Search This Blog

Monday, April 6, 2015

CCNA Security: Security Policy Using a Life Cycle Approach

CCNA Security: Security Policy Using a Life Cycle Approach


Risk Analysis and Management


Secure Network Life Cycle


  • Initiation: Preliminary risk assessments and categorization
  • Acquisition/Development: Detailed risk assessment, acquiring countermeasures to reduce risk, testing countermeasures
  • Implementation: Where countermeasures are deployed into a production network
  • Operations/Maintenance: Monitoring and incident handling of network security devices
  • Disposition: Disposing of network equipment, including wiping/sanitizing


Risk Analysis Methods


  • Qualitiative: Data is gathered by an individual subject matter expert of the asset who can speak to its value and vulnerability
  • Quantitative: Numbers and statistics determine risk
Using both methods yields a risk score which allows companies to justify cost of risk mitigation techniques


Security Posture Assessment


  • General Assessment: High-level idea about security state of network devices with intent to identify vulnerabilities
  • Internal Assessment: Identify how well protected the network is from internal attack
  • External Assessment: Assess security risks from devices that connect from the outside of the network
  • Wireless Assessment: Identifies vulnerabilities and weaknesses associated with wireless implementation, such as AP range allowing external access from outside the building
  • Analysis/Documentation: Report combining details about vulnerabilities taht may exist following security assessments and recommended solutions to mitigate attack


One Approach to Risk Management


When determining risk score of an asset, consider:
  • Asset Value
  • Vulnerabilities
  • Compliance Issues
  • Potential Threats
  • Business Needs
For new assets for which risk has not been identified, a qualitative/quantitative risk assessment should be performed, appropriate mitigation measures taken (transfer, acceptance or reduction in risk with countermeasures), and then the risk should be monitored


Regulatory Compliance Risk


Impact of not complying with local/state/federal compliance rules should be considered as part of risk assessment


Security Policy


Executive senior management is ultimately responsible for data, data governance policy must be created at high level from executive senior management such as an Acceptable Use Policy

Security policies have risk management as a primary aspect that should include an overview about the policy, what it covers and does not cover, Scope of Policy

Security policies exist to educate users about the company policy is in terms of security measures needed to be followed/enforced


Specific Types of Policy


  • Guideline: AUP, audit policy, password policy, etc
  • Email: Spam / Forwarding policies, etc
  • Remote Access: VPN access, minimum requirements for remote access such as virus scanning, etc
  • Telephony: Acceptable use of phone services
  • Network: Standards for access over wired or wireless, minimum requirements for PCs connecting to network, etc
  • Application: Minimum security features needed in applications, restrictions on what end users can install and run on company computers

Standards/Procedures/Guidelines

  • Standard: Specifies the use of specific technologies as countermeasures
  • Procedures: Document encompassing standards and guidelines for implementing security for the network, allows consistency in implementation of security
  • Guidelines: Best practice, suggestions, used in place of solid direction in order to determine best course
  • Policies: High-level documents that define strategic objectives of security, not technical in nature


Testing Security


Several techniques used to test security of a network:

  • Network Scanning
  • Password Cracking
  • Penetration Testing
  • Vulnerability Scanning
  • Social Engineering

Responding to Incidents

  • Assist in recovery of business operation while preserving attack evidence for forensics
  • Document details of incident
  • Prevent future incidents similar to one just experienced

Collecting Evidence

Equipment involved should be photographed or otherwise shown to be untampered with to preserve chain of evidence should a matter be brought to court. Disk storage should be saved before being disconnected, etc


Disaster Recovery and Continuity of Business Planning


Risk assessment can determine proper DR/ConOps strategy. Cost of maintaining DR should be weighed against potential business loss of not having DR. Max Tolerable Downtime (MTD), Recovery Time Objective (RTO) and Recovery Point Objective (RPO) are needed to deterine proper DR strategy

RTO: Number of hours/days needed to resume business
RPO: State of data restoration, ie restoring to 4 hours after disaster occurred
 


Thursday, April 2, 2015

CCNA Security: Network Security Concepts

               CCNA Security: Network Security Concepts


Basic Network Security Objectives


  • Confidentiality
Data at rest should be protected by authentication to ensure sensitive information is restricted
Data in motion should be protected by encryption/isolation as it moves through the network

  • Integrity
Data integrity is concerned with making sure that only authorized sources are manipulating data

  • Availability
For systems and data, availability refers to the ability to access data by authorized users


 Cost/Benefit Security Analysis

Risk management deals with identifying assets, threats/vulnerabilities and countermeasures that make sense commeasurate to the value of the asset

Asset: Anything that has value to an organization such as property or data

Vulnerability: Exploitable weakness in a system or its design

Threat: Potential danger to an asset. An unrealized threat is a vulnerability that has not yet been exploited. A realized threat is a successful attack against an asset. Attacker is a threat agent or threat vector.

Risk: Potential for compromise/destruction/access to an asset

Countermeasure: Safeguard that mitigates risk by eliminating or reducing a vulnerability, or otherwise making the asset less vulnerable.


Thresholds apply to classification, generally a countermeasure or risk mitigation would not cost more than the value of the asset excepting government/financial regulations, etc


Classifying Assets


Assets can be classified so that policy can be developed on how to take action for certain classifications

Government Classifications
  • Unclassified
  • Sensitive But Unclassified
  • Confidential
  • Secret
  • Top Secret

Private Sector Classifications
  •  Public 
  • Confidential
  • Sensitive 
  • Private

Classification Criteria
  • Value
  • Replacement Cost
  • Lifetime
  • Age


Classification Roles
  • Owner: Person or group ultimately responsible for the data
  • User: People who access the data any abide by acceptable use policy
  • Custodian: Group responsible for implementing policy dictated by owner


Classifying Vulnerabilities

 Potential Vulnerabilities

  • Policy Flaw
  • Misconfiguration
  • Protocol Weakness
  • Design Error
  • Software vulnerability
  • Malware
  • Hardware vulnerability
  • Human ffactor
  • Physical Access to Resources

 Classifying Countermeasures


Control Methods to Implement Countermeasures

  • Administrative: Policy, procedure, change control
  • Physical: Locked doors, access badges, cameras, etc
  • Logical: Passwords, firewalls, VPN, IPS, access lists





Recognizing Current Network Threats

 

Potential Attackers

  • Terrorists
  • Hackers
  • Government Agencies
  • Competitors
  • Criminals
  • Nation-states
  • Disgruntled Employees
  • Anyone that can access a computer


Attack Methods

  • Reconnaissance: Discovery process used to find information about the network. Port scans, IP scans, etc
  • Social Engineering: User compromise, email, misdirection of web pages, phishing, pharming
  • Privilege Escalation: Escalating level of access beyond what is allowed by policy/role
  • Back Door: Application or user access left behind by an attacker to allow future access


Attack Vectors

Attacks can be launched from outside or inside company, even by authorized users. Using ICE/NAC or 802.1x can help mitigate authorized users from launching attacks internally 

 

 

Man-in-the-Middle Attack


 Attacker places itself between two devices that are communicating to perform reconnaissance or manipulate data as it moves between them. Main purpose is eavesdropping so attacker can see all traffic.


Layer 2 MITM Attacks
  • ARP Poisoning: Attacker spoofs MAC address of actual default gateway in order to become gateway for the clients. Can be mitigated with Dynamic ARP Inspection
  • Root Bridge Attack: Attacker connects switch to network with intent of becoming spanning-tree root bridge and forcing all traffic through that switch. Mitigated by Root Guard and BPDU Guard.


Layer 3 MITM Attacks
  • Rogue Router: Rogue router can inject routes with better metric to force routing to go through the rogue router. Mitigated by routing protocol authentication and only listening for routing protocols on specific interfaces


Miscellaneous Attack Vectors

  • Covert Channels: Uses communications in unintended ways such as tunnelling P2P file sharing inside of HTTP traffic, or a backdoor using ICMP to communicate with an attacker 
  • Trust Exploitation:  Attacker leverages implied trust relationship to gain access, such as exploiting a DMZ server that can communicate to the inside to launch attacks internally
  • Password Attack: Brute force attacks to guess passwords, MITM or key logging software
  • BotNet: Infected computers that listen for command/control signals from an attacker utilizing a backdoor channel to communicate
  • DoS and DDoS: Usinga  botnet to target a particular system in order to flood it with malicious traffic with the intent to deny legitimate access


Applying Fundamental Security Principles to Network Design

Guidelines

  • Least Privilege: Minimal access to perform the function is assigned and no more
  • Defense in Depth: Security is implemented in multiple places on the network, such as a firewall with an IPS, host-based firewall, etc
  • Separation of Duty: Specific individuals are placed into specific roles, allows checks and balance regarding implementation of security policy
  • Auditing: Keeping records of what is occurring on the network using things like AAA and syslogs, logs can be reviewed to check access and events

Wednesday, February 4, 2015

CCNA Voice: The CME Dial-Plan

The CME Dial-Plan


Physical Voice Port Characteristics


Analog Voice Ports



Foreign Exchange Station (FXS): Connect to end stations such as analog phones and fax machines

Three normal configuration options:

  • Call signaling
  • Call tones
  • Caller ID Info
Call signaling:

voice-port (port number)
signal (loopstart or groundstart)


Call Tones: 

voice-port (port number)
cptone (Two letter country code)


