Cisco Networking Answers http://cisco-network.com Sat, 21 Nov 2009 20:45:40 +0000 http://wordpress.org/?v=2.9.1 en hourly 1 Cisco Network Monitoring Common Mistakes http://cisco-network.com/hands-on/cisco-network-monitoring-common-mistakes/ http://cisco-network.com/hands-on/cisco-network-monitoring-common-mistakes/#comments Sat, 05 Sep 2009 20:34:03 +0000 MustafaAksu http://cisco-network.com/?p=98 I am going to touch on common mistakes in cisco network monitoring today. You know for sure that you need a network-monitoring tool for managing your network. There are wide varieties of tools available that range from simple to complex and free to enterprise ones.
If you get one monitoring tool and install it, can you say that everything is under control? Are you going to be aware of what happened in your network? I will try to warn you about common mistakes in Cisco network monitoring. Actually, these mistakes are common for any kind of network however my experience on Cisco environment.

1. Monitoring without documentation
If you are monitoring your network and don’t have the complete network documentation, then it will not be clear whether monitoring is beneficial or not. How can you be sure about reliability of your monitoring system without knowing exact number of devices, their models and their interconnections?

2. Only network specialists should watch over network.
Network specialists must setup network monitoring systems, but watching over them and taking first action should not be their task. If you have network monitoring screens, then such screens should be watched over by -
• A monitoring team – if the network is big enough (e.g. a NOC)
• Help desk – if you have
• End user support team
Any alert (alerts, events, mails, SMSs) should be directed to help desk or end user support team. The receiver must be able to handle it immediately. Alertness is the key here and therefore this task should not be assigned to staff who is involved in projects and moving often. Help desk staff should be intimated first and then information should move upwards based on the hierarchy, finally reaching the network admin to sort out the issue.

3. Unhandled alerts
All alerts should be checked and cleared. If there is expected maintenance on some devices, then they have to be excluded from monitoring system (This is a must have for a network monitoring tool). If some alerts stay on the monitoring system for a long time, then it will cause alert blindness on the team. False alerts may also drop your confidence in the monitoring system.

4. Correct probe points & traffic behavior
You have to understand your routing infrastructure very well, especially for flow monitoring. Sometimes, you can find undesirable traffic so easily, but it does not happen always. In case of a huge download, you just have to look at the right point in the backbone. In case of an antivirus update, traffic is one to many, you have to summarize collected data by source or target upon direction of traffic and in the case of many to many traffic like virus infections, you have to know or guess characteristics of undesired traffic (like tcp port). If you ignore these details, you can look at your netflow monitor and can swear that all seen traffic is necessary.

5. No history
If you have your monitoring system ready, but you monitor just some nodes and think that you can monitor any necessary point if something untoward incident happens (I mean SNMP monitoring),then you are playing with the fire! When something happens, to analyze it you will have to compare this condition with the normal conditions but you will be too late for that. It won’t be possible to acquire this information anymore. Therefore, you must monitor all ports and the interfaces that have to be monitored from the first day. Your monitoring technique is correct only when it is complete.

6. We have a huge tool – problem is over
This is about decision phase of network monitoring. You should define your needs well and choose fitting tool for your network. No more, no less. This decision is not just about cost. The concept will be clear with an example and a good example is Cisco Works. It is huge, capable and a brand that is trusted all over the world. However, if you don’t have a dedicated staff for this, then it is really hard to install and use it. I have come across many people who purchased Cisco in anticipation that it will be very beneficial to them, but did not make use of this powerful tool completely. It is like buying a truck and trying to park it in your car garage, which is a foolish decision!

7. Network monitoring is not a mission critical process
How much loss do you incur if your network monitoring system stops working? Is it going to stop production, sales or logistics? The answer is no. So, network monitoring system is not a mission critical system. This could be true. Network itself is mission critical. Everything stops when it stops. Network problems should be fixed immediately. You have to find the problem (here you need monitoring) in minutes. Nevertheless, your monitoring system can be down because it is not a mission critical system. If this is the case, you should connect each device separately and look for errors. It is similar to a situation in which you are driving on the highway with broken gauges (fuel, temperature, speed). Good luck!

