SlideShare a Scribd company logo
Chapter 11: It’s a 
Network 
Network Fundamentals 
© 2008 Cisco Systems, Inc. All Presentation_ID rights reserved. Cisco Confidential 1
Chapter 11 
11.1 Create and Grow 
11.2 Keeping the Network Safe 
11.3 Basic Network Performance 
11.4 Managing IOS Configuration Files 
11.5 Summary 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 2
Chapter 11: Objectives 
 Identify the devices and protocols used in a small network. 
 Explain how a small network serves as the basis of larger 
networks. 
 Describe the need for basic security measures on network 
devices. 
 Identify security vulnerabilities and general mitigation 
techniques. 
 Configure network devices with device hardening features to 
mitigate security threats. 
 Use the output of ping and trace commands to establish 
relative network performance. 
 Use basic show commands to verify the configuration and 
status of a device interface. 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 3
Chapter 11: Objectives (continued) 
 Use the basic host commands to acquire information 
about the devices in a network. 
 Explain file systems on Routers and Switches. 
 Apply the commands to back up and restore an IOS 
configuration file. 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 4
Devices in a Small Network 
Small Network Topologies 
 Typical Small Network Topology 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 5
Devices in a Small Network 
Device Selection for a Small Network 
 Factors to be considered when selecting intermediate 
devices 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 6
Devices in a Small Network 
Addressing for a Small Network 
 IP addressing scheme should be planned, documented 
and maintained based on the type of devices receiving 
the address. 
 Examples of devices that will be part of the IP design: 
End devices for users 
Servers and peripherals 
Hosts that are accessible from the Internet 
Intermediary devices 
 Planned IP schemes help the administrator: 
Track devices and troubleshoot 
Control access to resources 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 7
Devices in a Small Network 
Redundancy in a Small Network 
 Redundancy helps to eliminate single points of failure. 
 Improves the reliability of the network. 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 8
Devices in a Small Network 
Design Considerations for a Small Network 
 The following should be included in the network 
design: 
Secure file and mail servers in a centralized location. 
Protect the location by physical and logical security measures. 
Create redundancy in the server farm. 
Configure redundant paths to the servers. 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 9
Protocols in a Small Network 
Common Applications in a Small Network 
 Network-Aware Applications - software programs 
used to communicate over the network. 
 Application Layer Services - programs that interface 
with the network and prepare the data for transfer. 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 10
Protocols in a Small Network 
Common Protocols in a Small Network 
 Network Protocols Define: 
Processes on either end of a communication session 
Types of messages 
Syntax of the messages 
Meaning of informational fields 
How messages are sent and the expected response 
Interaction with the next lower layer 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 11
Protocols in a Small Network 
Real-Time Applications for a Small Network 
 Infrastructure - needs to be evaluated to ensure it will 
support proposed real time applications. 
 VoIP is implemented in organizations that still use 
traditional telephones 
 IP telephony - the IP phone itself performs voice-to-IP 
conversion 
 Real-time Video Protocols - Use Time Transport 
Protocol (RTP) and Real-Time Transport Control 
Protocol (RTCP) 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 12
Growing to Larger Networks 
Scaling a Small Network 
Important considerations when growing to a larger network: 
 Documentation – physical and logical topology 
 Device inventory – list of devices that use or comprise the 
network 
 Budget – itemized IT budget, including fiscal year 
equipment purchasing budget 
 Traffic Analysis – protocols, applications, and services 
and their respective traffic requirements should be 
documented 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 13
Growing to Larger Networks 
Protocol Analysis of a Small Network 
Information gathered by protocol analysis can be used to 
make decisions on how to manage traffic more efficiently. 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 14
Growing to Larger Networks 
Evolving Protocol Requirements 
 Network administrator can obtain IT “snapshots” of 
employee application utilization. 
 Snapshots track network utilization and traffic flow 
requirements. 
