Mittwoch, 13. Juli 2011
Dienstag, 12. Juli 2011
INE WB Vol1 - 8.31 Anycast RP
Lab it up again on a small scenario
msdp originator-id should be set to unique peering loopbacks not the Anycast RP Loopback !
msdp originator-id should be set to unique peering loopbacks not the Anycast RP Loopback !
Montag, 11. Juli 2011
Sonntag, 10. Juli 2011
INE WB Vol2 - Configuration Lab 1
1. Layer 2
1.1 Layer 2 Features - 0 Points
- missed VLAN on removal
- PrivateVLANs not possible on 3550
2. IGP
2.1 OSPF - 0 Points
- missed virtual link
- missed hello multiplier (speed convergence)
- missed non-broadcast neighborship for security
2.2 IGP Features - 3 Points
2.3 BGP Bestpath Selection - 4 Points
3. IPv6
3.1 IPv6 Addressing - 4 Points
3.2. IPv6 Multicast Basics - 0 Points
- R4/R5 RP/BSR mixed-up (DAMN!)
4. MPLS VPN
4.1 LDP - 3 points
4.2 VPN - 3 points
5. IP Multicast
5.1 RP Assignment - 2 Points
5.2 Multicast Testing - 3 Points
5.3 Multicast Filtering - 0 Points
- used ip multicast boundary 1 instead of ip igmp access-group 1
6. Security
6.1 Denial of Service Tracking - 3 Points
6.2 Spoof Prevention - 2 Points
6.3 Information leaking - 0 Points
- used only unreachables not mask-reply
6.4 Control Plane Protection - 0 Points
- used a control plane policy :( instead of simple ACLs
7. Network Services
7.1 RMON - 3 Points
7.2 NTP - 2 Points
7.3 NTP Authentication 3 Points
7.4 Traffic Accounting - 3 Points
7.5 Gateway Redundancy - 3 Points
7.6 Network Address Translation - 3 Points
7.7 Embedded Event Management - 0 Points
- had absolutely no clue
8. QoS
8.1 Frame Relay Traffic Shaping - 0 Points
- had no real clue
8.2 Rate Limiting - 0 Points
- made it with rate-limit not with a policy-map
8.3 CBWFQ - 0 Points
- service-policy on physical interface not on DLCIs
8.4. Catalyst QoS - 0 Points
- no clue
(Full 79/Pass 64/My 44)
1.1 Layer 2 Features - 0 Points
- missed VLAN on removal
- PrivateVLANs not possible on 3550
2. IGP
2.1 OSPF - 0 Points
- missed virtual link
- missed hello multiplier (speed convergence)
- missed non-broadcast neighborship for security
2.2 IGP Features - 3 Points
2.3 BGP Bestpath Selection - 4 Points
3. IPv6
3.1 IPv6 Addressing - 4 Points
3.2. IPv6 Multicast Basics - 0 Points
- R4/R5 RP/BSR mixed-up (DAMN!)
4. MPLS VPN
4.1 LDP - 3 points
4.2 VPN - 3 points
5. IP Multicast
5.1 RP Assignment - 2 Points
5.2 Multicast Testing - 3 Points
5.3 Multicast Filtering - 0 Points
- used ip multicast boundary 1 instead of ip igmp access-group 1
6. Security
6.1 Denial of Service Tracking - 3 Points
6.2 Spoof Prevention - 2 Points
6.3 Information leaking - 0 Points
- used only unreachables not mask-reply
6.4 Control Plane Protection - 0 Points
- used a control plane policy :( instead of simple ACLs
7. Network Services
7.1 RMON - 3 Points
7.2 NTP - 2 Points
7.3 NTP Authentication 3 Points
7.4 Traffic Accounting - 3 Points
7.5 Gateway Redundancy - 3 Points
7.6 Network Address Translation - 3 Points
7.7 Embedded Event Management - 0 Points
- had absolutely no clue
8. QoS
8.1 Frame Relay Traffic Shaping - 0 Points
- had no real clue
8.2 Rate Limiting - 0 Points
- made it with rate-limit not with a policy-map
8.3 CBWFQ - 0 Points
- service-policy on physical interface not on DLCIs
8.4. Catalyst QoS - 0 Points
- no clue
(Full 79/Pass 64/My 44)
INE WB Vol2 - Troubleshooting Lab 1
TS1.1) 2p nni->dce
TS1.2) 2p next-hopf-self
TS1.3) 3p wrong static def.global
TS1.4) - RIP
TS1.5) 2p ospf-dead-interval
TS1.6) - WCCP
TS1.7) 2p ip rip send version 1 -> 2
TS1.8) 2p database-filter
TS1.9) - http authentication local
TS1.10) 2p drop / control-plane
----------------------------------
15 - FAIL (Passing grade 16) - but i used only 1 h and did not verify
TS1.2) 2p next-hopf-self
TS1.3) 3p wrong static def.global
TS1.4) - RIP
TS1.5) 2p ospf-dead-interval
TS1.6) - WCCP
TS1.7) 2p ip rip send version 1 -> 2
TS1.8) 2p database-filter
TS1.9) - http authentication local
TS1.10) 2p drop / control-plane
----------------------------------
15 - FAIL (Passing grade 16) - but i used only 1 h and did not verify
Donnerstag, 7. Juli 2011
[OT] TFTPD Error code 1: File not found
l33th4x0r@os390:~$ tftp 1.1.1.1
tftp> put i-hate-tftpd.txt
Error code 1: File not found
tftp>
...