Caller ID Info:

voice-port (port number)
station-id name (Name)
station-id number (Number)



Foreign Exchange Office (FXO)


Same configuration options as above with two extra:


  • Dial-Type
  • Ring Number
Dial-Type: Tone or Pulse Dialing

voice-port (port number)
dial-type (dtmf or pulse)



Ring Number: Number of rings that should pass before the router picks up the line

voice-port (port number)
ring number (number)





show voice port summary shows status of voice ports on router



Digital Voice Ports


Can be configured as CAS or CCS

Common Configuration:

clock source line
framing esf
linecode b8zs


CCS:

controller (port number)
pri-group 1 timeslots 1-24 (For T1)


CAS:

controller (port number)
ds0-group 1 time-slots 1-24 (For T1)


For T1, channel 24 (time-slot 24) is signaling
For E1, channel 16 (time-slot 17) is signaling



Dial-Peers










Call Processing / Digit Manipulation






Class of Restriction







Quality of Service



Thursday, January 22, 2015

CCNA Voice: Managing Users and Devices with CME

Managing Users and Devices with CME


Three key items needed to get CME configured:


  • IP Source Address
  • Max-DN
  • Max-Ephones

IP source address determines what interface will expect IP phone registration requests

Max-DN / Max-Ephone configuration reserves resources on the router and max-ephone should not exceed number of licenses purchased


Ephone / Ephone-DN Configuration




Can be configured as single-line, dual-line or octo-line

single-line ephone-dn: Can only make or receive a single call at a time. If in use caller will receive a busy signal

dual-line ephone-dn: Phone can handle two simultaneous calls and supports features such as call waiting, conference calling and warm transfer

octo-line ephone-dn: Typically use for shared lines where many share the same extension or receptionist phones


Configuration Example with CLI


EPHONE-DN

config t
!
ephone-dn 1
number 2000
!
ehone-dn 2 dual-line
number 2001 secondary 2085551212

EPHONE

ephone 1
mac address  00ab.5454.65ba


LINK EPHONE TO EPHONE-DN

ephone 1
button 1:2
!
restart


button command links ephone-dn 2 to button 1 on ephone 1

restart command tells phone to do warm reboot and redownload configuration file from TFTP server

Button assignments can be verified with show ephone command




Configuring Users, Phones and Extensions with CCP


Telephony Service is configured from the Configure > Unified Communications > Telephony Settings

Same three key items are required:


  • Max-Ephones
  • Max-DNs
  • IP Source Address

Once telephony services are activated, CCP can be used to configure users, extensions and phones


Configure Extensions


Configure > Unified Communications > Users, Phones and Extensions > Extensions

Configure DN, description, secondary DN if applicable, line type, click OK


Configure Phones


Configure > Unified Communications > Users, Phones and Extensions > Phones

Configure model of IP Phone, MAC address, click OK


Configure Users


Users must be created to link DN to IP Phone together with CCP

Configure > Unified Communications > Users, Phones and Extensions > User Settings


Add details:

  • User ID (Only field required)


Other optional fields:
  • First and last name
  • Display Name for Caller ID
  • Password
  • PIN

Click Phones/Extensions tab to associate user with phone and extension(s) via drop-down boxes

Click OK



CCP has template of show commands via drop-down box for troubleshooting, also functions as free-form typing box for show commands that can be accessed via:

Configure > View > IOS Show Commands



CCNA Voice: Introduction to CME Administration

CME Administration


Command Line Management


Use one of three methods to access CLI:

  • Console Port
  • Telnet
  • SSH

telephony-service configuration command activates CME functionality on a router that supports it

Core CME config commands are performed under telephony-service configuration

show ephone registered command shows phones registered with CME and is most common verification/troubleshooting command



GUI Management


Two flavors: Integrated CME GUI and Cisco Configuration Professional


Integrated CME GUI


Files loaded into flash of router, with assigned IP and http server service turned on the router

Focused on telephony, not pretty


CCP


Can configure all major elements of routers

Wizard-based

Local install on client PC, can be used to manage any supported Cisco platform

CCP Configuration


Before managing devices a community must be configured

Community consists of devices to be managed

Devices to be managed must be configured with four things to support CCP control:

  1. Reachable IP from CCP
  2. Level 15 Username/password on device
  3. HTTP services turned on
  4. Local authentication
CCP uses Telnet/HTTP by default, can be configured to use SSH/HTTPS

When a device is discovered by CCP it populates CCP with info

Unified Communications can be configured on a router (if not already enabled) in one of four ways:

  1. CME Standalone
  2. Voice Gateway (PSTN to VOIP or analog to digital)
  3. CME as SRST (CME acts as failover device if CUCM communication is lost)
  4. None
CCP has a configuration confirmation screen that shows what commands are to be delivered to the router before being applied, in order to verify correctness prior to submitting





Saturday, January 17, 2015

CCNA Voice: IP Phone Concepts and Phone Registration

IP Phone Concepts and IP Phone Registration


Connecting/Powering Cisco IP Phones

Three sources of power for IP phones available:

  • Catalst Switch PoE (pre-standard 802.3af)
  • Power Patch Panel PoE (pre-standard 802.3af)
  • Cisco IP Phone Power Brick (facility power)

Catalyst Switch PoE


Cisco Inline Power existed before official standard 802.3af was developed and used unused pairs in ethernet cable to deliver power

802.3at power standard created to increase maximum wattage fro 15.4W to 25.5W


Power Patch Panel


Patch panels are powered and inject power onto ethernet line as an intermediary

Lower cost than switch upgrades, but switches in use must otherwise support QoS and voice vlans or the switches need to be upgraded anyway, eliminating lower cost

Inline PoE Injector is even lower cost but requires dedicated power plug for each injector, not scalable


Cisco IP Phone Power Brick

Must be purchased separately from Cisco, one per phone, requires dedicated power plug for each phone brick

If IP phones have added modules (ie sidecar) then switch PoE is no longer sufficient and a brick is needed


Voice VLAN Concepts/Configuration


Cisco IP Phones support VLAN tagging and use CDP to discover voice vlan

PC can not understand tagged frames, so IP phone must strip tags before delivery to attached PC

Phone tags its own packets with voice vlan


VLAN Configuration


  1.  Add voice vlan to switch
  2. Configure IP phone switchport with mode access, access and voice vlan numbers
  3. Enable port for spanning-tree portfast to allow IP phone to boot quickly

Cisco IP Phone Boot Process


  1. IP phone receives power from the switch or one of several aforementioned power solutions
  2. Switch delivers voice vlan info to phone using CDP
  3. IP Phone sends DHCP request on voice vlan
  4. DHCP server responds with IP address offer
  5. IP phone receives DHCP option 150 with IP address and other normal info such as gateway and DNS
  6. Option 150 directs IP phone to TFTP server address to pull configuration of the IP phone
  7. Configuration includes call processing server IPs (CUCM or CME)
  8. IP Phone attempts to register with a call processing server in order of the list in the configuration

Config files are named by phone, ie, SEP(MAC ADDRESS OF IP PHONE).cnf.xml

If this file does not exist on TFTP server, IP Phone requests XMLDefault.cnf.xml that has base configuration for auto-registration with CME/CUCM


 Configuring a Router as the TFTP Server

  1. Create DHCP scope on router
  2. Add network, default gateway, dns server (optional) and option 150 address pointing at the router's voice vlan IP
  3. Ensure the configuration files are accessible on the router for the IP Phones to download 

NTP for Cisco Devices


Accurate clocks on devices are needed for the following reasons:

  • Correct date/time displayed for users
  • Correct date/time assigned to voicemail tags
  • Accurate CDR records
  • Many security features rely on accurate time
  • Logs on routers/switches are accurate with correct time

clock set command can manually set time

Stratum of NTP server determines how far away the device is from a radio/atomic clock

ntp server (IP ADDRESS) configures the device to use a server for NTP

clock timezone (name) (UTC Offset) command configures time zone

To configure the device as an NTP server, command ntp master (stratum number) is used


IP Phone Registration


Required steps before registering:

  1. IP Phone has received power
  2. IP Phone has voice vlan information via CDP
  3. IP Phone has DHCP address and option 150 address
  4. IP Phone has downloaded its configuration from TFTP server
IP Phone configuration will list up to three call processing servers (CME/CUCM), IP Phone will attempt to register in order until it successfully registers with one

Registration is done with either SCCP or SIP depending on phone firmware

SCCP is Cisco proprietary, SIP is industry standard

Registration process is as follows;
  1. IP Phone contacts call processing server, identifies itself by its MAC to the server
  2. Server consults database and sends operating configuraton to the IP Phone including Directory Numbers, ring tones, softkey template, etc using SCCP or SIP
  3. SCCP/SIP used to use phone from that point, when IP phone buttons are pressed, handset is lifted off-hook, etc







Thursday, January 15, 2015

CCNA Voice: Unified Communications at a Glance

Unified Communications Pieces

Unified Communications Products


Core products:
  • Cisco Unified Communications Manager Express
  • Cisco Unified Communications Manager
  • Cisco Unity Connection
  • Cisco Unified Presence
Other products include Cisco Unified Contact Center Enterprise/Express, Cisco Unified MeetingPlace, etc



Cisco Unified Communications Manager Express


CME was designed for ISR G2 Routers, ISR G1 routers with proper IOS and hardware can also support CME 8.X

Key Features of CME:

  • Call control device, handles signaling, call routing, call features
  • CLI or GUI based configuration using CCP
  • Local telephone directory
  • CTI support for application integration
  • Trunk to other VOIP systems (ie, CUCM)
  • Cisco Unity Express Module direct integration with network module
CME controls almost all actions performed with Cisco IP Phones using SCCP or SIP

As user inputs to the phone, SCCP or SIP messages are sent between CME and IP Phone to determine what is happening

After call setup, RTP stream is created between two endpoints and CME is no longer involved

For calls to the PSTN, CME acts as the voice gateway and transcodes analog to digital signal using DSP/PVDM modules. During the call CME transcodes between PSTN and IP phone and can not be removed from call flow

Cisco Unity Express

Integrated hardware module for CME router to provide voicemail services. Either comes as ISM or SM. ISM is internal to CME router and uses flash memory for storage. SM is external and uses a hard drive for storage. ISM/SM replace CUE AIM and NM

CUE runs its own independent Linux-based OS which is accessible from CME router after install

Key features of CUE:

  • Voicemail
  • Auto-attendant for dial-by-name, basic operator/menu capabilities
  • IVR system with basic menu tree system, more features than Auto-attendant
  • Native T.37 Fax Processing, can receive faxes and process to user's mailbox as TIFF attachment
  • SRSV sets CUE to act as backup voicemail if enterprise Cisco Unity Connection is inaccessible
  • Standards-based SIP protocol signaling between CUE and CME


Cisco Unified Communications Manager


CUCM is the call processing director of a Unified Communications solution

Key Features of CUCM:

  • Complete audio/visual telephony support
  • Appliance-based, meaning the operating system is secured/inaccessible 
  • Redundant servers
  • Intercluster/voice gateway control/communications
  • Disaster Recovery System
  • VMWare virtualization support
  • LDAP/Active Directory integration support


CUCM Database Replication

CUCM IBM Informix Database includes info such as dirctory numbers, route plan, hunt groups, etc which is replicated to all servers in cluster

CUCM Runtime (real-time) data is replicated to other cluster members using Cisco proprietary Intracluster Communication Signaling (ICSS)

All servers in CUCM cluster form TCP connecions to each other for ICSS on port 8002- 8004 and keep each other informed

CUCM Publisher holds master copy of Informix database, changes to the database happen on the Publisher and are replicated to subscribers

Each cluster supports one Publisher and up to eight Subscribers. Publisher maintains database and  serves TFTP requests and Subscribers handle phone registration and call control

If Publisher fails, changes can not be made to database, excepting user-facing features such as call forwarding and DND button, etc. Subscriber writes local copy of change and replicates to other subscribers until Publisher returns online


Cisco Unity Connection

Cisco Unity Connection is an enterprise, appliance-based voice-mail solution similar to CUCM

Key features of CUC:


  • Appliance-based: Stable, hardened, appliance-based OS
  • 20,000 mailboxes per server
  • Remote access to voicemail via email, browser, IM and phone
  • LDAP/Active Directory integration
  • Microsoft Exchange supported for calendar integration, text-to-speech, etc
  • Voice Profile for Internet Mail: Standard which allows other voicemail servers to integrate for exchange of voicemail and other messages
  • Active/Active HA cluster with Publisher/Subscriber and Informix DB allows doubling of voicemail ports and mailboxes


If one of HA cluster fails, half the voicemail ports and mailboxes are inaccessible

CUC is able to integrate with other call control systems such as PBX and so does not have close integration with CUCM. CUC is set as an outside system that CUCM communicates with using SIP/SCCP

CUCM to CUC Call Flow:

  1. Incoming voice call hits CUCM from PSTN VG or internal call
  2. CUCM routes call to approriate IP phone
  3. If call is not answered, CUCM forwards call to Voicemail pilot extension
  4. CUCM transfers call to CUC with original extension in SCCP/SIP signaling which CUC uses to find appropriate mailbox
  5. After VM is recorded, CUC calls MWI extension on CUCM to toggle light on IP phone 

All communication takes place using voicemail ports
CUC can also integrate with CME


Cisco Unified Presence


CUP is used to track availability of a user and provide enterprise IM capability

Key features of CUP:

  • Enterprise IM using Jabber XCP
  • Logging functionality for all types of IM communication
  • Can connect to other domains such as Google Talk or WebEx
  • XCP allows CUP to extend to almost any part of the network, for file sharing, app sharing, videoconferencing. XCP integrates with directory services, databases, web
  • CUP application integration supports IPSec or TLS encryption to secure communication

Unified Personal Communicator


Software application that combines softphone, IM client, employee directory, video/web conferencing. Allows tracking of user status and virtual meetings

CUPC uses LDAP for login to the client and a CUPS server on the back end











Sunday, January 11, 2015

CCNA Voice: Traditional Voice Concepts

Traditional Voice to Unified Voice



Analog Voice Terms


Loop Start: Relies on connecting 'tip' and 'ring' wires in an analog device to complete an electrical circuit and causing electrical signal to flow from PSTN CO. Susceptible to Glare

Glare: Caused when a user signals the PSTN CO at the same time that a call is coming in, causing that incoming call to be routed to the user that just picked up the phone

Ground Start: Relies on grounding the analog wires which causes the PSTN to send electrical signal to the device, only used on outgoing calls so this can prevent Glare

Analog Challenges

Signal boosting required as distance increases, boosting also boosts line noise

Separate physical lines required for each phone line causes scaling issues

Digital Voice Terms


Digitizing: Process by which analog vice signals are changed to digital numbers

Time-Division Multiplexing: Allows voice networks to carry multiple conversations at the same time using time-slots for the digitized conversations

T1: Digital circuit comprised of 24 seperate 64-kpbs channels known as DS0, each one of which supports one call. Used in US, Japan, Canada

E1: Digital circuit comprised of 30 seperate 64-kpbs channels known as DS0, each one of which supports one call. Used in areas other than US, Japan or Canada

Channel-Associated Signaling: Binary bits for voice are stolen for signalling, also known as Robbed-Bit Signaling (RBS). Uses eighth bit on every sixth sample in each channel

Common-Channel Signaling: Dedicated T1 channel for signaling information. Also called out-of-band signalling. Most popular method is Q931. For T1 circuits the 24th time-slot is used for signalling, for E1 the 17th time-slot is used for signalling


PSTN Concepts


Analog Telephone: Common device using PSTN, converts audio to electrical signals

Local Loop: Link between customer premises and telecom provider

CO: Provides services on local loop such as signalling, digit collecting, routing calls and call setup/teardown

Trunk: Connection between CO or private switches

Private Switch: Used for business to operate internal PSTN instead of each phone having separate connection to external CO

Digital Phone: Converts audio into digital signal, more efficient than analog

PSTN Numbering Plan


E.164 Numbering Plan was created by ITU and contains:

  • Country Code
  • National Destination Code
  • Subscriber Number
North American Numbering Plan uses:

  • Country Code
  • Area Code
  • CO/Exchange Code
  • Station Code

PBX/Key System Concepts


PBX/Key System: Internally manages phone calls/phones, has several different kinds of cards and equipment. Calls internally are controlled by  PBX/Key System, calls to/from PSTN utilize trunk between PBX/Key System and PSTN CO

Line Cards: Connects telephone handsets to PBX system

Trunk Cards: Connects PBX to PSTN or other PBX Systems

Control Complex: Intelligence behind PBX System, performs call routing, setup/teardown and management functions


VOIP Business Benefits


Reduces cost by allowing use of WAN connections instead of PSTN charges
Reduces cost of cabling, requiring single Ethernet drop
Centralized dial-plan and command/control of calling
Move/Add/Change costs are eliminated
Softphones allow users to use headset and computer as a phone instead of needing hardware
Unified messaging such as email, fax, voice mail
Multiple device ring increases productivity by allowing users to be reached on multiple devices
Feature-rich communication such as screen popup when customer calls into a call center
Compatible standards to allow different vendors to work together


Converting Voice to Data


Average human ear can hear frequencies from 20-20,000 Hz
Human speech uses frequencies from 200-9000 Hz
Telephone channels usually transmit 300-3400 Hz
Nyquist Theorem produces frequencies from 300-4000 Hz

Nyquist Theorem: Accurately reproducing an audio signal require sampling the signal at twice its highest frequency, ie, for a 300-4000 Hz signal to be reproduced would require 8000 samples per second

Quantization: Process by which analog waves are converted into digital signal

1 byte represents value of 0-255, voice scale must be between 127 and -127

Amplitude values common to voice are more tightly spaced

Sampling breaks 8 binary bits in each byte into two components: numeric representor and positive/negative value

G.711 a-law used everywhere except US and Japan, 64kbps

G.711 u-law used in US/Japan, also 64 kbps but sampling valuies are reversed (1 bits are 0 and 0 bits are 1)

Compression measures applied to lower bandwidth requirements

G.729 compresses by sending sample once and instructing device to play that sound for a time value, reduces bandwidth to 8kbps

Mean Opinion Score: Rates quality of voice codecs



G.711 and G.729 are common codecs for all Cisco IP Phones


Digital Signal Processors



DSP: Hardware chip that provides sampling, compression, encoding functions to audio coming into the router

PVDM: Packet Voice DSP Modules, bundle multiple DSPs into one chip

DSP/PVDM can be added directly to the router's motherboard (if supported) or as part of a Network Module