 Snapshots help inform network 
modifications needed in order to 
optimize employee productivity. 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 15
Network Device Security Measures 
Threats to Network Security 
 Categories of Threats to Network Security 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 16
Network Device Security Measures 
Physical Security 
Four classes of physical threats are: 
 Hardware threats - physical damage to servers, routers, 
switches, cabling plant, and workstations. 
 Environmental threats - temperature extremes (too hot 
or too cold) or humidity extremes (too wet or too dry) 
 Electrical threats - voltage spikes, insufficient supply 
voltage (brownouts), unconditioned power (noise), and 
total power loss 
 Maintenance threats - poor handling of key electrical 
components (electrostatic discharge), lack of critical 
spare parts, poor cabling, and poor labeling 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 17
Network Device Security Measures 
Types of Security Vulnerabilities 
 Technological weaknesses 
 Configuration weaknesses 
 Security policy weaknesses 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 18
Vulnerabilities and Network Attacks 
Viruses, Worms and Trojan Horses 
 A virus is malicious software that is attached to another 
program to execute a particular unwanted function on a 
workstation. 
 A Trojan horse is different only in that the entire 
application was written to look like something else, 
when in fact it is an attack tool. 
 Worms are self-contained programs that attack a 
system and try to exploit a specific vulnerability in the 
target. The worm copies its program from the attacking 
host to the newly exploited system to begin the cycle 
again. 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 19
Vulnerabilities and Network Attacks 
Reconnaissance, Access, and DoS Attacks 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 20
Vulnerabilities and Network Attacks 
Reconnaissance, Access, and DoS Attacks 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 21
Mitigating Network Attacks 
Backup, Upgrade, Update, and Patch 
 Keep current with the latest versions of antivirus 
software. 
 Install updated security patches 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 22
Mitigating Network Attacks 
Authentication, Authorization, and Accounting 
Authentication, Authorization, and Accounting (AAA, or 
“triple A”) 
 Authentication - Users and administrators must prove 
their identity. Authentication can be established using 
username and password combinations, challenge and 
response questions, token cards, and other methods. 
 Authorization - which resources the user can access 
and which operations the user is allowed to perform. 
 Accounting - records what the user accessed, the 
amount of time the resource is accessed, and any 
changes made. 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 23
Mitigating Network Attacks 
Firewalls 
A firewall resides between two or more networks. It 
controls traffic and helps prevent unauthorized access. 
Methods used are: 
 Packet Filtering 
 Application Filtering 
 URL Filtering 
 Stateful Packet Inspection 
(SPI) - Incoming packets 
must be legitimate 
responses to requests from 
internal hosts. 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 24
Mitigating Network Attacks 
Endpoint Security 
 Common endpoints are laptops, desktops, servers, 
smart phones, and tablets. 
 Employees must follow the companies documented 
security policies to secure their devices. 
 Policies often include the use of anti-virus software and 
host intrusion prevention. 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 25
Securing Devices 
Introduction to Securing Devices 
 Part of network security is securing devices, including 
end devices and intermediate devices. 
 Default usernames and passwords should be changed 
immediately. 
 Access to system resources should be restricted to only 
the individuals that are authorized to use those 
resources. 
 Any unnecessary services and applications should be 
turned off and uninstalled, when possible. 
 Update with security patches as they become available. 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 26
Securing Devices 
Passwords 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 27
Securing Devices 
Basic Security Practices 
 Encrypt passwords 
 Require minimum length passwords 
 Block brute force attacks 
 Use Banner Message 
 Set EXEC timeout 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 28
Securing Devices 
Enable SSH 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 29
Ping 
Interpreting ICMP Messages 
 ! - indicates receipt of an ICMP echo reply message 
 . - indicates a time expired while waiting for an ICMP 
echo reply message 
 U - an ICMP unreachable message was received 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 30
Ping 
Leveraging Extended Ping 
 The Cisco IOS offers an "extended" mode of the ping 
command 
R2# ping 
Protocol [ip]: 
Target IP address: 192.168.10.1 
Repeat count [5]: 
Datagram size [100]: 
Timeout in seconds [2]: 
Extended commands [n]: y 
Source address or interface: 10.1.1.1 
Type of service [0]: 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 31
Ping 
Network Baseline 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 32
Tracert 
Interpreting Tracert Messages 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 33
Show Commands 
Common Show Commands Revisited 
 The status of nearly every process or function of the 
router can be displayed using a show command. 
