UNIT 5: ADVANCED NETWORKING & SERVICES LAB - SHORT NOTES
5.1 Advanced IP Services & Configuration Labs
5.1.1 DHCP Server Configuration & Relay
-
Core Concept: Dynamically assigns IP addresses, subnet masks, gateways, and other options to clients.
-
Key Configuration Steps:
-
Define Scope: IP range, subnet mask, default gateway, DNS servers.
-
Exclusions: Reserve addresses for static devices (printers, servers).
-
Reservations: Map specific MAC addresses to guaranteed IPs.
-
Options: Configure domain name, DNS servers, NTP, etc.
-
-
DHCP Relay (IP Helper Address):
-
Purpose: Forwards DHCP broadcasts (
Discover,Request) from clients in one subnet to a DHCP server in another subnet. -
Command (Cisco IOS):
ip helper-address <server_ip>on the router interface facing the client subnet.
-
-
Troubleshooting:
-
show ip dhcp binding– View current leases. -
show ip dhcp server statistics– Check message counts. -
Common Issue:
NOIPerror on client → Check scope activation, relay config, and server availability.
-
5.1.2 DNS Implementation & Troubleshooting
-
Core Concept: Hierarchical, distributed database translating domain names to IP addresses (forward lookup) and vice-versa (reverse lookup).
-
Zone Types:
-
Forward Lookup Zone:
example.com→93.184.216.34 -
Reverse Lookup Zone:
34.216.184.93.in-addr.arpa→server.example.com
-
-
Server Roles:
-
Primary (Master): Holds read/write copy of zone file.
-
Secondary (Slave): Read-only copy via zone transfer.
-
Caching/Forwarding: Forwards queries to other servers; caches results.
-
-
Troubleshooting Tools:
-
nslookup/dig(Linux): Query specific record types (A,PTR,MX). -
show running-config– Verify zone and record configuration. -
Common Issue: Resolution failure → Check zone existence, record syntax, and server connectivity.
-
5.1.3 NAT Configuration & Advanced Scenarios
-
Core Concept: Translates private (RFC 1918) IP addresses to public IPs for Internet access.
-
Types & Configuration Logic:
| Type | Use Case | Translation Logic | Key Command | | :--- | :--- | :--- | :--- | | Static NAT | 1:1 mapping for servers |
InsideLocal:Port→InsideGlobal:Port|ip nat inside source static <local> <global>| | Dynamic NAT | Pool of public IPs for many hosts | From pool, on a first-come basis |ip nat inside source list <ACL> pool <pool_name>| | PAT (Overload)| Many hosts to one public IP | Uses port numbers to distinguish sessions |ip nat inside source list <ACL> interface <interface> overload| -
Interface Keywords:
ip nat inside(toward private network),ip nat outside(toward public network). -
Troubleshooting:
-
show ip nat translations– View active translation table. -
show ip nat statistics– Check hits/misses. -
Common Issue: "No translation" → Verify ACL matches traffic, inside/outside interface assignment, and route to NAT pool.
-
5.2 Network Security Implementation Labs
5.2.1 Access Control Lists (ACLs) - Deep Dive
-
Core Principle: Stateless packet filtering. Implicit
deny anyat end of every ACL. -
Standard vs. Extended ACLs:
| Feature | Standard ACL | Extended ACL | | :--- | :--- | :--- | | Number Range | 1-99, 1300-1999 | 100-199, 2000-2699 | | Filter Criteria | Source IP only | Source & Destination IP, Protocol, Port | | Typical Use | Permit/deny entire subnet | Granular control (e.g.,
permit tcp any host 192.168.1.10 eq 80) | | Placement | Close to destination | Close to source | -
Named ACLs: More descriptive (
ip access-list extended WEB-ACCESS). Can be modified (delete/modify lines). -
Placement Rule: Place ACL as close to the source as possible for extended ACLs (to filter unwanted traffic early). Place standard ACLs close to the destination (to avoid blocking traffic to other networks).
