11:16 PM10/15/10 11:16 PM 568 CCENT Certification All-In-One For Dummies Remote Access Service (RAS) authentication, 513 Remote Authentication Dial-In User Service (RADIUS), 64, 513 remote communication, 378, 380–382 remotely connecting, 163 repeaters, 55 request phase, 64 Reserved field, 103 resting before exam, 15 restrict action, 399 resume command, 258 RG-8 grade cabling, 27 RG-58 grade coax cables, 26 ring topology, 23 RIP (Routing Information Protocol) configuring SDM, 300–301 RIPv1 (RIP version 1), 349, 352–353 RIPv2 (Routing Information Protocol v2), 349–350, 353–354 troubleshooting, 354–357 RJ-45 connector, 27 rollover cables, 33–34, 163 ROM (read-only memory), 176 ROM Monitor (ROMMON), 176 router command, 350 Router Properties node, 299 router rip command, 352 router simulations, 12 router> prompt, 183 RouterA(config) prompt, 351 routers 2500-series, 288–289 2600-series, 289–290 banners configuring, 219–220 types of, 218–219 Cisco changing hostname, 203–204 connecting to devices, 200–203 configuring passwords auxiliary port, 215–216 console, 215 Telnet, 216–217 console timeout, 224 creating users, 217–218 deleting configuration, 221–222 domain lookups, 223 dynamic routing protocols 28_647486-bindex.indd 56828_647486-bindex.indd 568 Enhanced Interior Gateway Routing Protocol (EIGRP), 350–351 Interior Gateway Routing Protocol (IGRP), 350 Open Shortest Path First (OSPF), 351 Routing Information Protocol (RIP), 349, 352–357 Routing Information Protocol v2 (RIPv2), 349–350 types of, 345–348 Ethernet interfaces description for, 205–206 enabling and disabling interfaces, 206–207 IP settings, 204–205 other settings, 206 router R2, 207–208 lab exercises configuring DHCP, 305–306 configuring hostname resolution, 304–305 configuring passwords, 231–232 configuring router interfaces, 230–231 recovering passwords, 306–310 viewing configurations, 232–236 looking at most recently used commands, 222–223 network services configuring DHCP services, 276–278 hostname resolutions, 272–276 implementing Network Address Translation (NAT), 278–283 overview, 60–61 ports of auxiliary port, 163–164 Cisco Ethernet ports, 165–167 console port, 163 identifying 1604 router ports, 169–170 identifying 2811 router ports, 170 serial ports, 167–169 R1, 203 R2, 204 recovering passwords on 2500-series routers, 288–289 on 2600-series routers, 289–290 configuration registers, 283–287 routing by rumor, 345 saving configuration changes, 220–221 Security Device Manager (SDM) 10/15/10 11:29 PM10/15/10 11:29 PM Index configuring, 290–293 configuring DHCP using SDM, 299 configuring Ethernet interfaces, 295–297 configuring hostnames, 298–299 configuring NAT using SDM, 301–304 configuring RIP using SDM, 300–301 configuring serial interfaces, 293–295 viewing interface status, 297–298 security of auxiliary port password, 480 configuring banners, 483–485 configuring SSH, 486–487 configuring user accounts, 482–483 console port password, 479 encrypting passwords, 480–482 Telnet password, 480 serial interfaces description for, 209 IP settings, 208 other settings, 209–213 static routing adding, 326–329 configuring gateway of last resort (GWLR), 329–332 deleting, 329 overview, 316–319, 325–326 routing process, 319–321 viewing routing tables, 321–325 statically assign IP addresses to, 91 troubleshooting layer-1 and layer-2, 427–429 layer-1 and layer-2 troubleshooting, 427–429 layer-3, 429–431 layer-3 troubleshooting, 429–431 show controllers serial 0/0 command, 429 show interface serial 0/0 command, 428 show interfaces command, 427–428 show ip interface brief command, 428–429 viewing configuration files, 224–225 viewing interface configurations show controller command, 228–229 show interface f0/0 command, 227 show interfaces command, 226–227 show ip interface brief command, 228 show ip interface command, 227–228 Routing Information Protocol (RIP) configuring SDM, 300–301 RIPv1 (RIP version 1), 349, 352–353 28_647486-bindex.indd 56928_647486-bindex.indd 569 569 RIPv2 (Routing Information Protocol v2), 349–350, 353–354 troubleshooting, 354–357 routing tables connected routes, 322–323 link state routing protocols, 347 overview, 424–425 static routes, 323–325 update message, 343 RPS LED, 368–369 running configuration, 177 running-config file, 220, 221 RX (receive