 Frequently used show commands: 
show running-config 
show interfaces 
show arp 
show ip route 
show protocols 
show version 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 34
Show Commands 
Viewing Router Settings with Show Version 
Cisco IOS version 
System bootstrap 
Cisco IOS image 
CPU and RAM 
Number and type of 
physical interfaces 
Amount of NVRAM 
Amount of Flash 
Config. register 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 35
Show Commands 
Viewing Switch Settings with Show Version 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 36
Host and IOS Commands 
ipconfig Command Options 
 ipconfig - displays ip address, subnet mask, default 
gateway. 
 ipconfig /all – also displays MAC address. 
 Ipconfig /displaydns - displays all cached dns entries in 
a Windows system . 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 37
Host and IOS Commands 
arp Command Options 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 38
Host and IOS Commands 
show cdp neighbors Command Options 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 39
Host and IOS Commands 
Using show ip interface brief Command 
 Can be used to verify the status of all network 
interfaces on a router or a switch. 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 40
Router and Switch File Systems 
Router File Systems 
 show file systems command - lists all of the available 
file systems on a Cisco 1941 route 
 * Asterisk indicates this is the current default file system 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 41
Router and Switch File Systems 
Switch File Systems 
 show file systems command - lists all of the available 
file systems on a Catalyst 2960 switch. 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 42
Backup and Restore Configuration Files 
Backup and Restore using Text Files 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 43
Backup and Restore Configuration Files 
Backup and Restore using TFTP 
 Configuration files can be stored on a Trivial File 
Transfer Protocol (TFTP) server. 
 copy running-config tftp – save running configuration to 
a tftp server 
 copy startup-config tftp - save startup configuration 
to a tftp server 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 44
Backup and Restore Configuration Files 
Using USB Interfaces on a Cisco Router 
 USB flash drive must be formatted in a FAT16 format. 
 Can hold multiple copies of the Cisco IOS and multiple 
router configurations. 
 Allows administrator to easily move configurations from 
router to router. 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 45
Backup and Restore Configuration Files 
Backup and Restore Using USB 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 46
Chapter 11: Summary 
 Good network design incorporates reliability, scalability, and 
availability. 
 Networks must be secured from viruses, Trojan horses, worms 
and network attacks. 
 Document Basic Network Performance. 
 Test network connectivity using ping and traceroute. 
 Use IOS commands to monitor and view information about the 
network and network devices. 
 Backup configuration files using TFTP or USB. 