-
Troubleshooting:
show access-lists– View hit counts for each line. Zero hits on apermitline often means traffic isn't matching the ACL.
5.2.2 Firewall Configuration (Stateful Inspection)
-
Core Concept: Tracks connection state (TCP handshake, UDP "pseudo-connections") to allow return traffic automatically.
-
Basic Rule Logic:
-
Inbound (from Internet to DMZ/Internal): Explicit
permitfor required services (e.g.,permit tcp any host 10.0.1.10 eq 443). Implicitdenyfor everything else. -
Outbound (from Internal to Internet): Often
permit ip any any(trust internal users), or more restrictive policies.
-
-
DMZ (Demilitarized Zone):
-
Separate network segment for public-facing servers (Web, Mail).
-
Interfaces:
outside(Internet),dmz(servers),inside(internal users). -
Policy:
inside→dmz&internet(permit),dmz→inside(deny, except return traffic),outside→dmz(permit specific),outside→inside(deny).
-
-
Stateful Inspection: Enabled by default on modern firewalls. No need for explicit return traffic rules for established connections.
5.2.3 Virtual Private Networks (VPNs)
-
Site-to-Site VPN (IPsec):
-
Phases:
-
IKE Phase 1: Authenticates peers & establishes secure ISAKMP SA. (Main vs. Aggressive mode).
-
IKE Phase 2: Negotiates IPsec SA (encryption/authentication algorithms) for actual data.
-
-
Key Components:
-
Transform Set: Defines encryption (AES, 3DES) & authentication (SHA, MD5) algorithms.
-
Interesting Traffic ACL: Defines which traffic gets encrypted (e.g.,
permit ip 10.1.1.0 0.0.0.255 10.2.2.0 0.0.0.255). -
Crypto Map: Binds transform set, ACL, and peer IP to an interface.
-
-
-
Remote Access VPN (SSL/IPsec):
-
SSL VPN: Uses HTTPS (TCP 443). Browser-based client or AnyConnect. Easier through firewalls.
-
IPsec Remote Access: Requires VPN client software. Uses UDP 500 (IKE) & ESP (IP 50) or AH (IP 51).
-
-
Verification:
show crypto isakmp sa,show crypto ipsec sa,show crypto session.
5.3 Advanced Switching & VLAN Labs
5.3.1 VLAN Trunking & VTP
-
802.1Q Trunking:
-
Purpose: Carry traffic for multiple VLANs over a single physical link.
-
Tagging: Adds 4-byte VLAN tag to Ethernet frame.
-
Native VLAN: Untagged traffic on a trunk (default VLAN 1). Security Risk: Should be changed to an unused VLAN.
-
Command:
switchport mode trunk(on interface).
-
-
VTP (VLAN Trunking Protocol):
-
Purpose: Cisco-proprietary protocol to synchronize VLAN databases across switches.
-
Modes:
| Mode | Function | Risk | | :--- | :--- | :--- | | Server | Can create/modify/delete VLANs; advertises. | High – accidental VLAN deletion can propagate. | | Client | Receives VLAN info from Server; cannot modify. | Medium – follows server config. | | Transparent | Does not participate in VTP; forwards VTP ads. Own local VLANs only. | Safest – isolates VTP domain. |
-
VTP Pruning: Stops unnecessary VLAN broadcast traffic from crossing trunk links.
-
5.3.2 Inter-VLAN Routing
-
Router-on-a-Stick:
-
Single physical router interface configured as a trunk.
-
Creates Sub-Interfaces (e.g.,
Gig0/0.10,Gig0/0.20), each assigned an IP (default gateway) for a VLAN. -
Command:
interface Gig0/0.10→encapsulation dot1Q 10→ip address 192.168.10.1 255.255.255.0
-
-
Layer 3 Switch (SVI):
-
Switch with routing capability. Create Switched Virtual Interface (SVI) for each VLAN.