Based on complexity of codec, PVDMs can handle more or less audio calls at once


RTP/RTCP


RTP: Real-Time Transport Protocol, Transport Layer protocol, uses UDP. Provides time stamps and sequence numbers to UDP packet so it can be reassembled in order (sequence) and reduce jitter (time stamp) on remote end. Uses even UDP port between 16384 and 32767 for each audio stream (a two way call will have two one-way RTP streams)


RTCP: Real-Time Transport Control Protocol, Used for statistics reporting. Picks odd number UDP port range between 16384 and 32767. 
Reports:
  • Packet count
  • Delay
  • Packet Loss
  • Jitter
If RTP stream uses 17654, RTCP will use 17655








Thursday, February 21, 2013

CCDA Notes: WAN Technology

WAN Technology


When designing a WAN solution, the requirements typically stem from two goals:
  • Service Level Agreement (SLA): This agreement defines the availability of the network, based on what level of availability, downtime and impact are acceptable to the organization.
  • Cost and Usage: Consider the budget, expected utilization and usage requirements
Three objectives of effective WAN solution design:
  1. WAN must support policies and goals of the organization
  2. WAN technology selected must meet application requirements as well as future growth
  3. The proposed design must be within the budget allocated
The WAN interfaces with the Enterprise Edge module. There can be multiple connections, commonly used connectivity modules include Internet, DMZ, and site-to-site circuits. ISPs offer many options for Internet and DMZ connectivity as well as inter-site connectivity such as MPLS VPN/WAN. Alternative connection options include DSL/cable with IPSEC VPN.

WAN technology can be point-to-point or point-to-multipoint, such as MPLS or Frame Relay. Public WAN connections over the Internet such as cable/DSL are available as well. Usually Internet connections have a much lower SLA than MPLS/Frame Relay connections.


WAN Transport Technology

When choosing which WAN technology to implement, consideration must be taken for whether public Internet transport or private WAN connections are required. Geography also plays a role in what WAN technologies are available in a given area. Major cities have many options, while rural areas typically have few. Here are some WAN technologies compared/contrasted in terms of bandwidth, reliability, latency and cost:

ISDN: Low bandwidth, medium reliability, medium latency, low cost
DSL: Low/medium bandwidth, low reliability, medium latency, low cost
Cable: Low/medium bandwidth, low reliability, medium latency, low cost
Wireless: Low/medium bandwidth, low reliability, medium latency, medium cost
Frame Relay: Low/medium bandwidth, medium reliability, low latency, medium cost
TDM: Medium bandwidth, high reliability, low latency, medium cost
Metro Ethernet: Medium/high bandwidth, high reliability, low latency, medium cost
SONET/SDH: High bandwidth, high reliability, low latency, high cost
MPLS: High bandwidth, high reliability, low latency, high cost
Dark Fiber: High bandwidth, high reliability, low latency, high cost
DWDM: High bandwidth, high reliability, low latency, high cost

Above technologies explained below:

ISDN

Integrated Services Digital Network was standardized in the early 1980's. It's an all-digital phone line that carries voice and data. It comes in two flavors: Basic Rate Interface (BRI) and Primary Rate Interface (PRI).

ISDN BRI

BRI consists of two B channels and one D channel. Both BRI channels operate at 64kbps and carry data. D channel handles signaling/control info and operates at 16kbps. 48kbps is used for synchronization, totalling 192kbps data rate.

ISDN PRI

PRI consists of 23 B channels and 1 D channel in North America/Japan. Each channel operates at 64kbps, totalling 1.544 Mbps including the overhead. In Europe/Australia the service has 30 B channels and 1 64 kbps D channel.


Digital Subscriber Line (DSL)

DSL provides high speed Internet over plain old copper telephone cable using frequencies not utilized in normal voice calls.

ADSL is the most popular flavor of DSL and most widely available. The upstream/downstream is asymmetric, usually upstream is much slower than downstream. ADSL's main drawback is that it must be deployed geographically close to a digital subscriber line access multiplexer (DSLAM), typically less than 2 km. With DSL, the customer premise equipment (CPE) generally means a DSL modem and PC. An ADSL circuit consists of twisted-pair telephone line containing three info channels:
  • Medium-speed downstream channel
  • Low-speed upstream channel
  • Basic telephone service channel
DSL splitters separate the voice and data traffic. Since DSL crosses the public Internet it is suggested to use DSL in conjunction with VPN to connect to the corporate network.


Cable


 

Sunday, February 17, 2013

CCDA Notes: Wireless LAN Design (Mobility and WLAN Design Best Practice)

WLAN Mobility


AP Controller Equipment Scaling

Cisco provides different solutions for supporting differing numbers of APs within an enterprise. Standalone WLCs, modules for Integrated Services Routers (ISR), and modules for 6500 switches. Below is listed different WLC types, followed by the number of supported APs that can be associated:
  • 2100 series WLC: 25
  • WLC for ISR: 25
  • Catalyst 3750 Integrated WLC: 50
  • 4400 series WLC: 100
  • 6500/6700 series WLC module: 300
  • 5500 series WLC: 500

To scale beyond the default 48 supported APs on a Cisco WLC:
  1. Use multiple AP interfaces: This option only works on 4400 series WLCs
  2. Use link aggregation (LAG): This option works on 5500 and 4400 series WLC, and is the default operation on Catalyst 3750 Integrated WLCs and Catalyst 6500 WiSM

The largest limitation of LAG is that only one may exist per WLC, so if a LAG exists all physical ports are members. This means the WLC can only be connected to one neighboring device.


 Roaming and Mobility Groups

Roaming occurs when users move from one AP association to another, this may occur as a user moves around. This must be seamless to the end user, and can be intercontroller, or intracontroller.


Intracontroller Roaming

This occurs when a user moves between APs that are both associated with the same WLC. The WLC updates its client database with the new AP association and does not change the client's IP address. If required, a client is reauthenticated when changing AP associations and a new security association is created.

Layer 2 Intercontroller Roaming

This occurs when a user moves between two APs that are associated to different WLCs, but both WLCs are part of the same subnet. When this sort of roaming occurs, the WLC passes its client database to the other WLC, and no IP address change happens for the client. If required the client is reauthenticated and a new security association is created.

Layer 3 Intercontroller Roaming

This occurs when a client moves between APs associated to WLCs that are on different subnets. When the client moves its association, the new WLC and the previous WLC exchange mobility messages. The client database is not moved to the new WLC, instead the first WLC marks the client as an 'anchor' entry and the new WLC marks the client as a 'foreign' entry. The wireless client's IP address is preserved and, if required, the client reauthenticates and gets a new security association. From then on, traffic is routed asymmetrically. Traffic from the client is forwarded to the wired network by the new WLC, but traffic that is destined for the client is forwarded from the wired network to the original WLC.  The original WLC then forwards that traffic to the new WLC via Ether-in-IP tunneling, which is then sent from the new WLC to the client.

Mobility Groups

Mobility groups allow WLCs to peer with each other to allow roaming across the controller's boundaries, AP load balancing and redundancy. When WLCs are placed into the same mobility group, they will exchange mobility messages and the EtherIP tunneling is possible when roaming occurs. For this reason WLCs that are meant to be redundant and allow roaming should be placed into the same mobility groups.

Up to 24 WLCs can be placed into a mobility group, and what devices are in the group determine how many APs can be supported. WLCs can also be configured with mobility lists, which are lists of which WLCs belong to which mobility groups. If a WLC has this list, clients can roam between mobility groups so long as mobility lists are configured on the WLCs. Mobility lists can support 48 mobility groups with Release 5.0, or 72 lists with Release 5.1 or later

WLCs use UDP port 16666 for unencrypted messages and UDP 166667 for encrypted messages. APs learn the IPs of other members of the mobility group when joining via CAPWAP

Cisco best practice is to minimize intercontroller roaming, and if needed, Layer 2 intercontroller roaming is preferred as it is far more efficient. Total round-trip travel time between controllers should be under 10ms. Proactive key caching (PKC) or Cisco Compatible Extensions (CCKM) Version 4 is recommended to speed/secure roaming.

WLAN Design Best Practice


Controller Redundancy: Dynamic or Deterministic

Deterministic redundancy is best practice and requires APs to be configured with a primary/secondary/tertiary controller preference. This requires more front-end work, but allows for deterministic failover and predictability. Deterministic advantages include:
  • Predictability
  • Network scalability
  • Flexible/powerful redundancy options
  • Faster failover
  • Deterministic fallback

Dynamic redundancy uses CAPWAP to load balance APs across WLCs, by populating each AP with a backup WLC. This solution works best when all WLCs are located centrally since it is dynamic. Dynamic advantages include:
  • Easier configuration
  • Dynamic AP load balancing

Unpredictable operation and longer failover occurs with dynamic redundancy, as well as a lack of other options for failover.

N+1 WLC Redundancy

With this redundancy option, a single WLC is configured as a backup for multiple WLCs. This could cause the backup to become oversubscribed.

N+N WLC Redundancy

With this redundancy option, an equal number of backup WLCs are configured. A pair of WLCs on one floor may be configured as backup WLCs for another floor, and vice versa. There needs to be enough capacity to allow for failover if needed (no more than 50% capacity used).