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 47
Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 48

More Related Content

PPTX
CCNA RS_ITN - Chapter 7
PDF
CCNAv5 - S4: Chapter8 monitoring the network
PPTX
Ccna v5-S1-Chapter 6
PPTX
CCNA 1 Routing and Switching v5.0 Chapter 5
PPTX
CCNA RS_ITN - Chapter 6
PPTX
CCNA RS_ITN - Chapter 3
PPTX
CCNA RS_NB - Chapter 6
PPTX
CCNA RS_NB - Chapter 5
CCNA RS_ITN - Chapter 7
CCNAv5 - S4: Chapter8 monitoring the network
Ccna v5-S1-Chapter 6
CCNA 1 Routing and Switching v5.0 Chapter 5
CCNA RS_ITN - Chapter 6
CCNA RS_ITN - Chapter 3
CCNA RS_NB - Chapter 6
CCNA RS_NB - Chapter 5

What's hot (18)

PPTX
CCNA RS_ITN - Chapter 2
PPTX
CCNA 1 Routing and Switching v5.0 Chapter 7
PPTX
Ccna v5-S1-Chapter 1
PPTX
CCNA RS_ITN - Chapter 11
PDF
CCNAv5 - S1: Chapter 3 - Network protocols and communications
PPTX
CCNA RS_ITN - Chapter 9
PPTX
CCNA RS_NB - Chapter 9
PPTX
CCNA 1 Routing and Switching v5.0 Chapter 10
PPTX
CCNA RS_ITN - Chapter 5
PPTX
Ccna v5-S1-Chapter 5
PPTX
Ccna v5-S1-Chapter 7
PDF
CCNAv5 - S1: Chapter 1 Exploring The Network
PDF
CCNAv5 - S4: Chapter3 Point to-point Connections
PDF
CCNAv5 - S1: Chapter 7 - Transport Layer
PPTX
CCNA RS_ITN - Chapter 8
PPTX
Ccna v5-S1-Chapter 10
PDF
CCNAv5 - S2: Chapter1 Introsuction to switched networks
PPTX
CCNA 2 Routing and Switching v5.0 Chapter 11
CCNA RS_ITN - Chapter 2
CCNA 1 Routing and Switching v5.0 Chapter 7
Ccna v5-S1-Chapter 1
CCNA RS_ITN - Chapter 11
CCNAv5 - S1: Chapter 3 - Network protocols and communications
CCNA RS_ITN - Chapter 9
CCNA RS_NB - Chapter 9
CCNA 1 Routing and Switching v5.0 Chapter 10
CCNA RS_ITN - Chapter 5
Ccna v5-S1-Chapter 5
Ccna v5-S1-Chapter 7
CCNAv5 - S1: Chapter 1 Exploring The Network
CCNAv5 - S4: Chapter3 Point to-point Connections
CCNAv5 - S1: Chapter 7 - Transport Layer
CCNA RS_ITN - Chapter 8
Ccna v5-S1-Chapter 10
CCNAv5 - S2: Chapter1 Introsuction to switched networks
CCNA 2 Routing and Switching v5.0 Chapter 11
Ad

Viewers also liked (20)

PPTX
VMware vShield - Overview
PPTX
CCNA RS_NB - Chapter 10
PPTX
CCNA RS_NB - Chapter 8
PPTX
CCNA RS_NB - Chapter 2
PPTX
CCNA RS_NB - Chapter 7
PPTX
CCNA RS_ITN - Chapter 4
PPT
ITE v5.0 - Chapter 6
PPT
ITE v5.0 - Chapter 1
PPT
CCNA Security - Chapter 1
PPT
CCNA Security - Chapter 4
PPTX
CCNA RS_NB - Chapter 1
PPT
CCNA Security - Chapter 3
PPTX
CCNA RS_NB - Chapter 3
PPT
CCNA Exploration 4 - Chapter 8
PPT
CCNA Security - Chapter 5
PPT
CCNA Security - Chapter 7
PPT
CCNA Security - Chapter 2
PPT
ITE v5.0 - Chapter 9
PPT
CCNA Security - Chapter 9
PPTX
CCNA RS_NB - Chapter 4
VMware vShield - Overview
CCNA RS_NB - Chapter 10
CCNA RS_NB - Chapter 8
CCNA RS_NB - Chapter 2
CCNA RS_NB - Chapter 7
CCNA RS_ITN - Chapter 4
ITE v5.0 - Chapter 6
ITE v5.0 - Chapter 1
CCNA Security - Chapter 1
CCNA Security - Chapter 4
CCNA RS_NB - Chapter 1
CCNA Security - Chapter 3
CCNA RS_NB - Chapter 3
CCNA Exploration 4 - Chapter 8
CCNA Security - Chapter 5
CCNA Security - Chapter 7
CCNA Security - Chapter 2
ITE v5.0 - Chapter 9
CCNA Security - Chapter 9
CCNA RS_NB - Chapter 4
Ad