-
Command:
interface Vlan10→ip address 192.168.10.1 255.255.255.0→no shutdown. -
Advantage: Higher performance (hardware-based routing) vs. router-on-a-stick.
-
5.3.3 Spanning Tree Protocol (STP) Enhancement
-
PVST+ vs. RPVST+ (Rapid PVST+):
-
PVST+: Cisco Per-VLAN STP. One instance per VLAN. Convergence ~30-50 sec.
-
RPVST+: Uses 802.1w (RSTP) logic per VLAN. Convergence ~1-2 sec. (Port roles: Root, Designated, Alternate, Backup).
-
-
PortFast: Immediately transitions port to forwarding state (skips listening/learning). Use ONLY on end-host ports (access ports connecting to PCs/servers). Never on trunk ports.
-
BPDU Guard: Shuts down PortFast port if it receives a BPDU (protects against rogue switches).
-
Troubleshooting:
show spanning-tree– View root bridge, port roles, and state.
5.4 Network Analysis & Troubleshooting Tool Labs
5.4.1 Wireshark Advanced Capture & Filtering
-
Capture Filters: Applied during capture (BPF syntax). E.g.,
host 192.168.1.1 and port 80. -
Display Filters: Applied after capture (Wireshark syntax). Most Used:
-
ip.addr == 192.168.1.1– Traffic to/from IP. -
tcp.port == 80orhttp– HTTP traffic. -
udp.port == 53ordns– DNS traffic. -
bootp– DHCP traffic. -
tcp.flags.syn == 1 and tcp.flags.ack == 0– SYN packets only.
-
-
TCP Analysis: Follow TCP stream to see full conversation. Look for retransmissions (
[TCP Retransmission]), duplicate ACKs.
5.4.2 Protocol-Specific Analysis
-
DHCP (DORA Process):
-
Discover (Client → Broadcast)
-
Offer (Server → Client)
-
Request (Client → Broadcast)
-
Acknowledgment (Server → Client)
- Filter:
bootp
-
-
DNS:
-
Query Types:
A(IPv4),AAAA(IPv6),PTR(reverse),MX(mail). -
Filter:
dns
-
-
HTTP/HTTPS:
-
HTTP:
GET /index.html HTTP/1.1,200 OK. -
HTTPS: Encrypted. Look for TLS handshake (
Client Hello,Server Hello). Filtertlsorssl.
-
5.4.3 Network Performance & Latency Measurement
-
pingOptions:-
-l <size>(Windows) /-s <size>(Linux): Set packet size. -
-f(Windows) /-M do(Linux): Do Not Fragment bit – tests for MTU issues. -
-i <TTL>: Set Time-To-Live.
-
-
traceroute/tracert: Sends probes with incrementing TTL to map path & identify latency at each hop. -
iperf: Measures throughput (TCP/UDP). Client-server model.iperf -c <server_ip> -t 10(10-sec test). -
Jitter: Variation in latency. Measured with
iperf(UDP mode) or specialized tools.
5.5 Wireless Networking Labs
5.5.1 WLAN Infrastructure Setup
-
Standalone AP: Individual configuration via web GUI or CLI.
-
SSID: Network name.
-
Security Mode: WPA2/WPA3-Personal (PSK), WPA2/WPA3-Enterprise (802.1X).
-
Channel: 2.4 GHz (1,6,11 non-overlapping), 5 GHz (auto-select).
-
-
Lightweight AP & WLC: APs (LWAPP) controlled by a central Wireless LAN Controller. APs "join" the WLC. Simplifies management.
5.5.2 Wireless Security Configuration
-
WPA2/WPA3-Personal (PSK): Pre-Shared Key (password) for all users. Vulnerable if password is weak/shared.
-
WPA2/WPA3-Enterprise (802.1X/EAP):
-
Components: Supplicant (client), Authenticator (AP), Authentication Server (RADIUS).