These are the seven common mistakes in Cisco network monitoring. You are in charge of keep them away from your network.

]]>
http://cisco-network.com/hands-on/cisco-network-monitoring-common-mistakes/feed/ 0
WS-X6516-GBIC is PwrDown after supervisor module upgrade http://cisco-network.com/hands-on/ws-x6516-gbic-pwrdown-after-supervisor-module-upgrade/ http://cisco-network.com/hands-on/ws-x6516-gbic-pwrdown-after-supervisor-module-upgrade/#comments Wed, 05 Aug 2009 18:46:35 +0000 MustafaAksu http://cisco-network.com/?p=89 supervisor 720 is not compatible with DFCMaybe I am the worst network engineer in the world or maybe I am unlucky.

Recently, I made an upgrade on some of 6509 switches. I bought totally new 6509-E system including chassis, fan, power, and some new line cards. I also insert my fiber line cards that I used in old 6509 with supervisor 2.
Everything was fine until I checked modules status with “show module” command. Switch was up, new line cards were functioning, but my old WS-X6516-GBIC’s were in PwrDown state. When I checked the switch logs I found

00:02:31: %C6KPWR-SP-4-UNSUPPORTED: unsupported module in slot 2, power not allowed: The image for the card is not bundled in image.

What does it mean? I had a recent IOS and it does not support this card. I was not surprised because it happened to me before. I just checked the software advisor tool from Cisco and found another version.I tried it, but it did not work out.

A wise friend of mine told me that I should give a try to a safe harbor image. I was not aware of safe harbor program until that time. Safe harbor images are tested images. They are stable, interoperable and solid. It was my last chance before I should have to escalate this problem.

I found out that there are some problems between Supervisor Engine 720 and WS-X6516-GBIC, but the problem were only valid for 5.0 to 5.3 Hw versions and I had 5.7. It should not be my problem but text mentioned about DFC Sub-modules. I focused on DFC daughter card then. Everything become clear when I found “Catalyst 6500 Series DFC, DFC3A, DFC3B, and DFC3BXL Installation Note” document. I saw a note mentioned below

Note You cannot have a DFC in a system with a Supervisor Engine 720

I removed one DFC (WS-F6K-DFC) from one of the WS-X6516-GBIC and finally it started to work. I also changed the IOS images to safe harbor ones. I spent days to solve this problem and this turned out to be a simple issue for which I got the answer instantaneously from the web!

]]>
http://cisco-network.com/hands-on/ws-x6516-gbic-pwrdown-after-supervisor-module-upgrade/feed/ 0
Network Security first-step http://cisco-network.com/book-reviews/network-security-first-step/ http://cisco-network.com/book-reviews/network-security-first-step/#comments Mon, 06 Apr 2009 18:39:29 +0000 MustafaAksu http://cisco-network.com/?p=68 I am writing my first book review here, in my blog after almost two years. I guess, this is the only technical book that I read within this period “Network Security first-step”. Honestly, I do not feel the necessity to read a book. I can easily goggling on the Internet, write on forums or better ask my contracted partner for the necessary info.

I was sitting lazy in the office; one of my colleagues came and said “if you want to order a book this year, find it on Barns&Noble and send me the link until afternoon”. Some ideas flashed in my mind
- No, I don’t need a book
- Maybe, a reference book would be good. No, I am using Cisco web site , everything is available and searchable.
- Exam preparation books maybe. No they are boring.
- I wanted to find a book, which I could read before sleep. It should be well written, easy to read, but not marketing mambo jambo, and should have some real purified info.
I started hunting for such a book!

The book “Network Security first-step”

Network Security first-step cover

It has been written by Tom Thomas, published by Cisco Press in 2004. ISBN number is 1-58720-099-6. It has red cover with a lock on it, 431 pages. It has price tag of $29.99 at the back of the book.