Similar to CCNA RS_NB - Chapter 11 (20)

PPTX
CCNA 1 Routing and Switching v5.0 Chapter 11
PPTX
Ccna v5-S1-Chapter 11
PDF
CCNAv5 - S1: Chapter11 It's A Network
PPTX
Chapter 11 : It’s a network
PPTX
CCNA (R & S) Module 01 - Introduction to Networks - Chapter 11
PDF
ITN6_Instructor_Materials_Chapter11.pdf
PPTX
ITN_instructorPPT_Chapter1.pptx
PPTX
ITN_instructorPPT_Chapter1.pptx
PPTX
Itn instructor ppt_chapter1 - exploring the network
PPTX
CCNA 1 Routing and Switching v5.0 Chapter 1
PPTX
CCNA RS_ITN - Chapter 1
PDF
Introduction of Exploring the Network Part 1
PPTX
Chapter 1 Exploring the Network. Intoduction.pptx
PPTX
Network Security.pptx
PPTX
Chapter 1 : Exploring the Network
PPTX
Itninstructorpptchapter1final 141024004546-conversion-gate02
PDF
It nv51 instructor_ppt_ch11
PPTX
Itn instructor ppt_chapter1 exploring the network smartskills
PPTX
Itn6 instructor materials_chapter1
PPTX
ITN_Module_17.pptx
CCNA 1 Routing and Switching v5.0 Chapter 11
Ccna v5-S1-Chapter 11
CCNAv5 - S1: Chapter11 It's A Network
Chapter 11 : It’s a network
CCNA (R & S) Module 01 - Introduction to Networks - Chapter 11
ITN6_Instructor_Materials_Chapter11.pdf
ITN_instructorPPT_Chapter1.pptx
ITN_instructorPPT_Chapter1.pptx
Itn instructor ppt_chapter1 - exploring the network
CCNA 1 Routing and Switching v5.0 Chapter 1
CCNA RS_ITN - Chapter 1
Introduction of Exploring the Network Part 1
Chapter 1 Exploring the Network. Intoduction.pptx
Network Security.pptx
Chapter 1 : Exploring the Network
Itninstructorpptchapter1final 141024004546-conversion-gate02
It nv51 instructor_ppt_ch11
Itn instructor ppt_chapter1 exploring the network smartskills
Itn6 instructor materials_chapter1
ITN_Module_17.pptx

More from Irsandi Hasan (12)

PPTX
CCNA v6.0 ITN - Chapter 11
PPTX
CCNA v6.0 ITN - Chapter 10
PPTX
CCNA v6.0 ITN - Chapter 09
PPTX
CCNA v6.0 ITN - Chapter 08
PPTX
CCNA v6.0 ITN - Chapter 07
PPTX
CCNA v6.0 ITN - Chapter 06
PPTX
CCNA v6.0 ITN - Chapter 05
PPTX
CCNA v6.0 ITN - Chapter 04
PPTX
CCNA v6.0 ITN - Chapter 03
PPTX
CCNA v6.0 ITN - Chapter 02
PPTX
CCNA v6.0 ITN - Chapter 01
PPTX
CCNA RS_ITN - Chapter 10
CCNA v6.0 ITN - Chapter 11
CCNA v6.0 ITN - Chapter 10
CCNA v6.0 ITN - Chapter 09
CCNA v6.0 ITN - Chapter 08
CCNA v6.0 ITN - Chapter 07
CCNA v6.0 ITN - Chapter 06
CCNA v6.0 ITN - Chapter 05
CCNA v6.0 ITN - Chapter 04
CCNA v6.0 ITN - Chapter 03
CCNA v6.0 ITN - Chapter 02
CCNA v6.0 ITN - Chapter 01
CCNA RS_ITN - Chapter 10

Recently uploaded (20)

PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
Spectroscopy.pptx food analysis technology
PDF
Approach and Philosophy of On baking technology
PDF
Unlocking AI with Model Context Protocol (MCP)
PDF
Review of recent advances in non-invasive hemoglobin estimation
PPTX
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
NewMind AI Weekly Chronicles - August'25 Week I
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Electronic commerce courselecture one. Pdf
PDF
Empathic Computing: Creating Shared Understanding
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPTX
Cloud computing and distributed systems.
