Avoiding HSRP Instability in a Switching Environment with Various Router Platforms
Understanding and Troubleshooting HSRP Problems in Catalyst Switch Networks
If you're not making mistakes, then you're not doing anything.
+
+
+
+
+
+
A short listing of handy commands used on a regular basis:
#show ip interface brief
Shows status of the interfaces on the device, including up/down and ip information.
#show ip protocol summary
Will show you all the routing protocols running on the router
#show log
Will display the configured log settings and buffered log messages
#show interfaces status
Shows Port, Status, VLAN, Duplex, Speed and Type for all interfaces.
#show interfaces summary
Live traffic stats on the interfaces.
#show ip arp
Displays the IP to MAC Address resolution for all the IP’s on the device, and from the interfaces it was learned.
#show mac address-table
Shows the MAC table entry and interface it is being seen on.
#show policy-map [interface]
Displays the QoS Policy information
#show interfaces link
Will display how long the interface has been disconnected
#show version
Displays information about the device. It gives you details such as; IOS version, System Uptime, Image filename, Type of Processor, Amount of RAM, Number of Ports, Flash Memory, MAC Address and Serial Number
#show clock
Displays the clock status
#show version | include uptime
Shows the uptime of the device
#show processes cpu
Displays the CPU utilisation stats
#show processes cpu history
Displays a one minute output, and so on……
#show history
Lists the commands the user has entered in the session
#show inventory
Displays all the inventory information about the device
#show line
Lines connected on the router’s physical ports, such as serial connected.
#show cdp neighbour
Shows the directly connected devices with local and remote interfaces, via Cisco’s Discovery Protocol
+
+
+
+
+
+
A short and simple explanation of VXLAN
VXLAN Overview: Cisco Nexus 9000 Series Switches
+
+
+
+
+
+
The most sure-fire way to do this is to start a command-line session with the router, erase the startup-config and reload the router. The command syntax for that would be:
router>en
router#write erase
router#reload
*If you don’t have the login credentials for the router to get in, do this:
-Start a terminal session with the router via the Console port (telnet will not work for this). Physically reload the router, and from the console repeatedly hit the “Break” key, normally on the upper right hand side of the keyboard.
-You should now be in ROMMON mode. Type “confreg 0x2142” without quotes and hit Enter. Now type “reset” without quotes and hit Enter.
-Allow the router to restart, and hit “n” followed by Enter to stop the startup wizard.
-Type the following command sequence:
enable
conf t
config-register 0x2102
exit
write erase
<Enter key>
reload
The router will now boot normally, with a factory default configuration, even if you did not know any of the password(s) securing the router.
+
+
+
+
+
+
You can download PuTTY here.
Tunnelier is an SSH and SFTP client for Windows. It is developed and supported professionally by Bitvise. Tunnelier is robust, easy to install, easy to use, and supports all features supported by PuTTY, as well as the following:
Tunnelier is free for personal use, as well as for individual commercial use inside organizations. You can download Tunnelier here.
WinSSHD is an SSH, SFTP and SCP server for Windows. It is robust, easy to install, easy to use, and works well with a variety of SSH clients, including Tunnelier, OpenSSH, and PuTTY. WinSSHD is developed and supported professionally by Bitvise.
You can download WinSSHD here.
+
+
+
+
+
+
Network Time Protocol (NTP) is used for network devices, servers and workstations to periodically correct deviations in the system time reported by operating systems through a synchronisation process. The protocol is designed to compensate for variable latencies in the network.
Accurate time on network devices, servers and workstations ensures that timestamps tat are reported in log files such as the system log (SYSLOG) are within minimal tolerance, facilitating comparison of log entries between different systems and devices. This is essential when an intrusion or security breach has been detected, and for a corresponding forensic investigation.
For redundancy purposes, two or more internal time servers should be created. A list of publicly accessible and restricted-access time sources is provided by the Internet Systems Consortium (ISC) or dedicated time server can be implemented which can synchronise time via GPS or GSM networks.
NTP should be protected using authentication to ensure that communication with NTP server cannot be interfered with. An MD5 hash should be used was the authentication text. Access Controls Lists (ACL’s) should be used on the nominated NTP server to limit which systems are able to update the time and which systems are allowed to synchronise from the server. This is done with the ’ntp access-group’ command on Cisco devices.
All Client XYZ network devices should obtain time from a centralised time source.
Client XYZ to implement Network Time Protocol (NTP) capabilities within the network. The internal time servers should synchronise their time with a known time source ever 1-2 days. It is recommended that a stratum 1 or stratum 2 server be used, or if one is not available, then a time source from Oceania pool is recommended.
All network devices, servers and workstations within the internal network should periodically synchronise their system time with the internal time servers. A synchronisation interval of less than 14 days is recommended to reduce the impact of clock drift on these NTP clients.
+
+
+
+
+
+
+
+
+
+
+
+
While reviewing the ASA logs in relation to a large wireless metering project in WA, i came across a number of log entries that were just there (hundreds of thousands of them), so here’s how to disable them:
%ASA-6-302013: Built inbound TCP connection……
%ASA-6-302013: Built inbound TCP connection…..
%ASA-6-302015: Built outbound UDP connection…..
%ASA-6-302014: Teardown TCP connection…….
%ASA-6-302013: Built inbound TCP connection ………
%ASA-6-302020: Built outbound ICMP connection………
%ASA-6-302013: Built inbound TCP connection……
To exclude these types of log messages from being recorded. Simply login to the CLI and type the following:
ASA#config t
ASA(config)#no logging message 302016
Each log message has a syslog-id which is the 6 digit number. If there are additional types of logs you want to block, simply repeat the command above for each syslog-id. Link to the massive list of syslog-id messages and their descriptions:
http://www.cisco.com/c/en/us/td/docs/security/asa/syslog-guide/syslogs/logmsgs.html
And the command reference:
http://www.cisco.com/c/en/us/td/docs/security/asa/asa82/command/reference/cmd_ref/l2.html#wp1773284
+
+
+
+
+
+
I thought i better just make a link to this guys website, to help with any future upgrades given I’ll need to.
http://www.duppeditten.com/blog/qnap-ts-870-ultimate-nas-on-steroids