pins), 31 RX-Boot, 249 RX-boot mini-IOS, 176 S S (static), 322 SCNP (Security Certified Network Professional), screened-host firewall, 463 screened-subnet, 463 screening, 463 SDM See Security Device Manager (SDM) Secure Shell (SSH), 486–487 security authentication smart card, 450–451 strong passwords, 451 authorization, 451 availability, 452–453 confidentiality, 452 devices firewalls, 461–463 intrusion detection system (IDS), 463–464 physical premises, 476 routers, 478–487 secure facility, 477 switches, 464–465, 487–490 virtual private networks (VPN), 465–466 windows and lighting, 476–477 workstations and servers, 477 exploits, 452 integrity, 452 of ports configuring, 397–400 viewing, 400–401 10/15/10 11:29 PM10/15/10 11:29 PM 570 CCENT Certification All-In-One For Dummies security (continued) social engineering attacks, 454–455 terminology of, 450–453 threats to network, 467–468 servers, 466–467 workstations, 466 vulnerability, 451–452 wireless changing SSID, 511 disabling SSID broadcasting, 511 enabling encryption, 511–512 encryption protocols, 512–517 restrict by MAC, 511 Security Certified Network Professional (SCNP), Security Device Manager (SDM) configuring, 290–293 configuring DHCP using, 299 configuring DHCP using SDM, 299 configuring Ethernet interfaces, 295–297 configuring hostnames, 298–299 configuring NAT using, 301–304 configuring NAT using SDM, 301–304 configuring RIP using, 300–301 configuring RIP using SDM, 300–301 configuring serial interfaces, 293–295 overview, 173–174 viewing interface status, 297–298 security violation count, 401 segments, 43 Select Installation Type screen, 241 self-replicating, 460 Sequence Number field, 103 sequence numbers, 98 Serial 0/2/0 is administratively down status, 226 serial interfaces configuring, 293–295 description for, 209 IP settings, 208 other settings bandwidth, 212–213 clock rate, 211–212 encapsulation protocol, 209–211 serial links High Data Link Control (HDLC), 529 Point-To-Point Protocol (PPP), 529–531 28_647486-bindex.indd 57028_647486-bindex.indd 570 protocols, 529–531 setting clock rate, 531–532 serial ports, 167–169, 525–527 Serial0/2/0 is down status, 226 Serial0/2/0 is up status, 226 servers authentication, 64 domain name system (DNS), 62–64 e-mail, 62 security of, 477 statically assign IP addresses to, 91 threats to, 466–467 Web, 61 service dhcp command, 278 service password-encryption command, 217, 481 service provider, 167 service set identifier (SSID), 511 services authentication servers, 64 domain name system (DNS) servers, 62–64 Dynamic Host Configuration Protocol (DHCP) servers, 64–65 e-mail servers, 62 Network Address Translation (NAT), 65–67 Web servers, 61 sessions hijacking attacks, 459 layers, 42 suspending and disconnecting, 258–259 Setup cannot continue message, 542 setup command, 180, 182 setup mode, 182 Sharing Internet Connection screen, 302 shielded twisted pair (STP) cables, 27 show arp command, 419 show cdp commands, 249, 251 show cdp entry * command, 254 show cdp entry command, 254–255 show cdp entry device_ID command, 431 show cdp neighbors command, 252–254, 431 show cdp neighbors detail command, 253–254, 431 10/15/10 11:29 PM10/15/10 11:29 PM Index show commands, 206, 426 show controller command, 228–229 show controllers serial 0/0 command, 429 show controllers serial slot/ port command, 429 show flash command, 245, 247 show history command, 222 show hosts command, 274, 275, 425 show interface f0/0 command, 227 show interface serial 0/0 command, 428 show interface type command, 428 show interfaces command, 226–227, 427–428 show ip arp command, 419 show ip dhcp binding command, 278 show ip dhcp server statistics command, 278 show ip interface brief command, 228, 428–429 show ip interface command, 227–228 show ip protocols command, 354, 356, 430 show ip route command, 322, 326, 329, 430 show mac-address-table command, 373, 400 show port-security address command, 400 show port-security interface command, 400 show running-config command, 208, 214, 216 show sessions command, 258, 259 show startup-config command, 225, 426 show terminal command, 222 show users command, 260 show version command, 186–187, 286 show vlan command, 404, 405 shutdown action, 399 shutdown command, 207, 396–397 simlets, 12, 225 Simple Mail Transfer