It is a must read for any IT guy who is into network “security” and has a job that deals with it. If you are teaching any kind of information security courses /classes, then you too need it. It is also a must read for all those who specialize in network security and also it is suitable for Information security auditors.

It is nice to read if you are CIO or IT technology manager/director and any kind of networker.

The Content
It starts with basics of hacking; terminology, methods and organizations that are working against the hackers.
The book speaks about security technologies like ACLs, NAT and TACACS, security protocols like DES, MD5, PPTP and SSH, A full chapter for firewalls, a full chapter for router security. A very clear and detailed VPN chapter has been followed by wireless security. Wireless security includes both technology related titles like WEP, EAP and history of war walking and wireless hacking tools. IDS chapter is so informative and honeypots was a new term for me explained in this chapter. Last chapter is about real world hacking tools.

Most interesting thing in this book for me was second chapter completely dedicated for security policies. Explains basics of building security policies and than it gives some reusable security policy samples.

Mentioned tools mostly open source tools which you can easily download from Internet and work on your own in more detail. Related URLs has been given for tools and organizations. This will let you use this book as a start point for your further security studies.

He mention about his own company (Granite Systems) in some points. I have to say there are some hidden advertising on it.

Conclusion
This book does the trick. Get one copy of it for your own. I am aware this book has been published in 2004 and I am suggesting it in 2009. I know what I said. You can download Chapter 8: Wireless Security under Sample Content tab from informIT website. You will see why I suggest it.

icon

]]>
http://cisco-network.com/book-reviews/network-security-first-step/feed/ 0
Is it worth it to getting CCNA Certified? http://cisco-network.com/jobs/worth-to-getting-ccna-certified/ http://cisco-network.com/jobs/worth-to-getting-ccna-certified/#comments Tue, 10 Feb 2009 20:46:45 +0000 MustafaAksu http://cisco-network.com/?p=51 It depends on how much you can invest on it – The money and your time.
To answer this question, we also need to know about your goal. You can continue with other Cisco certifications or maybe, you can change the line and mix it with something else.

Let’s have a look, which jobs openings are on the job boards to utilize a CCNA certificate.

OnTheCCRoad
I- You got only CCNA cert and you are in the way to be a network professional
This means that you are beginning your journey to become a network expert. You can work as junior admin in an environment where experienced network professionals work. You will do some daily task including monitoring, hardware installations (as the second guy), and routine things like configuration backup etc. In this position you cannot earn too much money, but it is a good investment for your bright future. If you spend one or two years while preparing for your CCNP, you will have the chance to choose the position, which you desire and also you will get a good income boost. CCNA certificate is a mandatory and foundational step for CCNP.

JustCCNA
II- You got only CCNA cert and you don’t want to invest more on it
If you say “CCNA is enough for me and I don’t want to waste more of my time and money for certifications”, then you can find a job in a mid size company as system/network admin. You have to look after windows servers and maybe some other systems. You can make an acceptable amount of cash and work in an environment without too much hierarchy. If you are good in relationships and you are practical in mind this is exact job for you. CCNA certificate is sufficient for this position. It will be very helpful in your career.

MsCCNA
III- You have got CCNA + some Microsoft certifications (like MCSE) + experience
In this case, your dominant specs are system admin specs. You already proved yourself in this area and can work in a Multinational Enterprise branch as senior system admin. You can cover network admin tasks with your CCNA certificate or better, in very large structures, it will let you to lead a team both system and network admins included.

NetSecCCNA
IV- You have got CCNA + Security certification (CISA+GIAC) + 3-4 years experience
You can work as System Security Engineer in Enterprise environment or you can work in a consulting company as information security auditor. Your CCNA certificate will let you have more expertise on network related issues and support your success.

ArchCCNA
V-You have got CCNA + more than ten years experience on Windows & UNIX
If you have development skills, project management skills and you have spent considerable number of years in several areas of IT business, then CCNA is not a big component in your skill set, but at least it shows people that you are still in touch with practicalities of network operations and it can help you achieve Enterprise Architect position.

