazakh
Kinyarwanda
Kirundi
Kongo
Korean
Krio (Sierra Leone)
Kurdish
Kurdish (Soranรฎ)
Kyrgyz
Laothian
Latin
Latvian
Lingala
Lithuanian
Lozi
Luganda
Luo
Luxembourgish
Macedonian
Malagasy
Malay
Malayalam
Maltese
Maori
Marathi
Mauritian Creole
Moldavian
Mongolian
Myanmar (Burmese)
Montenegrin
Nepali
Nigerian Pidgin
Northern Sotho
Norwegian
Norwegian (Nynorsk)
Occitan
Oriya
Oromo
Pashto
Persian
Polish
Portuguese (Brazil)
Punjabi
Quechua
Romanian
Romansh
Runyakitara
Russian
Samoan
Scots Gaelic
Serbian
Serbo-Croatian
Sesotho
Setswana
Seychellois Creole
Shona
Sindhi
Sinhalese
Slovak
Slovenian
Somali
Spanish
Spanish (Latin American)
Sundanese
Swahili
Swedish
Tajik
Tamil
Tatar
Telugu
Thai
Tigrinya
Tonga
Tshiluba
Tumbuka
Turkish
Turkmen
Twi
Uighur
Ukrainian
Urdu
Uzbek
Vietnamese
Welsh
Wolof
Xhosa
Yiddish
Yoruba
Zulu
In the section we're going to take a to the sewage that works where we.
If you want to manage as switch remotely You should try an IP address and default gateway to the Duke's
management IP and default gateway is configured on salvages for remote access.
If you want to assign an IP address to allow you to switch you should assign it to the learn not the
physical interface.
As you can see in a year we are getting into the interface mode by typing interface and the real number
then we're as signing our IP address by using the IP address IP address that we want to configure and
the subnet mask command the default gateway configuration is also pretty straightforward to configure
a default gateway on a switch.
Our command is IP default gateway and the IP address of the default gateway.
Let's go ahead with how to configure switch port now to configure as to which port we should go to the
interface mode by typing interface and the interface name on the coffee mug in the same example we are
defining the speed of the port.
And we are defining a full duplex option for the related interface.
Let's take a look to the configuration now.
The interface names first turn you want as you can see and I'm getting into the interface mode by typing
interface and the name of the interface as you can see as soon as I type the answer as soon as I hit
the enter key I'm anywhere in the config.
F I'm in the conflict interface mode and to define a duplex I'm typing Duplaix and Duplaix speed.
And to define the speed for the port I'm typing the speed and the speed that I want command 12:5 to
switch port configuration we can use show on interface and the interface name as the first option.
This command shows us that configuration of the related interface for example in here we are typing
is show run interface.
Fast Internet 0 1.
And here is the whole covert operation of the first Internet 0 1.
As you can see the second option for verifying switchboard configuration is show IP in the race brief
commands.
This command shows the physical status of the interfaces.
And if this is a layered take to recompile build the switch this command also shows the IP addresses
assigned for the interfaces.
For example as you can see here on each one we are typing is show IP interface brave command and vse.
We can't see the physical state of the ports in here.
And as you can see some ports are in up mode some of them are in administratively down mode and we can
see the IP addresses assigned to switch ports because the this layer to recap able to switch.
The third option to verify the switch port configuration is the show interfaces and the interface interface
name command.
This command shows the physical status of the interface such as if this is up or down or something like
that.
And this command also shows some useful information such as NTEU bandwidth delay.
If we have some input errors or not or if we have some secrecies or something like that we can monitor
all of them.
This command Let's take a look at the series security now as we talk before we should we always use
S-sh instead of talent because S-sh and creep's the WHO Conexion to configure the S-sh as a remote connection
portico on asswage or Commandery s crypto key generate RSA general keys models and 1024.
But first we should create a domain name to activate S-sh on our DeWyze.
Here is the domain name configuration IP domain name and we are typing air arbitrary domain name then
to generate the crypto keys we are typing the crypto key generate RSA general keys models and the key
more than the size which is 1024 bits for this example.
Let's take a look to the local arena work ethic to attract types.
Now we do have security measures and controls in place your network might be subject to an attack.
Some attacks are passive meaning information is monitored.
Others are active meaning the information is altered with intent to corrupt or destroy the data or the
network itself.
You're not of works and data are Wooler built to any of the following types of attacks such as Mac faluting
the ACP spoofing Talmud ethics and the CPA attacks.
If you do not have a security plan in place you may face with all of these attack sites.
Let's start with the Mac fluting for us in computer networking emic fluting is a technique employed
to compromise the security of networks to which they attack works by forcing it they get made to make
table contents out of the switch and forcing a unicast flooding the area or potentially sending sensitive
information of portions of the network where it is not normally intended to go sewage maintain a make
table that maps individual Neka addresses on the network to the physical ports on the switch as you
know and this ellos the switch to direct data out of physical port where the recipient is located as
opposed to indiscriminately broadcasting the data out all of its ports as an Internet hub does either
type Mac fooling attack and switch is fed many Ethernet frames each containing different source make
addresses by the attacker.
The intention is to consume the limited memory set aside in the switch to store the Mac address table.
As you can see in here we are an attacker and our attacker Fluke's can table it frames with numerous
and Blitzers make addresses and will hosts cannot create scam entries anymore.
Then in the second step normal traffic is flooded out all of its ports because no Kim into his existe
for the well-led horses.