Protocol (SMTP), 62, 96 Simple Network Management Protocol (SNMP), 97 simplex communication, 67, 396 simulators, 334 28_647486-bindex.indd 57128_647486-bindex.indd 571 571 single-mode fiber (SMF) cables, 30 1604 router ports, 169–170 slot/port syntax, 166, 172 small routed networks, 13 small switch networks, 13 smart cards, 450–451 SMF (single-mode fiber) cables, 30 SMTP (Simple Mail Transfer Protocol), 62, 96 smurf attack, 457 sniffers, 55 SNMP (Simple Network Management Protocol), 97, 105 social engineering attacks, 454–455 software-based attacks SQL injection, 460 viruses, 460–461 logic bombs, 461 Trojan horses, 460 worms, 460–461 Source Address field, 107 Source Port field, 103, 105 sources, 57 Spanning Tree Protocol (STP), 376 special addresses Automatic Private IP Addressing (APIPA), 89–90 public versus private addresses, 89–90 speed command, 206, 395 speed mode, 371 Speed mode LED, 369 spoofing attack, 457–458 SQL injection attack, 460 SSH (Secure Shell), 486–487 SSID (service set identifier), 511 standards 10 Gigabit Ethernet, 39–40 802.11a, 506 802.11b, 507 802.11g, 507 802.11n, 507 Fast Ethernet, 38 Gigabit Ethernet, 39 star topology, 24 star-bus topology, 24 Starting IP and Ending IP address field, 299 startup configuration, 178 startup operations, 176 startup-config file, 220, 221, 225 10/15/10 11:29 PM10/15/10 11:29 PM 572 CCENT Certification All-In-One For Dummies stateful packet inspection firewall, 462 states, 84–85 static, 91, 327 static (S), 322 static addressing, 91 static NAT, 281 static routing adding, 326–329 configuring gateway of last resort (GWLR), 329–332 deleting, 329 lab exercises configuring gateway of last resort (GWLR), 334–337 configuring static routes, 334 planning routes, 332–333 overview, 316–319, 323–326 routing process, 319–321 viewing routing tables connected routes, 322–323 static routes, 323–325 Statically Set IP Address option, 93 status mode, 370 Status mode LED, 369 sticky option, 398, 399, 400, 488 store-and-forward switch operation mode, 377 STP (shielded twisted pair) cables, 27 STP (Spanning Tree Protocol), 376 straight-through cables, 31–32 streaming applications, 105 strong passwords, 451 subnet bits, 125, 126 subnet mask, 82–83, 127, 133 Subnet Mask column, 146 Subnet mask field, 299 subnet mask option, 327 Subnet Size column, 146 subnets, 126 subnetting class A network broadcast address, 130–131 first valid addresses, 129–130 last valid addresses, 131–132 network IDs, 128–129 overview, 124–128 class B network, 132–137 28_647486-bindex.indd 57228_647486-bindex.indd 572 class C network, 137–141 fast subnetting, 141–143 IP Subnet Zero, 143–144 lab exercises, 151–156 reasons for, 122–124 variable-length subnet masks (VLSM), 144–151 suites, 80 suspending sessions, 258–259 switches basic configurations configuring default gateway setting, 383–385 configuring device name, 382 configuring IP address, 382–383 circuits, 523 Cisco switches RPS LED, 368–369 switch display modes, 369–371 system LED, 368 configuring switch ports adding port descriptions, 394 adjusting duplex setting, 395–396 choosing port speed, 394–395 disabling and enabling ports, 396–397 port security, 397–401 viewing port configuration, 397 core switch services address learning, 373–374 filtering and forwarding, 374–375 loop avoidance, 375–377 data flow local communication, 378–379 remote communication, 380–382 lab exercises configuring port security, 406–407 configuring ports, 406 configuring VLANs, 408–412 overview, 58–60, 372–373 packets, 524–525 ports Console, 171 Ethernet, 172 security of configuring port security, 487–488 disabling ports, 488–490 overview, 464–465 10/15/10 11:29 PM10/15/10 11:29 PM Index statically assign IP addresses to, 91 switch operation modes cut-through, 377–378 fragment-free, 378 store-and-forward, 377 VLANs basic configurations, 403–406 concepts of, 401–403 switchport command, 404 switchport port-security command, 398, 488 synchronization (SYN) flood, 457 synchronization (SYN) phase, 101 system LED, 368 systems, 54 T T1 links, 524 T3 links, 524 tables configuring hostname, 272–274 MAC address, 372 neighbors, 347 routing connected routes, 322–325 link state routing protocols, 347 overview, 424–425 update message, 343 translation, 279 TCP (Transmission Control Protocol) application