Illustration of CCNA Career Paths

Illustration of CCNA Career Paths

As a step or as a component, CCNA is a valuable item in your personal inventory. It is worthy to get it and anybody can get the certificate, but you need other skills and experience to utilize it to the maximum extent. Initially you cannot expect high paying jobs ,but with some experience ,you can climb the ladder of success. For students, I strongly recommend participating to Cisco programs in colleges. This will help them to make an easy start for their careers.

If you want to see real jobs for CCNA holders, go to our job board and write CCNA in keyword box and click “Search Jobs”.

To get the answer of “What is a ccna worth?” as $ dolar figures, please have a look at below links.
Salary Survey Report for CCNA Certification
2006-2007 TCPMag.com Internetworking Salary Survey

]]>
http://cisco-network.com/jobs/worth-to-getting-ccna-certified/feed/ 0
Before buying an RPS for Cisco Catalyst Switches http://cisco-network.com/do-you-know/before-buying-rps-for-cisco-catalyst-switches/ http://cisco-network.com/do-you-know/before-buying-rps-for-cisco-catalyst-switches/#comments Wed, 07 Jan 2009 12:18:22 +0000 MustafaAksu http://cisco-network.com/?p=32 There are two issues that you have to be aware of when you are evaluating RPS solutions for fixed Cisco catalyst switches. Cisco has a product named Cisco Redundant Power System 2300 (RPS 2300) for the non-modular switch series like Catalyst 3560, Catalyst 3750. This is the successor of old Cisco Redundant Power System 675 (RPS 675).

You have only one bullet in your gun when you have an RPS

Switch draw power from RPS after power fail

Switch draw power from RPS after power fail


You can provide a limited redundancy to your network by installing an RPS for your Catalyst Switches. Switch survives without rebooting when main power goes off. It draws power from RPS, but it never return back to main power. An orange LED shows the switch powered by RPS. If you press the standby/active button on the RPS, your switch will reboot and become a normal operation. The only exception is E series switches + RPS 2300 combination. This combination could restore power state without rebooting.

RPS supports only one switch(in some cases two) at one time

Some of the switches will fail with a power circuit fail

Some of the switches will fail with a power circuit fail


You can attach up to 6 switches to an RPS, but if power Circuit 1 fails as shown in the above scenario then RPS only can support one switch and the rest will fail. RPS 2300 can support 2 switches if power requirements are moderate, but no more.

]]>
http://cisco-network.com/do-you-know/before-buying-rps-for-cisco-catalyst-switches/feed/ 0
Network Engineer Jobs http://cisco-network.com/jobs/network-engineer-jobs/ http://cisco-network.com/jobs/network-engineer-jobs/#comments Mon, 03 Nov 2008 21:23:53 +0000 MustafaAksu http://cisco-network.com/?p=25 I have included a job board for network engineers on this web site. You can find the link on the top navigation as cisco network jobs.

I am sure that it is not the main goal of this web site to find a new job for you or the best employee for new openings. However, it is good to be aware of the skills that people are looking and it is beneficial for both the employer and employee.

I used to attach a recent job posting on my freezer door. It is not that I am looking for a new job or higher pay, but it just reminds me that there are many alternatives and I can jump anytime. Now I am checking online job listings like Craigslist. This is why I really impressed when I saw Simply Hired has an offer to add this job board to my site.

For the employer, this is one of the best places to find amazingly talented network professional. Our visitors are network professionals who have spent years working on networking and internet. As an employer, you have to only make an attractive offer that they cannot reject. You can post it here if you want to hire a talented network engineer.

I will appreciate you very much if you can leave your opinion.