N+N+1 WLC Redundancy

With this redundancy option, an equal number of controllers are configured as backups for each other (as above), and a tertiary backup WLC is configured as well. This tertiary controller backs up the secondary controllers, usually placed in the data center or NOC

Radio Management/Radio Groups

Due to the ISM limit on available frequencies for 802.11b/g/n there is a limit on what non-overlapping channels can be used (1, 6, 11). Best practice for APs is to limit the number of data devices attached to a single AP to 20, or 7 concurrent Voice over WLAN (VoWLAN) calls using G.711 codec, or 8 concurrent VoWLAN calls using G.729.

As user population grows on the WLAN additional APs should be added to maintain the ratio. Cisco Radio Resource Management (RRM) manages AP RF channels/power configuration to minimize interference. WLCs use RRM algorithm to automatically optimize and self-heal the radio frequencies using these functions:
  • Radio Resource Monitor: LWAPs monitor all radio channels and monitor for rogue APs, clients and interfering APs
  • Dynamic Channel Assignment: WLCs automatically manage channels for APs to avoid interference
  • Interference Detection/Avoidance: Interference is detected by a predefined threshold (10% default)
  • Dynamic Transmit Power Control: WLCs automatically adjust broadcast power of APs
  • Coverage Hole Detection/Correction: WLCs can adjust AP power output if clients report low signals
  • Client/Network Load Balancing: Clients can be influenced to connect to certain APs to load balance

WLCs can use RRM to raise power levels and channels of APs to compensate for lost/downed APs.

RF Groups

RF groups are clusters of WLCs that coordinate their RRM calculations. When the WLCs join the group, the RRM calculation expands to include the WLCs joined. APs send neighbor messages to each other, and if the message is above -80dBm the controllers form an RF group. WLCs elect a leader to analyze the RF data and make RRM decisions. The leader exchanges messages among RF group members on UDP port 12114 for 802.b/g/n, and UDP port 12115 for 802.11a.

How RF groups form:
  1. APs send out neighbor messages looking for other APs, which includes an encrypted shared secret key that is preconfigured on trusted WLCs
  2. Messages with the same secret key are validated and trusted. These messages must be transmitted above -80dBm to form the group.
  3. Members of the formed RF group elect a leader to analyze and push a master power/channel scheme for the group. The leader receives realtime data about the WLAN to make this calculation

RF Site Survey

Site surveys are done similarly to surveys for wired network design. The RF site survey identifies customer requirements and coverage needed as well as check for interference. The site survey should consist of the following steps:
  1. Define customer requirements, what applications are needed (such as VOIP) and what types of devices need to be supported as well as where these wireless devices will be located
  2. Obtain a facility diagram to identify RF interference/dead zones
  3. Visually inspect the facility to identify barriers to wireless signal like elevator shafts and stairwells
  4. Identify areas intensively used as well as areas that are not used often
  5. Determine preliminary AP locations, power placement, wired network access, channel selection, mounting locations, antennas
  6. Use an AP to survey locations and the received RF strength based on targeted AP placement
  7. Document findings by recording locations, signal readings, data rates at the outer areas of coverage. The report includes:
  • Detailed customer requirements, diagram AP coverage
  • Parts list including antennas, accessories, network components
  • Tools/methods used for site survey

Ethernet over IP Tunnels for Guest Services

Basic guest access entails separating guest SSID/vlan from the corporate network, broadcasting guest access but not corporate. Another solution involves EoIP to tunnel the guest traffic from the AP to the an anchor WLC. When guests access the guest APs, their connections are automatically tunneled to the specified anchor WLC for guest access. This keeps guest traffic logically separated from the corporate network without the need to run extra vlans.

Wireless Mesh in Outdoor Wireless

Wireless Mesh Components:
  • Wireless Control System (WCS): Wireless mesh SNMP management system allows network-wide configuration/management
  • WLAN Controller (WLC): Links the meshed APs to the wired network, manages security, mitigates radio interference, etc
  • Rooftop AP(RAP): Connects the mesh to the wired network, serves as root. Communicates with MAPs, typically located on rooftops/towers
  • Mesh Access Point(MAP): AP that provides access to wireless clients, communicating with RAPs for wired network connection. Usually located on a lamppost or other pole.

Mesh Design Recommendations

  • Less than 10ms latency per hop, 2-3ms preferred
  • Four or fewer hops are recommended for outdoor deployment though eight are supported
  • For indoor deployment one hop is supported
  • Best performance occurs when no more than 20 MAPs are used per RAP, though 32 are supported
  • Throughput: One hop = 14Mbps, two hops = 7 Mbps, three hops = 3 Mbps, four hops = 1 Mbps

Campus Design Considerations

  • Number of APs: Should be enough APs to provide full coverage for wireless clients for the expected access locations. 20 data devices per AP, and 7 G.711 concurrent or 8 G.729 concurrent VoWLAN calls.
  • AP Placement: APs should be placed in a centralized location of the expected access area, and placed in conference rooms to accommodate peak requirements
  • AP Power: Traditional wall power can be used, or Power over Ethernet (PoE)
  • Number of WLCs: The number of WLCs depends on the redundancy strategy and number of required APs
  • WLC Placement: WLCs are placed in secured wiring closets or the data center. Intercontroller roaming should be minimized, and deterministic redundancy is recommended

Branch Design Considerations

Branch offices may not need a WLC installed depending on how many APs are needed. If a WLC is not installed at the branch office, the round-trip time between APs and the WLC should not exceed 300ms. REAP or Hybrid REAP (H-REAP) should be used.

Local MAC: CAPWAP supports local media access control for branch deployments. In this deployment, the AP provides MAC management support for associations, terminating traffic at the AP instead of a WLC. This allows local access without requiring traffic to travel all the way to a central office WLC, and to continue functioning if the connection to the central office is lost.

REAP: REAP supports branch offices by extending LWAPP control timers. Control traffic is still encapsulated over an LWAPP tunnel over the WAN to a WLC, but local traffic is bridged. In this way the clients still have access to local resources if the WAN fails. REAP devices only support Layer 2 security policy, do not support NAT and need a routable IP address.

Hybrid REAP: H-REAP enhances REAP by providing additional capabilities like NAT and the ability to control three APs remotely. APs connect to WLC over WAN and use two security modes:
  1. Standalone: H-REAP authenticates clients when the WLC can't be reached. WPA-PSK and WPA2-PSK are supported.
  2. Connected: The AP uses the WLC for client authentication. H-REAP supports WPA-PDK, WPA2-PSK, VPN, L2TP, EAP and web authentication

H-REAP round-trip time must not exceed 300ms and CAPWAP must be prioritized traffic.

Branch Office Controllers

  1. Cisco 2100 series
  2. Cisco 4402-12/4402-24
  3. WLC Module in Integrated Services Router
  4. 3750 with WLAN controller

WLAN Design Summary

  • RF site survey will determine RF characteristics and AP placement
  • Guest services are supported using EoIP in the Cisco Unified Wireless Network
  • Outdoor wireless is supported using outdoor APs and mesh networking APs
  • Campus WLAN design provides wireless coverage using LWAPs managed by WLCs
  • Branch WLAN design deals with wireless access management at remote sites using REAP or H-REAP
  • Each AP should be limited to 20 data devices
  • Separate SSIDs should be used for voice, and APs should not have more than 7 concurrent calls using G.711 codec, or 8 using G.729 codec

UDP Ports Used by Wireless

LWAPP Control: 12223
LWAPP Data: 12222
WLC Exchange Messages (unencrypted): 16666
WLC Exchange Messages (encrypted): 16667
RF 802.11b/g/n: 12114
RF 802.11a: 12115
CAPWAP Control: 5246
CAPWAP Data: 5247

Saturday, February 16, 2013

CCDA Notes: Wireless LAN Design (WLAN Standards and WLCs)

Wireless LAN Design


WLAN Standards


First standard for WLAN was established by IEEE, 802.11, ratified in 1997. Originally implemented at speeds of 1-2 MBPS using direct sequence spread spectrum (DSSS) and frequency-hopping spread spectrum (FHSS) at the Physical Layer of OSI model. DSSS separates data into sections which is transmitted over different frequencies at the same time, while FHSS uses frequency-hopping to send data in bursts, transmitting part of the data on channel 1, then hopping to channel 2 for the next part, then back to channel 1.

802.11b was announced in 1999 which provided 11MBPS data rate, using 11 channels of the Industrial, Scientific and Medical (ISM) frequencies. 802.1b uses DSSS and is backwards compatible with other 802.11 systems which use DSSS.

802.11a was approved as a second standard in 1999, providing 54MBPS data rate but being incompatible with 802.11b. 802.11a uses 13 channels of Unlicensed National Information Infrastructure (UNII) frequencies and is incompatible with 802.11b/g.

802.11g was approved in 2003 which used ISM frequencies and provided 54 MBPS data rate. 802.11g was also backwards-compatible with 802.11b.

802.11n standard was ratified in 2009. It uses multiple-input multiple-output (MIMO) antennas and expected max data rate of 600 MBPS using 4 streams, each with 40-MHz width. Uses DSSS and orthogonal frequency-division multiplexing (OFDM) as the digital carrier modulation method, 802.11n uses both 2.4-GHz and 5-GHz bands.

ISM and UNII Frequencies

802.11b/g uses 2.4-GHz range of frequencies as set in ISM, with overlapping channels that are 22MHz wide. Common non-overlapping channels used are 1, 6 and 11 to prevent interference.