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
sap open course for s4hana steps from ECC to s4
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Spectroscopy.pptx food analysis technology
Approach and Philosophy of On baking technology
Unlocking AI with Model Context Protocol (MCP)
Review of recent advances in non-invasive hemoglobin estimation
ACSFv1EN-58255 AWS Academy Cloud Security Foundations.pptx
Dropbox Q2 2025 Financial Results & Investor Presentation
NewMind AI Weekly Chronicles - August'25 Week I
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
MYSQL Presentation for SQL database connectivity
Electronic commerce courselecture one. Pdf
Empathic Computing: Creating Shared Understanding
Understanding_Digital_Forensics_Presentation.pptx
The Rise and Fall of 3GPP – Time for a Sabbatical?
Cloud computing and distributed systems.
Diabetes mellitus diagnosis method based random forest with bat algorithm
Advanced methodologies resolving dimensionality complications for autism neur...
sap open course for s4hana steps from ECC to s4

CCNA RS_NB - Chapter 11

  • 1. Chapter 11: It’s a Network Network Fundamentals © 2008 Cisco Systems, Inc. All Presentation_ID rights reserved. Cisco Confidential 1
  • 2. Chapter 11 11.1 Create and Grow 11.2 Keeping the Network Safe 11.3 Basic Network Performance 11.4 Managing IOS Configuration Files 11.5 Summary Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 2
  • 3. Chapter 11: Objectives  Identify the devices and protocols used in a small network.  Explain how a small network serves as the basis of larger networks.  Describe the need for basic security measures on network devices.  Identify security vulnerabilities and general mitigation techniques.  Configure network devices with device hardening features to mitigate security threats.  Use the output of ping and trace commands to establish relative network performance.  Use basic show commands to verify the configuration and status of a device interface. Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 3
  • 4. Chapter 11: Objectives (continued)  Use the basic host commands to acquire information about the devices in a network.  Explain file systems on Routers and Switches.  Apply the commands to back up and restore an IOS configuration file. Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 4
  • 5. Devices in a Small Network Small Network Topologies  Typical Small Network Topology Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 5
  • 6. Devices in a Small Network Device Selection for a Small Network  Factors to be considered when selecting intermediate devices Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 6
  • 7. Devices in a Small Network Addressing for a Small Network  IP addressing scheme should be planned, documented and maintained based on the type of devices receiving the address.  Examples of devices that will be part of the IP design: End devices for users Servers and peripherals Hosts that are accessible from the Internet Intermediary devices  Planned IP schemes help the administrator: Track devices and troubleshoot Control access to resources Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 7
  • 8. Devices in a Small Network Redundancy in a Small Network  Redundancy helps to eliminate single points of failure.  Improves the reliability of the network. Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 8
  • 9. Devices in a Small Network Design Considerations for a Small Network  The following should be included in the network design: Secure file and mail servers in a centralized location. Protect the location by physical and logical security measures. Create redundancy in the server farm. Configure redundant paths to the servers. Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 9
  • 10. Protocols in a Small Network Common Applications in a Small Network  Network-Aware Applications - software programs used to communicate over the network.  Application Layer Services - programs that interface with the network and prepare the data for transfer. Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 10
  • 11. Protocols in a Small Network Common Protocols in a Small Network  Network Protocols Define: Processes on either end of a communication session Types of messages Syntax of the messages Meaning of informational fields How messages are sent and the expected response Interaction with the next lower layer Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 11
  • 12. Protocols in a Small Network Real-Time Applications for a Small Network  Infrastructure - needs to be evaluated to ensure it will support proposed real time applications.  VoIP is implemented in organizations that still use traditional telephones  IP telephony - the IP phone itself performs voice-to-IP conversion  Real-time Video Protocols - Use Time Transport Protocol (RTP) and Real-Time Transport Control Protocol (RTCP) Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 12