]]>
http://cisco-network.com/jobs/network-engineer-jobs/feed/ 0
Network Monitoring Tools http://cisco-network.com/hands-on/network-monitoring-tools/ http://cisco-network.com/hands-on/network-monitoring-tools/#comments Sun, 13 Jul 2008 11:23:45 +0000 MustafaAksu http://cisco-network.com/?p=24 What are your daily duties as the network administrator? You have to keep your network up and running. You have to answer calls which may relate to situations like “X location is down” or “Y location is slow”. You should monitor your network as described below to fulfill the tasks.

  • You should monitor your network and take actions with respect to situations like device and line failures.
  • You should analyze line utilizations, errors on the line and be sure about network performance.
  • You should be aware of who talks with whom? How much bandwidth is needed for every single application?
  • And sometimes, you need to see exact data flow over the network.

If you have all these information ready, then people will think twice before they point finger at you. How can you achieve this?
We need a layered approach to understand network monitoring. I am not talking about network layers, but network monitoring layers. We have to involve deeply to monitoring layers before decide about network monitoring software needs. A simple summary could be like below.

  • Preconditions of network monitoring.
  • Up/Down monitoring
  • Performance Monitoring / SNMP monitoring
  • Who talks with whom? / Netflow monitoring
  • Data capture / Data sniffing

network monitoring tools
Preconditions of Network Monitoring
Network documentation is essential to monitor a network. Trying to set up network monitoring tools before going through the documentation is complete waste of time. You will see everything green on the screen, but this maybe due to one of the redundant lines that are down. You will sit staring without knowing what is happening. Always remember, documentation comes first and everything follows.
Suggested monitoring tools: Powerpoint/Visio, NetViz

Up/Down monitoring
You have a map in which you can see some red and green lights glowing. Green means up and red means down. It is simple yet powerful. You will immediately come to know that there is some problem if the red light glows.
This is based on ping. Almost every IP devices support echo/echo reply. So, you can monitor all IP devices in your network by using ping. You go one step further by monitoring one application at a time present on a device instead of whole device. All network applications utilize TCP/UDP ports. You can monitor the applications by trying to access with telnet to its TCP/UDP ports. The port being open suggests that the application is running

Suggested monitoring tools: WhatsupGold, nmap

Performance monitoring / SNMP monitoring
The lines are up, the devices are up, but life is not perfect. People complain about performance of data lines. Are they saturated? Do we have package losses on the lines? Are routers running out of memory? We need SNMP to monitor heart beat of the network.

Suggested monitoring tools: MRTG, Solarwinds Orion, PRTG

Who talks with whom? / Netflow monitoring
You realized that the line is full. Someone / some applications make increase traffic load enormously. Who are they? Is it necessary traffic? In Cisco devices, by using “ip accounting” command we can get an idea of current traffic sources and destinations. Nevertheless, to analyze and to optimize the traffic we need flow monitoring. We need to know source and destination IP addresses and TCP/UDP ports and number of packages/bytes.
Everyone blames the network speed until you publish the network usage report that clearly shows only 15% of the traffic is ERP traffic and rest comes Internet access.
You should know that flow monitoring tools requires more server resources, since they collect enormous amount of data.

Suggested monitoring tools: Fluke Netflow monitor, Paasler

Data capture / RMON – Sniffer tools
Sometimes you need to observe the exact data flow on the line and not just information about it. Just have a look at this sample scenario. After you find out that the web service causes inappropriately high network traffic, the owner of the application just can say “No, we are not pushing this much of data to network. We just respond Yes or No in this web service and it is just 100 bytes”. Therefore, you should sniff the data flow on the line. Maybe, you will find that web service responds yes or no (100 bytes) and with the definition of web service (6 kilobytes).

Suggested monitoring tools: Wireshark

You can have a look at Network Monitoring Tools in Stanford University web site for a great list of network monitoring tools. You can find another tidy list at Network Traffic Monitoring in Alan Kennington’s topology.org.