UNII has three ranges:
  1. 5.15 GHz - 5.25 GHz, and 5.25 GHz - 5.35 GHz
  2. 5.47 GHz - 5.725 GHz. Used by High Performance Radio LAN in Europe
  3. 5.725 GHz - 5.875 GHz. This range overlaps ISM
802.11a has 12 non-overlapping channels.

Service Set Identifier

WLANs use an SSID to identify WLAN network name. SSIDs can be 2 to 32 characters, and all devices in WLAN must use the same SSID to communicate. This acts very much like a vlan in a wired network. The main difficulty in large networks is configuring SSID, frequency and power settings for remotely located access points. Cisco use Wireless Control System (UCS).

WLAN Layer 2 Access

802.11 media layer access control uses Carrier Sense Multiple Access Collision Avoidance (CSMA/CA) as the access method. Each WLAN station listens for other stations transmitting, and then transmits if no other traffic is detected on the radio frequency. Of course, with a centrally located access point it is entirely possible to have stations unable to detect each other, whereas on a wired network the collision would be detected by all participants on the network segment. If the AP does not receive the transmission, the station backs off a random amount of time before trying again.

WLAN Security

Because of wireless signals proliferation and ease of eavesdropping on signal, wireless security has its own set of challenges. Several standards were created to address wireless security concerns. The first was Wireless Equivalent Privacy (WEP) which was used in the 802.11b standard. This method used a short preshared key to encrypt traffic and was easily cracked. In 2004, the 802.11i standard was created to provide additional security for WLAN networks. This standard is also known as Wireless Protected Access 2 (WPA2) and Robust Security Network (RSN). 802.11 contains the following:
  • 4-Way Handshake and Group Key Handshake, both using 802.1x for authentication (using Extensible Authentication Protocol and an authentication server)
  • Robust Security Network for establishment and tracking of robust security associations
  • Advanced Encryption Standard (AES) for confidentiality, integrity, and origin authentication

Unauthorized Access

Wireless signals are difficult to control and contain. Because wireless signal may extend beyond the physical boundaries, attackers may be able to gain access to the network. If the wireless network does not have a mechanism to compare wireless card MAC addresses of hosts to a database of approved MACs, attackers may achieve unauthorized access. Simply having a database is also not protection because MAC addresses can be spoofed by attackers. Because static MAC address lists are not scalable and are defeated by spoofing, wireless encryption methods such as WEP/WPA2 need to be employed so that attackers cannot gain access without the security keys.

WLAN Security Design Approach

Two assumptions are made concerning the security design approach described:
  • All WLAN devices are connected to a unique IP subnet
  • Most services available to the wired network are also available to users of the WLAN
With those assumptions in mind, there are two basic security approaches:
  • Use EAP via Secure Tunneling (EAP-FAST) to secure authentication
  • Use VPN with IP Security (IPSec) to secure traffic from wireless to wired network
WLANS can potentially open new attack vectors for hackers and so security should be enhanced by using VPN with IPSec, 802.1x protocol, and WPA.

802.1x Port-Based Authentication

802.1x is a port-based authentication protocol that can be used on Ethernet, Fast Ethernet and WLAN networks. Client hosts run 802.1x software utilizing EAP to communicate with the AP. The AP relays the authentication request to an authentication server that will accept or deny the credentials, activating or deactivating the port/wireless connection. Usually a Remote Authentication Dial-In User Service (RADIUS) server handles authentication requests. This request is not encrypted as 802.1x is not an encryption protocol.

Dynamic WEP Keys and LEAP

Cisco offers dynamic, per-session WEP keys that are more secure than statically configured WEP keys. To centralize user-based authentication, Cisco developed LEAP. LEAP uses mutual authentication between client/server and 802.1x for wireless authentication messaging. LEAP can use Temporary Key Integrity Protocol (TKIP) rather than WEP to overcome the weakness of WEP. LEAP uses RADIUS to manage user information.

LEAP combines 802.1x and EAP, combining the ability to authenticate to various servers (such as RADIUS) with the ability to force users to log onto an AP that compares logon info with RADIUS. This solution is far more scalable than trying to keep a database of authorized MAC addresses.

Because the WLAN access depends on receiving an address using DHCP, and authenticating connection attempts via RADIUS, the WLAN needs access to these servers. LEAP does not support one-time passwords (OTP) so good password security practice is essential.

Controlling WLAN Access to Servers

The security posture of servers accessible to the WLAN should be similar to that of a DMZ because it is potentially accessible by attackers. WLAN RADIUS and DHCP servers should be kept on a separate segment (vlan) from other primary servers. Access into this vlan should be filtered, which ensures that attacks on these WLAN-accessible servers are contained within that segment. Network access to these servers should be controlled and restricted, as the WLAN should be considered an unsecured network segment. 

These WLAN-accessible servers also need to be protected from attack, possibly using IDS/IPS or firewalls.

Cisco Unified Wireless Network


Cisco UWN Architecture


The Cisco Unified Wireless Network architecture combines elements of wireless and wired networks to manage, secure and scale WLANS. Cisco UWN architecture is comprised of five elements:
  • Client Devices: Laptops, workstations, IP phones, PDAs and manufacturing devices to access WLAN
  • Access Points: Placed in strategic locations to maximize signal and minimize interference
  • Network Unification: The WLAN should support wireless applications by providing security policy, QoS, intrusion prevention, and radio management. Cisco WLAN Controllers provide this functionality and integrates within all major routing/switching platforms
  • Network Management: Cisco Wireless Control System (WCS) provides central management tool to allow design, control and monitoring of WLAN
  • Mobility Services: Includes guest access, location services, voice services, threat detection/mitigation

The Cisco UWN provides benefits:
  • Reduced Total Cost of Ownership (TCO)
  • Enhanced visibility/control
  • Dynamic radio management
  • WLAN Security
  • Unified wireless/wired network
  • Enterprise mobility
  • Enhanced collaboration/productivity

Lightweight Access Point Protocol

LWAPP is an IETF standard for control messaging between APs and WLCs. LWAPP control messages can be transmitted as Layer 2 or Layer 3 tunnels. Layer 2 LWAPP tunnels came first, and APs did not need an IP address, but the WLC had to be on every subnet on which an AP resides because only Layer 2 traffic was available. Layer 3 LWAPP is now the preferred solution, but lightweight APs can support both. LWAPP Layer 3 tunneling uses IP addresses that are collected from a mandatory DHCP server. When using Layer 2 tunneling, LWAPP uses a proprietary code to communicate with access points. WLCs reside on the wired network and the lightweight APs are at the edge, not directly connected. This is why tunneling is needed, to protect control traffic between WLCs and LWAPs.

LWAPP Layer 2 uses EtherType code 0xBBBB, Layer 3 uses UDP ports 12222/12223.

Control And Provisioning for Wireless Access Points


CAPWAP is an IETF standard for control messaging between APs and WLCs. Using Control Software 5.2, Cisco LWAPs use CAPWAP to communicate between LWAPs and WLCs. CAPWAP is different from LWAPP in the following ways:
  • CAPWAP uses Datagram Transport Layer Security (DTLS) for authentication and encryption to protect traffic between LWAP and WLC. LWAPP uses EAP for the same.
  • CAPWAP has a dynamic MTU discovery mechanism.
  • CAPWAP control messages use UDP port 5246.
  • CAPWAP data messages use UDP port 5247.
CAPWAP uses Layer 3 tunnels between the LWAP and WLC. The LWAP obtains an IP from DHCP servers. Control and data messages sent from an LWAP use an ephemeral UDP port that is derived from a hash of the AP MAC addresses, while WLC traffic uses UDP port 5246/5247 for control/data traffic.

Cisco Unified Wireless Split-MAC Architecture

With split-MAC architecture, LWAP control and data messaging is split. LWAPs communicate with WLCs using control messages over the wired network, while LWAPP/CAPWAP data messages are encapsulated and forwarded to/from wireless clients. WLCs provide configuration and firmware updates to APs as needed.

LWAP MAC functions:
  • 802.11: Beacons, probe response
  • 802.11 Control: Packet acknowledgement and transmission
  • 802.11e: Frame queuing and packet prioritization
  • 802.11i: MAC layer data encryption/decryption
Controller MAC Functions:
  • 802.11 MAC Management: Association requests and actions
  • 802.11e Resource Reservation: Reserves resources for specific applications
  • 802.11i: Authentication and key management

Local MAC

Local MAC is supported by CAPWAP, which moves the MAC management from the WLC to the local AP. This allows termination of client traffic at the wired port of the AP. This is useful at small or remote offices where a WLC isn't needed. 

LWAP MAC Functions:
  • 802.11: Beacons, probe response
  • 802.11 Control: Packet acknowledgement/transmission
  • 802.11e: Frame queuing/packet prioritization
  • 802.11i: MAC layer data encryption/decryption
  • 802.11 MAC Management: Association requests/actions

Controller MAC Functions:
  • 802.11: Proxy association requests/actions
  • 802.11e Resource Reservation: Reserves resources for specific applications
  • 802.11i: Authentication and key management

With autonomous APs not associated to a WLC, the AP simply acts as a trunk carrying different vlan traffic. With a WLC connected with CAPWAP, the AP tunnels to the WLC and then the WLC trunks to the switch.