  • 13. Growing to Larger Networks Scaling a Small Network Important considerations when growing to a larger network:  Documentation – physical and logical topology  Device inventory – list of devices that use or comprise the network  Budget – itemized IT budget, including fiscal year equipment purchasing budget  Traffic Analysis – protocols, applications, and services and their respective traffic requirements should be documented Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 13
  • 14. Growing to Larger Networks Protocol Analysis of a Small Network Information gathered by protocol analysis can be used to make decisions on how to manage traffic more efficiently. Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 14
  • 15. Growing to Larger Networks Evolving Protocol Requirements  Network administrator can obtain IT “snapshots” of employee application utilization.  Snapshots track network utilization and traffic flow requirements.  Snapshots help inform network modifications needed in order to optimize employee productivity. Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 15
  • 16. Network Device Security Measures Threats to Network Security  Categories of Threats to Network Security Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 16
  • 17. Network Device Security Measures Physical Security Four classes of physical threats are:  Hardware threats - physical damage to servers, routers, switches, cabling plant, and workstations.  Environmental threats - temperature extremes (too hot or too cold) or humidity extremes (too wet or too dry)  Electrical threats - voltage spikes, insufficient supply voltage (brownouts), unconditioned power (noise), and total power loss  Maintenance threats - poor handling of key electrical components (electrostatic discharge), lack of critical spare parts, poor cabling, and poor labeling Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 17
  • 18. Network Device Security Measures Types of Security Vulnerabilities  Technological weaknesses  Configuration weaknesses  Security policy weaknesses Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 18
  • 19. Vulnerabilities and Network Attacks Viruses, Worms and Trojan Horses  A virus is malicious software that is attached to another program to execute a particular unwanted function on a workstation.  A Trojan horse is different only in that the entire application was written to look like something else, when in fact it is an attack tool.  Worms are self-contained programs that attack a system and try to exploit a specific vulnerability in the target. The worm copies its program from the attacking host to the newly exploited system to begin the cycle again. Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 19
  • 20. Vulnerabilities and Network Attacks Reconnaissance, Access, and DoS Attacks Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 20
  • 21. Vulnerabilities and Network Attacks Reconnaissance, Access, and DoS Attacks Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 21
  • 22. Mitigating Network Attacks Backup, Upgrade, Update, and Patch  Keep current with the latest versions of antivirus software.  Install updated security patches Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 22
  • 23. Mitigating Network Attacks Authentication, Authorization, and Accounting Authentication, Authorization, and Accounting (AAA, or “triple A”)  Authentication - Users and administrators must prove their identity. Authentication can be established using username and password combinations, challenge and response questions, token cards, and other methods.  Authorization - which resources the user can access and which operations the user is allowed to perform.  Accounting - records what the user accessed, the amount of time the resource is accessed, and any changes made. Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 23
  • 24. Mitigating Network Attacks Firewalls A firewall resides between two or more networks. It controls traffic and helps prevent unauthorized access. Methods used are:  Packet Filtering  Application Filtering  URL Filtering  Stateful Packet Inspection (SPI) - Incoming packets must be legitimate responses to requests from internal hosts. Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 24
  • 25. Mitigating Network Attacks Endpoint Security  Common endpoints are laptops, desktops, servers, smart phones, and tablets.  Employees must follow the companies documented security policies to secure their devices.  Policies often include the use of anti-virus software and host intrusion prevention. Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 25
  • 26. Securing Devices Introduction to Securing Devices  Part of network security is securing devices, including end devices and intermediate devices.  Default usernames and passwords should be changed immediately.  Access to system resources should be restricted to only the individuals that are authorized to use those resources.  Any unnecessary services and applications should be turned off and uninstalled, when possible.  Update with security patches as they become available. Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 26