]]>
http://cisco-network.com/hands-on/network-monitoring-tools/feed/ 4
Reflexive Access Lists http://cisco-network.com/hands-on/reflexive-access-lists/ http://cisco-network.com/hands-on/reflexive-access-lists/#comments Thu, 20 Dec 2007 22:23:53 +0000 MustafaAksu http://cisco-network.com/hands-on/reflexive-access-lists/ Cisco IOS has statefull firewall features like reflexive access lists. By using this feature, you can use your Cisco router as a second firewall (the choke point concept in Cisco firewall trainings) and increase your network security by layered approach.

You can use an access control list (ACL) for the filtering one way traffic, but what about the responding packages. You have to add an incoming ACL and it should include only sessions started from internal. Reflexive ACLs helps us in this point.

Requirements
To use reflexive ACLs
1. You MUST use named access lists
2. You MUST add “reflect samplename” to the end of permit line.
3. You MUST create a second named access list and add “evaluate samplename” line for responding traffic.

Sample Scenario
In our example, we have a proxy server (e.g. Microsoft ISA Server) with 122.22.22.1 IP address. This server needs access to internet via http (tcp 80) for web browsing and via dns (udp 53) for name resolution.
Reflexive ACLs Sample

interface Serial0/0/0
description Internet connection
ip access-group INBOUND in
ip access-group OUTBOUND out
!
ip access-list extended OUTBOUND
permit tcp host 122.22.22.1 any reflect PROXYTCP
permit udp host 122.22.22.1 any eq domain reflect PROXYUDP
!
ip access-list extended INBOUND
evaluate PROXYTCP
evaluate PROXYUDP
!

We used reflect command to create reverse ACL and we added it to inbound ACL with evaluate command.

Last Words
This feature is really a powerful tool to increase network security, but you should not use it instead of a real firewall for Internet access. It should be used as another security layer.

]]>
http://cisco-network.com/hands-on/reflexive-access-lists/feed/ 2
The new 640-802 exam & CCNA http://cisco-network.com/training-certification/the-new-640-802-exam-ccna/ http://cisco-network.com/training-certification/the-new-640-802-exam-ccna/#comments Sat, 08 Dec 2007 10:06:49 +0000 MustafaAksu http://cisco-network.com/training-certification/the-new-640-802-exam-ccna/ I just took 640-802 exam and got my CCNA certification. It may sound funny, but I have taken this exam after 10 long years of practical experience in networking and was very nervous!
Why do you need a Cisco Certified Network Associate certificate Mustafa?
Actually, I did not have plans for certification. If I get a CCIE certification, then it would be good for my career (not for salary but to change my job). On the other hand, I was afraid of to take the CCIE exam. I do not have a good history with exams. I took ten years to finish my Computer Science degree (normal period is 4 years)!

Two months ago, I heard that 640-801 exams will be expired and Cisco added one more milestone to career path as CCENT. I told my wife about it and she gifted me exam fee to take up the exam. I had all this pressure on me.

Preparations and exam
I managed to get two days off, one day for preparation and one day for the exam. I also spent the last three evenings for this purpose. I did not attend any Cisco training class and use only CCNA Prep center (Exam Study tab) for preparation. This web site is very useful and the content provided is sufficient enough for experienced professionals. If you start from scratch, then it will be good for you to attend a Cisco CCNA class, but not a CCNA bootcamp. This is not a big deal. Don’t waste your money.

Exam day did not start very good. Whether was rainy. There was a traffic jam. I reached the exam center just 5 minute before my reservation. A cute girl told me that I can start two hours later because of some technical problems. I spent that time in a café (well known chain), near the exam center. I realized again, these cafes are not as good as people believe them to be (tables, pictures etc. fine but what about the taste). When I returned back to exam center another cute girl told me that they are just downloading the exam. I had to wait 15 minutes more. Cable paths caught my attention, I easily came to know that bad materials were used and it was installed by an inexperienced staff.