AP Modes

  • Local mode: Default mode of operation. Every 180 secs, the AP measures noise floor/interference and scans for IDS events. This occurs on unused channels, lasts 60ms
  • Hybrid Remote Edge AP (H-REAP) Mode: Enables LWAP to reside across a WAN from the WLC. It uses local MAC, and is supported on Cisco 1130, 1140, 1240AB, and 1250AG series LWAPs.
  • Monitor mode: Feature to allow specific CAPWAP-enabled APs to opt out of handling data traffic, instead serving as sensors for rogue APs, intrusion detection and location-based services (LBS). These monitors continuously cycle through channels listening to each for 60ms.
  • Rogue Detector mode: LWAPs in this mode monitor for rogue APs. RD APs are attached to a trunk port to enable seeing all traffic since rogue APs can be connected to any vlan. The wired switch sends a list of rogue AP/client MACs to the RD AP and the RD AP forwards the list to the WLC to compare with MACs registered over the WLAN. If there are matches, then the WLC is aware that a rogue AP is plugged into the wired network and what rogue clients are connected.
  • Sniffer mode: LWAP that operates in sniffer mode captures and forwards packets on a particular channel to a remote machine running AiroPeek. This mode only works with AiroPeek, a 3rd party packet sniffer.
  • Bridge mode: This mode is only available on Cisco 1130 and 1240 series (typically indoor), and 1500 APs (typically outdoor mesh) and provides high-bandwidth cost-effective bridging. Point-to-point, point-to-multipoint, point-to-point wireless access with integrated backhaul and point-to-multipoint wireless access with integrated backhaul 

LWAPP Discovery of WLC


LWAPs placed on the network attempt DHCP discovery to obtain an IP address, followed by a Layer 3 LWAPP discovery attempt. If the WLC does not respond, the AP reboots and tries again. Layer 3 LWAPP discovery algorithm follows:
  1. AP sends a Layer 3 LWAPP discovery request
  2. All WLCs that receive this request reply with a unicast LWAPP discovery response message
  3. The requesting AP compiles a list of responding WLCs.
  4. The AP selects its preferred WLC based on certain criteria
  5. The AP validates the selected WLC and sends an LWAPP join response. An encryption key is agreed upon and future communications are encrypted.

Layer 3 discovery requests are sent in one or more of the following ways:
  • Local subnet broadcast
  • Unicast LWAPP discovery requests to WLCs advertised by other APs
  • Previously stored WLC addreses
  • IP addresses learned by DHCP option 43
  • IP addresses learned by DNS resolution of CISCO-LWAPP-CONTROLLER.local-domain

The WLC which is selected is selected based on certain criteria:
  • Previously configured primary/secondary/tertiary WLCs
  • WLC configured as master
  • WLC which has the most capacity for AP associations

If the WLC has CAPWAP, the AP follows this process:
  1. CAPWAP AP begins discovery process to find the WLC using a CAPWAP request, to which the WLC sends a CAPWAP response.
  2. If the AP receives no CAPWAP response within 60 seconds, the AP uses LWAPP discovery
  3. If the AP cannot find a WLC using LWAPP within 60 seconds it tries CAPWAP again.

CAPWAP is a design decision that is configurable within the WLC. APs select the WLC to create a CAPWAP tunnel based on information contained within the WLC responses. These responses contain the controller sysName, current capacity and load, status of the master WLC and the AP manager IP address. Based on this information, the AP will select its preferred WLC as followed:
  • Primary/Secondary/Tertiary WLC preconfigured sysName (preconfigured preference)
  • Master WLC
  • WLC with greatest capacity for AP associations

 

WLAN Authentication

When wireless clients try to associate with an AP, they need to authenticate with an authentication server before being granted access to the WLAN. The authentication server resides in the wired LAN and and EAP/RADIUS tunnel is built from the WLC to the server to handle the request. Cisco has a Secure Access Control (ACS) which uses EAP which can service these requests.


Authentication Options

Different types of EAP have advantages and disadvantages. There are trade-offs in security, types of devices supported, ease of use and infrastructure support.
  • EAP-Transport Layer Security (EAP-TLS): Open IETF standard that is well-supported but rarely deployed. Uses PKI to secure communications to the RADIUS server using TLS and digital certificates.
  • Protected Extensible Authentication Protocol (PEAP): PEAP/MSCHAPv2 is the most common version deployed and is widely available. Similar in design to EAP-TTLS, needing only a server-side PKI cert to create a secure TLS tunnel to protect user authentication. PEAP-GTC allows more generic authentication to other kinds of user databases such as Novell Directory Services.
  • EAP-Tunneled TLS (EAP-TTLS): Widely supported across platforms, offers good security, using PKI certs on the authentication server. 
  • Cisco Lightweight EAP (LEAP): Early proprietary method of EAP supported in Cisco Certified Extensions (CCX) program. Vulnerable to dictionary attacks.
  • EAP-Flexible Authentication via Secure Tunneling (EAP-FAST): Proposal by Cisco to address the weaknesses of LEAP. EAP-FAST uses a Protected Access Credential with optional server certificates. EAP-FAST has three phases:
  1. Phase 0: Optional phase where PAC can be provisioned manually or dynamically.
  2. Phase 1: Client and AAA server use the PAC to establish a TLS tunnel.
  3. Client sends information over the established tunnel

WLAN Controller Components

Three major components of WLCs:
  • WLANS: Identified by unique SSID network names, each assigned to an interface on the WLC.
  • Interface: A logical connection mapping a wireless network to a vlan on the wired network
  • Port: Physical connection to the wired LAN, usually a trunk. There could be multiple ports on a WLC that are port-channeled into a single interface. Some WLCs may have an out-of-band management port.

WLC Interface Types


WLCs have five different interface types:
  •   Management: Mandatory static interface configured at setup, used for in-band management, AAA authentication and Layer 2 discovery/association
  • Service Port: Optional, statically configured at setup, used for out-of-band management
  • AP Manager: Static, configured at setup, mandatory on all but 5508 model WLC. Used for Layer 3 discovery/association, has source IP of AP that is statically configured
  • Dynamic: Analogous to vlans, used for client data
  • Virtual: Static, configured at setup, and mandatory, used for Layer 3 security authentication, DHCP relay, and mobility management

Monday, February 4, 2013

CCDA Notes: Data Center Design

Enterprise Data Center Architectures


Data Centers used to use mainframes to centrally process data, with users connecting via terminals to do work on the mainframe (Data Center 1.0).

Data Center 2.0 introduced the concept of client/server connections and distributed computing. Business applications were installed on servers in data center and accessed by users on their workstations. Applications services were distributed because of cost of WAN links and slow performance.

In Data Center 3.0, consolidation and virtualization are the main components. Due to communication equipment becoming cheaper and stronger computing power being available, the current move is toward consolidating services in data centers, which centralizes management and is more cost-effective than distributing services. Newer architecture takes advantage of server virtualization which results in higher utilization of computing/network resources. This raises return on investment (ROI) and lowers total cost of ownership (TCO).

Data Center 3.0 Components

Virtualization
  • Virtual local area networks (vlans), virtual storage-area networks (VSAN), virtual device contexts (VDC) help segment LAN/SAN/network instances
  • Cisco Nexus 1000V virtual switch for VMWare ESX/ESXi helps with policy control and visibility of virtual machines (VM)
  • Flexible network options that support multiple server form factors/vendors including those with integrated Ethernet/Fibre channel switches
Unified Fabric
  • Fibre Channel over Ethernet (FCoE) and Internet Small Computer Systems Interface (iSCSI) are two methods to implement unified fabric in data center oveer 10 Gigabit Ethernet networks
  • FCoE is supported on VMWare ESX/ESXi vSphere 4.0 and up
  • Cisco Catalyst/Nexus/MDS family of switches support iSCSI. Cisco Nexus 5000  supports unified fabric lossless operation which improves iSCSI performance using 10 Gigabit Ethernet
  • Cisco Nexus switches created to support unified fabric. Nexus 4000/5000 supports data center bridging (DCB) and FCoE, in future Nexus 7000 and Cisco MDS switches will as well
  • Converged network adapters (CNA) run at 10GE speeds and support FCoE. Available from Emulex and QLogic, and certain software stacks for 10GE interfaces are available from Intel
Unified Computing
  • Cisco Unified Computing System (UCS) is next-gen platform designed to converge computing, storage, network and virtualization together into one system
  • Integrates lossless 10GE unified network fabric with x86-based servers
  • Allows Cisco Virtual Interface Cards to virtualize network interfaces on servers
  • Cisco VN-Link virtualization
  • Supports extended memory technology patented by Cisco
  • Uses just-in-time provisioning using service profiles to increase productivity
At top layer of architecture, the virtual machines are software entities that run hypervisors which emulate hardware. Then there are the unified computing resources within which service profiles define the identity of the server. Identity includes hardware settings such as allocated memory and CPU, network card information, boot image and storage. 10GE, FCoE and Fibre Channel technologies provide unified fabric supported by Cisco Nexus 50000. FCoE allows native Fibre Channel frames to function on 10GE networks. VLAN/VSAN technology segments multiple LANs and SANs on same physical equipment. At the lowest layer there is virtualized hardware where storage devices can be virtualized into storage pools, and network devices are virtualized using virtual device contexts.