  • 27. Securing Devices Passwords Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 27
  • 28. Securing Devices Basic Security Practices  Encrypt passwords  Require minimum length passwords  Block brute force attacks  Use Banner Message  Set EXEC timeout Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 28
  • 29. Securing Devices Enable SSH Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 29
  • 30. Ping Interpreting ICMP Messages  ! - indicates receipt of an ICMP echo reply message  . - indicates a time expired while waiting for an ICMP echo reply message  U - an ICMP unreachable message was received Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 30
  • 31. Ping Leveraging Extended Ping  The Cisco IOS offers an "extended" mode of the ping command R2# ping Protocol [ip]: Target IP address: 192.168.10.1 Repeat count [5]: Datagram size [100]: Timeout in seconds [2]: Extended commands [n]: y Source address or interface: 10.1.1.1 Type of service [0]: Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 31
  • 32. Ping Network Baseline Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 32
  • 33. Tracert Interpreting Tracert Messages Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 33
  • 34. Show Commands Common Show Commands Revisited  The status of nearly every process or function of the router can be displayed using a show command.  Frequently used show commands: show running-config show interfaces show arp show ip route show protocols show version Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 34
  • 35. Show Commands Viewing Router Settings with Show Version Cisco IOS version System bootstrap Cisco IOS image CPU and RAM Number and type of physical interfaces Amount of NVRAM Amount of Flash Config. register Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 35
  • 36. Show Commands Viewing Switch Settings with Show Version Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 36
  • 37. Host and IOS Commands ipconfig Command Options  ipconfig - displays ip address, subnet mask, default gateway.  ipconfig /all – also displays MAC address.  Ipconfig /displaydns - displays all cached dns entries in a Windows system . Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 37
  • 38. Host and IOS Commands arp Command Options Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 38
  • 39. Host and IOS Commands show cdp neighbors Command Options Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 39
  • 40. Host and IOS Commands Using show ip interface brief Command  Can be used to verify the status of all network interfaces on a router or a switch. Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 40
  • 41. Router and Switch File Systems Router File Systems  show file systems command - lists all of the available file systems on a Cisco 1941 route  * Asterisk indicates this is the current default file system Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 41
  • 42. Router and Switch File Systems Switch File Systems  show file systems command - lists all of the available file systems on a Catalyst 2960 switch. Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 42
  • 43. Backup and Restore Configuration Files Backup and Restore using Text Files Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 43
  • 44. Backup and Restore Configuration Files Backup and Restore using TFTP  Configuration files can be stored on a Trivial File Transfer Protocol (TFTP) server.  copy running-config tftp – save running configuration to a tftp server  copy startup-config tftp - save startup configuration to a tftp server Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 44
  • 45. Backup and Restore Configuration Files Using USB Interfaces on a Cisco Router  USB flash drive must be formatted in a FAT16 format.  Can hold multiple copies of the Cisco IOS and multiple router configurations.  Allows administrator to easily move configurations from router to router. Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 45
  • 46. Backup and Restore Configuration Files Backup and Restore Using USB Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 46
  • 47. Chapter 11: Summary  Good network design incorporates reliability, scalability, and availability.  Networks must be secured from viruses, Trojan horses, worms and network attacks.  Document Basic Network Performance.  Test network connectivity using ping and traceroute.  Use IOS commands to monitor and view information about the network and network devices.  Backup configuration files using TFTP or USB. Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 47
  • 48. Presentation_ID © 2008 Cisco Systems, Inc. All rights reserved. Cisco Confidential 48