Lectures / Lessons Learned
- Time is enough, don’t hurry
- You need to know basic configuration of RIPv2,OSPF,EIGRP
- Basics of routing algorithms
- Be able to configure NAT
- Be able to configure DHCP
- Understanding of ACL
- Basics of wireless network, how WPA works
- No questions like binary equivalent of something
- But be able to calculate subnets
- Match given IPs to given topology/schema
- Differentiate the terms MAC,IP and TCP/UDP ports
- How a packet travels within network(ARP, encapsulation)
- OSI layers vs. TCP/IP layers
- Chose the exam center with pretty girls , they keep you lively!

In general, exam went better than I expected. Questions were mostly meaningful and for me it required just two days to study.

]]>
http://cisco-network.com/training-certification/the-new-640-802-exam-ccna/feed/ 12
Advanced SSH settings for Cisco IOS http://cisco-network.com/hands-on/advanced-ssh-settings-for-cisco-ios/ http://cisco-network.com/hands-on/advanced-ssh-settings-for-cisco-ios/#comments Sun, 25 Nov 2007 20:40:28 +0000 MustafaAksu http://cisco-network.com/hands-on/advanced-ssh-settings-for-cisco-ios/ I mentioned about basic SSH setting in SSH@Cisco article. But I saw that there are other questions about SSH settings, so, I decided to dive a bit deeper. The settings mentioned below are tested with IOS 12.4, but I am not sure about exact version that supports below features.

Q1. What happens if I changed hostname or ip domain name after SSH settings has been done?
A1. Nothing. You need them to create rsa keys but, but afterwards, if you change them, only the key name changes and key data remain same.

ciscolab#sh crypto key mypubkey rsa
% Key pair was generated at: 13:08:15 UTC Aug 28 2007
Key name: ciscolab.mydomain.com
Storage Device: private-config
Usage: General Purpose Key
Key is not exportable.
Key Data:
30819F30 0D06092A 864886F7 0D010101 05000381 8D003081 89028181 00B67A9F
EED05E82 FFE41EB0 0CE9BC9E 40D1DD1D CF7AA44F CB5C1029 9502C379 469BF37D
099082BD 9618CC4E 8314866E 3B26F01B BE3AC27E 33EC7A2D 7FE5B503 3C24500B
733B391A D2DC4AAF C322C549 8A4638F1 9EAA0FF1 0ABCACD3 B1DF9753 02790FD7
E6A29602 39EFBAB4 2D4D7119 5C95D403 E1E9EB40 E01A1679 231C2F93 53020301 0001
.
.
ciscolab#conf t
Enter configuration commands, one per line. End with CNTL/Z.
ciscolab(config)#hostname sshrouter
sshrouter(config)#end
sshrouter#sh crypto key mypubkey rsa
% Key pair was generated at: 13:08:15 UTC Aug 28 2007
Key name: sshrouter.mydomain.com
Storage Device: private-config
Usage: General Purpose Key
Key is not exportable.
Key Data:
30819F30 0D06092A 864886F7 0D010101 05000381 8D003081 89028181 00B67A9F
EED05E82 FFE41EB0 0CE9BC9E 40D1DD1D CF7AA44F CB5C1029 9502C379 469BF37D
099082BD 9618CC4E 8314866E 3B26F01B BE3AC27E 33EC7A2D 7FE5B503 3C24500B
733B391A D2DC4AAF C322C549 8A4638F1 9EAA0FF1 0ABCACD3 B1DF9753 02790FD7
E6A29602 39EFBAB4 2D4D7119 5C95D403 E1E9EB40 E01A1679 231C2F93 53020301 0001
.
.
sshrouter#

Q2. Is there any other way to create rsa keys?
A1. Yes, There is. You can create rsa keys which are labeled by you. In this case, you don’t need a hostname(Always, you will have one) and an ip domain name.

ciscolab(config)#crypto key generate rsa general-keys label TEST
The name for the keys will be: TEST
Choose the size of the key modulus in the range of 360 to 2048 for your
General Purpose Keys. Choosing a key modulus greater than 512 may take
a few minutes.

How many bits in the modulus [512]: 1024
% Generating 1024 bit RSA keys, keys will be non-exportable…[OK]

ciscolab(config)#

Nov 24 20:08:59: %SSH-5-ENABLED: SSH 1.5 has been enabled


Q3. May I create more than one key?