-
Process: Mutual authentication using digital certificates or credentials. Unique session keys per user.
-
-
MAC Filtering: Whitelists specific device MAC addresses. Easily spoofed; not a primary security control.
-
Rogue AP: Unauthorized AP connected to network. Detection: Wireless scanners (airmon-ng, Kismet) or WLC rogue AP detection.
5.6 Network Automation & Scripting Introduction
5.6.1 Basic Scripting for Network Tasks
-
Goal: Parse
showcommand output (e.g.,show ip interface brief) to extract status, IPs. -
Example (Bash):
grep "up"orawk '{print $1, $2}'to filter/format output. -
Automation: Schedule scripts (cron) to backup configs (
show running-config > backup.cfg).
5.6.2 Introduction to Network APIs & Programmability
-
REST API: Uses HTTP methods (
GET,POST,PUT,DELETE). Data format: JSON/XML. -
Network Device API: Modern routers/switches/firewalls expose RESTCONF or gRPC APIs.
-
Tools:
-
curl: Command-line tool for HTTP requests.curl -X GET https://device-api/api/v1/interfaces -
Postman: GUI for API testing and request building.
-
-
Concept: Scripts/Applications use APIs to configure (POST/PUT) or retrieve data (GET) from devices instead of CLI.
5.7 Emerging & Integrated Scenario Labs
5.7.1 QoS (Quality of Service) Basics
-
Goal: Manage congestion by prioritizing critical traffic (voice, video).
-
Mechanisms:
-
Classification & Marking: Identify traffic (ACL) and set DSCP (Differentiated Services Code Point) value in IP header.
- Example:
class-map match-any VOICE→match access-group name VOICE-ACL→policy-map OUTBOUND-QOS→class VOICE→set ip dscp ef(Expedited Forwarding).
- Example:
-
Queuing: FIFO (default), Priority Queuing (PQ – strict priority), Weighted Fair Queuing (WFQ), Class-Based WFQ (CBWFQ).
-
Policing vs. Shaping: Policing drops excess traffic. Shaping buffers and delays excess traffic.
-
5.7.2 VoIP & Video Traffic Analysis
-
SIP (Session Initiation Protocol): Signaling protocol (TCP/UDP 5060/5061). Sets up, manages, tears down calls.
-
Wireshark Filter:
sip -
Look for:
INVITE,200 OK,BYE.
-
-
RTP (Real-time Transport Protocol): Carries actual audio/video media streams (dynamic UDP ports 10000-20000).
-
Wireshark Filter:
rtp -
Analysis: Check for jitter, packet loss, and sequence number gaps.
-
-
Effects of Latency/Jitter: Choppy audio, delayed conversations, video freezing.
5.7.3 Comprehensive Troubleshooting Methodology
-
OSI/TCP-IP Model Approach:
-
Physical/Link: Cables, interfaces (
show interface), switches, VLANs. -
Network: IP addressing, routing (
show ip route), ACLs, NAT. -
Transport: Ports, connectivity (
telnet,nc), firewall rules. -
Application: Service status, DNS, DHCP.
-
-
General Flow:
-
Define Problem: "PC-A cannot reach Web Server."
-
Test Local Connectivity:
ping 127.0.0.1,ping default-gateway. -
Test Remote Connectivity:
ping server_ip. -
If ping fails: Check ARP (
show arp), route (tracert), ACLs, NAT. -
If ping works but service fails: Check port (
telnet server_ip 80), DNS, firewall on server. -
Use
showcommands on intermediate devices (switch, router) to verify configurations. -
Isolate: Replace components, try different ports/cables.
-
[!TIP] Exam Focus: Be prepared to configure DHCP scopes with reservations, NAT (especially PAT), extended ACLs for specific protocols/ports, and inter-VLAN routing (both methods). Know Wireshark filters for DNS, DHCP, HTTP. Understand ACL placement rules and VPN phases.