layer protocols, 96–97 assigning IP addresses configuring TCP/IP on clients, 91–93 identifying invalid addresses, 90–93 static addressing versus dynamic addressing, 91 converting decimal to binary, 83–85 data encapsulation, 95 four layer models, 93–94 IP address classes A, 85–87 B, 87–88 C, 88 D and E, 88–89 28_647486-bindex.indd 57328_647486-bindex.indd 573 573 IP addressing default gateway, 83 IP address, 80–81 subnet mask, 82–83 lab exercises converting binary to decimal, 114 converting decimal to binary, 113 identifying address classes, 113 identifying invalid addresses, 114 match protocol, 115–118 special addresses Automatic Private IP Addressing (APIPA), 89–90 public versus private addresses, 89–90 three-way handshake, 100–102 transport layer protocols Transmission Control Protocol (TCP), 98–104 User Datagram Protocol (UDP), 104–105 User Datagram Protocol (UDP) Address Resolution Protocol (ARP), 110–112 Internet Control Message Protocol (ICMP), 107–110 Internet Protocol (IP), 105–107 TCP flags, 102 TCP header, 102–104 TCP/ IP Internet model, 94 TCP ports, 98–100 TCP/IP option, 92 TCP/IP settings, 424 telcos, 167 Telnet application protocol, 96 monitoring connections, 260–261 overview, 256–257 passwords, 216–217, 480 suspending and disconnecting sessions, 258–259 telnet command, 257, 419 Temporal Key Integrity Protocol (TKIP), 512 temporary entry, 273–274 10 Gigabit Ethernet standards, 39–40 10 Gigabit port, 166 10Base2, 38 10/15/10 11:29 PM10/15/10 11:29 PM 574 CCENT Certification All-In-One For Dummies 10Base5, 38 10BaseT, 38 terminal history command, 223 terminal monitor command, 434 Test Engine tab, 540–541 test site, 15 testlets, 12 TFTP (Trivial File Transfer Protocol) installing software, 240–243 servers, 240 TFTP Server Manager option, 242 Thicknet cables, 26 Thinnet cables, 26 threats to networks, 467–468 to servers, 466–467 to workstations, 466 three-way handshake, 100–102 Time to Live (TTL) field, 107 timer parameter, 251 TKIP (Temporal Key Integrity Protocol), 512 token passing, 36 Token Ring architecture, 40–41 tokens, 36 topology ad hoc wireless network, 506 bus, 22–23, 24 hybrid, 24–25 networks, 22 of networks, 431–432 ring, 23 star, 24 star-bus, 24 table of, 347 Total Length field, 106 traceroute command, 418, 420, 421 tracert command, 420–421 traffic management broadcast domain, 68–70 collision domain, 70 duplexing, 67 overview, 70–71 types of communication, 67–68 trailers, 57 Transact SQL statements, 460 28_647486-bindex.indd 57428_647486-bindex.indd 574 translated IP, 280 translated ports, 280 translation table, 279 Transmission Control Protocol See TCP (Transmission Control Protocol) Transmission Control Protocol/Internet Protocol (TCP/IP), 80 transmit pins (TX), 31 transport input ssh command, 487 transport layer, 42, 94 transport layer protocols Transmission Control Protocol (TCP) TCP flags, 102 TCP header, 102–104 TCP ports, 98–100 three-way handshake, 100–102 User Datagram Protocol (UDP), 104–105 Trivial File Transfer Protocol (TFTP) server, 240 Trojan horses, 460 troubleshooting CD-ROM, 541–542 Cisco commands ARP cache, 419 Packet InterNet Groper (PING) command, 417–418 telnet command, 419 traceroute command, 418 connectivity cables and connectors, 422–423 LED indicators, 423 name resolution, 425 routing table, 424–425 TCP/IP settings, 424 debug commands disabling debugging, 435–436 example of, 433–434 overview, 432 lab exercises enabling debugging, 439–443 identifying connectivity issues, 436–437 troubleshooting configuration, 439 using show commands, 437–438 Routing Information Protocol (RIP), 354–357 viewing configuration files, 426 10/15/10 11:29 PM10/15/10 11:29 PM Index viewing network topology, 431–432 viewing router configuration layer-1 and layer-2 troubleshooting, 427–429 layer-3 troubleshooting, 429–431 show controllers serial 0/0 command, 429 show interface serial 0/0 command, 428 show interfaces command, 427–428 show ip interface brief command, 428–429 Windows commands ARP cache, 421 ipconfig command, 420 ping command, 420 tracert command, 420–421 wireless networking I — “Networking Basics” — contains all the basic networking information, including explanations of terminology and devices 03_647486-intro.indd 303_647486-intro.indd 10/15/10 11:18 PM10/15/10