Let's take a look to the JCP spoofing.
Now this this is a special kind of attack where attackers can gain access to network traffic by spoofing
responses that would miss them by.
Well it did C-p server collect PCs sending DCP requests on the network.
This request is broadcast and all hosts on the local area network will receive it.
As you know guys already DHC server knows what this request means actually.
And in the normal situation only the real delayed sleep is chervil will replied that request DCP So
is there replied the client with a message that will configure the host client PC with IP address subnet
mask and the default gateway when we Ebtekar PC in the network.
He will simulate the ATP server on his host PC with this action.
He will be able to reply to the DCP request before the real day is over because it's closer to the client
husked it will configure the client host with IP address of that subnet but it will also give to host
false default gateway address and maybe even false DNS server address DNS server and default gateway
address will both be IP address of attacking attackers.
Computers in this manner he will point out all the communication of the client host to himself.
Later he will make it possible to forward friends from class host to real destinations in order to make
communication of client possible.
Clients will not know that his communication is always going to Ebtekar PC and that attacker can easily
sniff friends.
To mitigate this attack we can use the HCB snooping method which we are going to see on our later slides.
And let's go ahead with the telnet issues.
We talked a lot of about this thing as you know and as we talked before tell that is an unsecure remote
connection protocol because it does not encrypted communication tell it can also be used as a part of
the didoes attacks and because of this we should always use S-sh instead of telnet.
And let's go with how we can secure our So which parts to secure our suites ports which means their
interfaces.
We have three options.
First we should shut down our Onias ports.
Second we should use DHC snooping.
And third we should use port security
if we are not using a physical port.
We should always shut down it manually because of mitigating the physical layer attacks unused ports
always must be kept shut on.
So to configure manual shutdown we are getting into the interface mode again.
Interface and the interface name that we want to shut down and the command is pretty straightforward
we're using shut down command and we are shut down and administratively shut down the port and let's
go ahead with the SEP snooping in computer networking.
Snooping is a series of techniques like to improve the security of the sleepy infrastructure when the
servers are allocating IP addresses to the clients on the local area network disappeared snooping can
be configured on a local area network so it's to prevent malicious or malformed DHC traffic or road
did C-p service in additional information on a horse which have successfully completed the DCP transaction
is reeled in a database of bindings which made them be used by other security or accounting features.
So let's go ahead how we can configure it DHC snooping.
Now to call here at DGP snooping we're getting into the coffee more than first we're global enabling
the snooping by typing IP DCP snooping command.
The second thing we are going to do is we're tapping IP diciples snooping Melanne and we're defining
the real numbers.
Then we are going to use for the database snooping in the third step.
We are enabling DGP auction 18:3 by typing.
I did see this snooping information option then we're defining the number of acceptable DCP packet per
second force which ports by typing IP the snooping limit rate and the rate that we want.
Then in the last step we're defining the seeping through us to port IP the city snooping.
Trust is the comment that we are using for this.
Please keep in mind that for transports and DCP So we're ports.
We should define these command.
Let's go ahead with the port security now.
You can use port security feature to restrict input to an interface by limiting and identifying the
make up addresses of the workstations that are allowed to access port.
If airport is configured as a secure port and the maximum number of secure Miracle-Gro aggressors is
reached when the Mac address of every workstation attempting to access to the port is different from
any identified secure MAC addresses and securely elation or cures.
And we have three violation modes and they are shut down protect and restrict.
So as they go to the port security in our slide now or at any year we ever switch port and we have a
hop connect to to this.
So which part as you get seen here in the hub we have two pieces and they are p.s. one and PC two which
means we have to make calderas this behind the hour.
So which part are if we define port security for this part of the switch and if we go every year in
the year we put security of maximum mix of three for example.
And if I plug a PC which is PC 3 and more PC which is PC for that means airport security while lation
as I told you we have three ports they killed the Welshman's and they are shut down.
Pro-sex and restraint in shut down but we're blocking all traffic and placed the port into errored disable
mode.
We are shut down and our ports are switch port.
If a violation occurs in the project we are blocking the traffic who makes the wireless.
And we are allowing our other means for example in here.
We are just looking through traffic of the PC for.
But PC one two and three is to can go hat and in the restrict month we are booking through every room
makes the world Asian and EHLO either.
And this time we are also creating a log message to configure Iris port security.
We're getting into the interface more by typing interface and the name of the interface then we're typing
switchboard.
Port security and enabling the port security now but as you can see in here command is rejected because
Frist is zero one is a dynamic port which means we need to type we need to define air access we want
for the switch port that we need to configure the port security because of this when we are typing switchboard.
More access then we're typing the switchboard.
Port security command after switchboard port secure the maximum and we're defining the maximum MAC addresses
that can be learned from that.
So each port l the last step we are typing switchboard port security to whale Asian and we are defending
the violation more which is.
For this example airport security will wishing can make airport to and error or disable Maut ports must
be read to it by using shut down and the nose shut down commands after the device is removed.
To me each makes the way election we can't use the show interfaces.
There is an air disabled command to monitor the disabled ports.
For example let's say that first 0 1 got into the area disabled mode to react to it.
This port we are getting into the conflict if more by typing interface faster 0 1 and we're typing shut
down first then we need to type no shut down to activate it.
Can't find what you're looking for?
Get subtitles in any language from opensubtitles.com, and translate them here.