A3. You can create several keys and chose one of them to use with SSH.You do not need to define which key to be used, but if you want to define, then you have to issue “ip ssh rsa keypair-name” command in the configuration mode.

ciscolab#sh crypto key mypubkey rsa
% Key pair was generated at: 20:08:59 UTC Nov 24 2007
Key name: TEST
Storage Device: not specified
Usage: General Purpose Key
Key is not exportable.
Key Data:
30819F30 0D06092A 864886F7 0D010101 05000381 8D003081 89028181 00BDFABF
948EF1FC 1CFC6C5C F5863980 D7D7B9E6 B256D84F 8F279E2E 63303403 A26E6160
A2928C87 4F0A846E F8A9FB0A 7D92108F ABD5734C AE7555BC 94CB13D9 41E8E04C
1514A499 68CC9925 A3DB2CFA 3176A65E 2DC504EE EF5C209E 4D348B20 9C324CBC
230451DD 96EC090C 99C5FB58 E06876D3 161E758E 486987B7 CD147AB0 0F020301 0001
% Key pair was generated at: 20:08:59 UTC Nov 24 2007
Key name: TEST.server
Temporary key
Usage: Encryption Key
Key is not exportable.
Key Data:
307C300D 06092A86 4886F70D 01720103 00036B00 30680261 00AEC9A3 4078450F
B1714135 F66FC617 3083F337 1309D493 654BC77D 4D08DE27 5A54FF44 C4CE0174
507385A9 99B93D70 4E980CE1 89465B14 00E2C26D A633F1FB C4D08A90 3A8EF761
EBB41B0D C3EB2190 E4FD1E4B E519A06E 4B6BAE46 4E1FA9D8 C1020301 0001
% Key pair was generated at: 20:11:56 UTC Nov 24 2007
Key name: CHECK
Storage Device: not specified
Usage: General Purpose Key
Key is not exportable.
Key Data:
305C300D 06092A86 4886F70D 01720103 00034B00 30480241 00CCB917 D58E9D45
BC5EFF15 E2945343 18E5338B 26E1ED9F 869C2B6F 77C27595 8AC0D7B7 9D503F31
192D08EF C5DE87B5 911779BD 464913CD BB93F883 6F23AE0A 91020301 0001
ciscolab#

ciscolab(config)#ip ssh rsa keypair-name CHECK

Q4. May I create more than one session from same computer like telnet?
A4. Yes.

Q5. Is it possible to use SSH1 and SSH2 at the same time?
A5. Yes. If you don’t fix the version with “ip ssh version” configuration command. You can use both protocol simultaneously as shown below.

ciscolab >sh ssh
Connection Version Encryption State Username
0 1.5 3DES Session started sshtest
Connection Version Mode Encryption Hmac State Username
1 2.0 IN aes256-cbc hmac-sha1 Session started sshtest
1 2.0 OUT aes256-cbc hmac-sha1 Session started sshtest
ciscolab>

As you can see here SSH1 uses 3DES and SSH2 uses AES.

Q6. Does SSH cause a slowdown on my device?
A6. No. I made some tests with both SSH1 and SSH2. Tests have been done on Cisco 7206 VXR, Cisco 3845 and Cisco 1841 with size of key modulus 2048. In the 1841 router, key generation took some time (30-40 seconds). There was a small delay (1-2 second) when I first connected the device, but rest of the interaction was same like the telnet. CPU utilization was at %1 and memory was OK.

Q7. I have copy my whole router / switch configuration but SSH does not work. Why?
A7. Did you create rsa certificate? Crypto key generate command is a configuration mode command, but it is not a part of the configuration. It will be used for creating your rsa certificate then it is gone. So, just copying configuration is not enough.

Please leave a comment if you have any other questions.

]]>
http://cisco-network.com/hands-on/advanced-ssh-settings-for-cisco-ios/feed/ 3