Challenges in the Data Center

Data center requirements and mechanical specifications help to define the following:
  • Power needed
  • Physical rack space used
  • Limits on scaling
  • Management (resources, firmware)
  • Security
  • Virtualization support
  • Management effort required

Data Center Facility Considerations


  • Space available
  • Floor load capacity
  • Power/cooling capacity
  • Cabling infrastructure
  • Operating temperature and humidity level
  • Access to site, security alarms and fire suppression
  • Space for employees to move/work
  • Compliance with regulations such as Payment Card Industry (PCI), Sarbanes-Oxley (SOX), and Health Insurance Portability and Accountability Act (HIPAA)

Data Center Space

  • Number of employees who will support data center
  • Number of servers and amount of storage/network gear needed
  • Space needed for non-infrastructure areas such as shipping/receiving, server/network staging, storage/break/bathrooms, and office space
Other considerations related to equipment rack/cabinet space:
  • Weight of rack/equipment
  • Heat expelled from equipment
  • Amount and type of power required (UPS/RPS)
  • Loading, which determines what/how many devices can be installed

Data Center Power

Desired power reliability drives requirements which may include multiple redundant power feeds from utility, backup generators, redundant power supplies. Power in the data center is used to power and cool devices in the data center. The power system also needs to protect against power surges, failures and other electrical problems. Key points of a power design will:
  • Define overall power capacity
  • Provides physical electrical infrastructure and addresses redundancy

Data Center Cooling

Cooling is used to control humidity and temperature in order to extend the lifespan of devices. High-density rack design should be weighed against heating considerations. Smaller form-factor servers allow more to be placed into a rack but airflow and cooling must be accounted for. Cabinets and racks should be organized into 'cold' and 'hot' aisles. In cold aisles, the fronts of devices should face each other across the aisle and in hot aisles the backs of devices should face each other across the aisle. Cold aisles should have perforated floor tiles through which cold air is blown that will be drawn into the fronts of the devices, flushing the hot air out of the back into the hot aisles. Hot aisles should have no perforated tiles, which will keep hot/cold air from mixing and diluting its effect.

If equipment does not exhaust heat to the rear, other cooling techniques can be leveraged:
  • Block unnecessary air escapes to increase airflow
  • Increase height of raised floor
  • Spread equipment to unused racks
  • Use open racks rather than cabinets in places security is not a concern
  • Use cabinets with meshed front/back
  • Custom perforated tiles with larger openings to allow more cold airflow

Data Center Heat

Data center design must account for high density servers and heat produced by them. Considerations in design for cooling need to be taken into account for proper sizing of servers and anticipated growth, along with the corresponding heat output.
  • Increase number of HVAC units
  • Increase airflow through devices
  • Increase space between racks/rows
  • Use alternative cooling technologies such as water-cooled racks

Data Center Cabling

Data center cabling is known as passive infrastructure. The cabling plant is what connects everything together, terminating connections between devices and governing how devices communicate. Cabling must be easy to maintain, abundant and capable of supporting different media types and connectors for proper operations.

Considerations for following must be determined during design:
  • Media selection
  • Number of connections
  • Type of cable termination organizers
  • Space for cabling on horizontal/vertical cable trays
Cabling needs to avoid the following:
  • Inadequate cooling due to restricted airflow
  • Outages due to accidental disconnections
  • Unplanned dependencies
  • Difficult troubleshooting options

Enterprise Data Center Infrastructure

Current enterprise data center design follows Cisco multilayer (hierarchical) architecture including access, aggregation and core layers. This model supports blade servers, single rack-unit (RU) servers and mainframes.

Defining Data Center Access Layer

The main purpose of data center access layer is to provide Layer 2/3 physical port density for various servers. The access layer also provides low-latency and high-performance switching that can support oversubscription requirements. Most data centers are built with Layer 2 connectivity but Layer 3 (routed access) options are available. Layer 2 connectivity uses vlan trunk uplinks to allow aggregation services to be shared across the same vlan across multiple switches. Spanning Tree is used in Layer 2 access to avoid loops in network. The recommended STP instance is RPVST+.
New routed access design aims to contain Layer 2 to the access layer and avoid the use of STP. First-hop redundancy must be be provided as the access switch becomes the first-hop router. Access layer benefits are as follows:
  • Port density for server farms
  • Supports single/dual-homed servers
  • High-performance, low-latency Layer 2 switching
  • Supports mix of oversubscription requirements

Defining Data Center Aggregation Layer

Aggregation (Distribution) layer aggregates Layer 2/3 links from the access layer and connects upstream to the core layer. Layer 3 connectivity, if not implemented at access layer, is typically used towards core from aggregation layer. The aggregation layer is a critical point for data center application and security services including load balancing, SSL offloading, and firewall/IPS services. Depending on design requirements the Layer 2/3 border could be in multilayer switches, firewalls, or content switching devices. Multiple aggregation layers can support different environments such as a test environment, production, etc each with its own applications and security requirements. First-hop redundancy is typically implemented in aggregation layer if Layer 3 is not implemented at the access layer. Benefits of the aggregation layer are:
  • Aggregates traffic from data center access layer and connects to data center core
  • Supports advanced security/application services
  • Layer 4 services such as firewalls, IPS, SSL offloading and server load balancing
  • Large STP process load
  • Highly flexible/scalable

Defining Data Center Core Layer

Data Center Core connects the campus core to the data center aggregation layer utilizing high-speed Layer 3 links. The core is a centralized Layer 3 routing layer to which the data center aggregation layers connect. Data center networks are summarized here and shared with the campus core, and default routes are injected into the data center aggregation layer from the data center core. Multicast traffic must also be allowed through the data center core to support a growing list of multicast applications.

Data Center Core Drivers
  • 10 Gigabit Ethernet density: Are there enough links to link multiple aggregation layers together?
  • Administrative domains/policies: Separate cores help isolate campus distribution from data center aggregation for troubleshooting and QoS/ACL policies
  • Future Growth: Future impact/downtime that would be needed to expand later makes it important to provide enough core layers when designing for initial implementation
Characterisics of a Data Center Core
  • Low-latency switching
  • Distributed forwarding architecture
  • 10 Gigabit Ethernet
  • Scalable IP Multicast support

Virtualization Overview

Virtualization technology allows one physical device to emulate several, or several physical devices to emulate a single logical device. The modern data center is changing based on virtualizatuion and data center design changes with it.

Virtualization Driving Forces
  • Need to reduce rising cost of powering/cooling devices while getting more productivity
  • Data center consolidation of assets performing individual tasks
  • Logical, separate user groups secured from other groups on same network
  • Eliminate underutilized hardware that has poor performance/price ratio

Virtualization Benefits
  • Better use of computing resources, higher server densities, simplified server migration
  • Flexibility and ease of management for adds/reassignments/repurposing of resources
  • Separation of groups utilizing same physical network, enabling traffic isolation
  • Ability to provide per-department security policy
  • Reduction in power/space needed
  • Increased uptime, decreased operational cost

Network Virtualization
  • VLAN
  • VSAN
  • VRF (Virtual Routing/Forwarding)
  • VPN
  • vPC (Virtual Port Channel)

Device Virtualization
  • Server virtualization (VM)
  • Cisco Application Control Enginre (ACE) context
  • Virtual Switching System (VSS)
  • Cisco ASA firewall context
  • Virtual device contexts (VDC)

Virtualization Technologies


VSS
Virtual Switching System is network virtualization that allows two physical Cisco Catalyst 6500 series switches to act as a single logical switch. Similar to StackWise technology used on Cisco Catalyst 3750 switches that allows chaining multiple switches together into a single logical switch, but VSS is limited to two chassis linked together.

VRF
Virtual routing and forwarding virtualizes Layer 3 route tables to allow multiple routing tables to exist on a single device. In Multi-Protocol Label Switching VPN environment, VRF allows  multiple networks to exist on the same MPLS network. Routing information is contained in VRF and is only visible to other routers participating in the same VRF instance. Because of this duplicate IP address schemes can be used.

vPC
Virtual Port Channel technology works by virtualizing two Cisco Nexus 7000 or Nexus 5000 series switches as a single logical switch. 10GE links connect the two physical switches which then represent themselves as a single logical switch for purposes of port channeling. Although multiple redundant paths exist, the spanning tree topology appears loop-free. This allows all links to be utilized.

Device Contexts
Device contexts allow a single physical network device to host multiple virtual devices. Each context is its own instance with its own configuration, policies, network interfaces and management. Most features available on single network devices also exist on contexts. These devices support contexts:
  • Cisco Nexus 7000 series switches
  • Cisco ASA Firewall
  • Cisco Catalyst 6500 Firewall Services Module (FSM)
  • Cisco Application Control Engine Appliance
  • Cisco Catalyst 6500 Application Control Engine Module
  • Cisco IPS
Server Virtualization
Server virtualization is a software technique which abstracts server resources from hardware to provide flexibility and optimize the usage of the underlying hardware. The virtualized hypervisor controls hardware and physical resources that can be allocated to the different server VMs. This shares resources among the VMs without the VMs being aware of their actual physical hardware. Several vendors for server virtualization, along with products:
  • VMWare ESX Server
  • Citrix XenServer
  • Microsoft Hyper-V

Network Virtualization Design Considerations


Access Control
Access should be controlled to make sure users and devices are identified and authorized to communicate with their assigned network segment.

Path Isolation
Path isolation involves the creation of independent logical paths over the same physical network infrastructure. MPLS VPN assigned to specific VRFs is an example of this. VLANs and VSANs also logical separate networks.

Services Edge
Services Edge refers to making services available to the users, groups and devices intended with an enforced centralized managed policy. Effective way to enforce service access is a firewall or other centralized device that contains policies on what should and should not be accessible.