my-fucking-tftpd:~# cat /etc/default/tftpd-hpa
#Defaults for tftpd-hpa
RUN_DAEMON="yes"
OPTIONS="-l -c -s /var/lib/tftpboot/"
#change to "-c" for creating files
my-fucking-tftpd:~#
my-fucking-tftpd:~# chown nobody -R /var/lib/tftpboot/
my-fucking-tftpd:~# chmod -R 777 /var/lib/tftpboot/
...
l33th4x0r@os390:~$ tftp 1.1.1.1
tftp> put i-hate-tftpd.txt
Sent 856063 bytes in 1.2 seconds
tftp>
Wow....
If you encounter problems with the tftpd-hpa package on Debian systems... here's the solution
tftp> put i-hate-tftpd.txt
Error code 1: File not found
tftp>
...
my-fucking-tftpd:~# cat /etc/default/tftpd-hpa
#Defaults for tftpd-hpa
RUN_DAEMON="yes"
OPTIONS="-l -c -s /var/lib/tftpboot/"
#change to "-c" for creating files
my-fucking-tftpd:~#
my-fucking-tftpd:~# chown nobody -R /var/lib/tftpboot/
my-fucking-tftpd:~# chmod -R 777 /var/lib/tftpboot/
...
l33th4x0r@os390:~$ tftp 1.1.1.1
tftp> put i-hate-tftpd.txt
Sent 856063 bytes in 1.2 seconds
tftp>
Wow....
If you encounter problems with the tftpd-hpa package on Debian systems... here's the solution
Samstag, 2. Juli 2011
DUMBASS SECTION - BGP communities
route-map COM, permit, sequence 10
Match clauses:
community (community-list filter): 200:200
Set clauses:
local-preference 200
Policy routing matches: 0 packets, 0 bytes
route-map COM, permit, sequence 20
Match clauses:
Set clauses:
Policy routing matches: 0 packets, 0 bytes
Rack1R3#
Match clauses:
community (community-list filter): 200:200
Set clauses:
local-preference 200
Policy routing matches: 0 packets, 0 bytes
route-map COM, permit, sequence 20
Match clauses:
Set clauses:
Policy routing matches: 0 packets, 0 bytes
Rack1R3#
Rack1R3#show ip bgp 112.0.0.0
BGP routing table entry for 112.0.0.0/8, version 9
Paths: (3 available, best #1, table Default-IP-Routing-Table)
Advertised to update-groups:
1 2 3
100 54 50 60
155.1.13.1 from 155.1.13.1 (150.1.1.1)
Origin IGP, localpref 100, valid, external, best
Community: 200:200
300 100 54 50 60
155.1.37.7 from 155.1.37.7 (150.1.7.7)
Origin IGP, localpref 100, valid, external
100 54 50 60
155.1.45.4 (metric 27262976) from 155.1.0.5 (150.1.5.5)
Origin IGP, metric 0, localpref 100, valid, internal
Rack1R3#
BGP routing table entry for 112.0.0.0/8, version 9
Paths: (3 available, best #1, table Default-IP-Routing-Table)
Advertised to update-groups:
1 2 3
100 54 50 60
155.1.13.1 from 155.1.13.1 (150.1.1.1)
Origin IGP, localpref 100, valid, external, best
Community: 200:200
300 100 54 50 60
155.1.37.7 from 155.1.37.7 (150.1.7.7)
Origin IGP, localpref 100, valid, external
100 54 50 60
155.1.45.4 (metric 27262976) from 155.1.0.5 (150.1.5.5)
Origin IGP, metric 0, localpref 100, valid, internal
Rack1R3#
...
Hm.. community arrives at R3 but the route-map doesn't care. Still localpref 100 not 200.
Minutes passing by....
....
AHH not the community itself, sure... i need a community-list
....
Rack1R3(config)#ip community-list standard 200:200 permit 200:200 ?
Rack1R3#show ip bgp regexp _60$
BGP table version is 25, local router ID is 150.1.3.3
Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,
r RIB-failure, S Stale
Origin codes: i - IGP, e - EGP, ? - incomplete
Network Next Hop Metric LocPrf Weight Path
*> 112.0.0.0 155.1.13.1 200 0 100 54 50 60 i
* 155.1.37.7 0 300 100 54 50 60 i
*> 113.0.0.0 155.1.13.1 200 0 100 54 50 60 i
* 155.1.37.7 0 300 100 54 50 60 i
Rack1R3#s
Rack1R3(config)#ip community-list standard 200:200 permit 200:200 ?
Rack1R3#show ip bgp regexp _60$
BGP table version is 25, local router ID is 150.1.3.3
Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,
r RIB-failure, S Stale
Origin codes: i - IGP, e - EGP, ? - incomplete
Network Next Hop Metric LocPrf Weight Path
*> 112.0.0.0 155.1.13.1 200 0 100 54 50 60 i
* 155.1.37.7 0 300 100 54 50 60 i
*> 113.0.0.0 155.1.13.1 200 0 100 54 50 60 i
* 155.1.37.7 0 300 100 54 50 60 i
Rack1R3#s
Abonnieren
Posts (Atom)