Local Area Networks / Laboratory
LABORATORY 07

Access network and wireless security

Duration: 2 hours Platform: the workbench in this page, or Packet Tracer Background: lectures 11–12 PDF: download the notes RO versiunea română

The last exercise does something that is usually avoided: it carries out three real attacks on one's own network - a switch turned into a hub, a rogue DHCP server and a device that passes itself off as the gateway - and then closes their doors, one by one. At the end, you add a wireless network and compare its security with that of the cable.

1The golden rule of this exercise

Read before you begin Every attack in this exercise is carried out exclusively on your own topology, in the laboratory or in the workbench in this page. The same techniques applied to a real network - that of the faculty, of a company, of a neighbour - constitute a criminal offence, whatever the intention and whether or not "nothing was broken".

The purpose of the exercise is not to teach you to attack, but to make you understand why the attacks work, because that is the only way in which defensive configurations stop being a memorized list and become understood decisions.

The three attacks have the same common denominator: the protocols of the local network were designed in an age in which anyone with physical access to the cable was, by definition, trustworthy. None of them has any authentication. All the countermeasures below add, in one form or another, exactly what is missing: a source of truth about who is allowed to say what.

The attackWhy it worksThe countermeasure
CAM overflowthe switching table is finite; once full, the switch floods everythingport-security
Rogue DHCPDHCP has no authentication; the client believes the first answerip dhcp snooping
ARP poisoningARP accepts unsolicited replies, with no verificationip arp inspection

2Equipment needed

QtyEquipmentModelPacket Tracer categoryWhat it is for here
1Router4331Network Devices → Routersthe gateway and the legitimate DHCP server
1Access switch2960Network Devices → SwitchesSW-ACCES, the device you are securing
1Extra switch2960Network Devices → Switches"the switch somebody brought in", for BPDU Guard
2ComputerPC-PTEnd DevicesPC-1 and PC-2, DHCP clients
1ServerServer-PTEnd DevicesSERVER, with a static address
1Server (attacker)Server-PTEnd DevicesATACATOR, with the DHCP service running
1Access pointAccess Point-PTNetwork Devices → Wireless Devicesthe wireless network
1LaptopLaptop-PTEnd Devicesthe wireless client - requires the WPC300N module
1AAA serverServer-PTEnd Devicesoptional, for the RADIUS part
The laptop has no wireless card out of the factory In Packet Tracer, open the laptop → the Physical tab → switch it off from the power button → pull out the existing Ethernet module → put a WPC300N in its place → switch it back on. It is the step everybody misses on the first attempt.

3The topology

R1gateway + DHCP SW-ACCES2960 · 24 ports G0/1 · trunk PC-1 PC-2 SERVER ATACATOR AP LAPTOP Fa0/1Fa0/2 Fa0/3 Fa0/10 Fa0/20Wi-Fi
Fig. 1 - The topology of the exercise. The ATACATOR host is an ordinary computer, attached to an ordinary port - exactly as a laptop somebody brought into the meeting room would look.
DeviceAddressPortVLAN
R1 (gateway and DHCP server)192.168.100.1/24, on G0/0/0.10G0/0/0 (trunk)10
PC-1, PC-2through DHCPFa0/1, Fa0/210
SERVER192.168.100.10, staticFa0/310
ATACATOR192.168.100.66, static, with DHCP runningFa0/1010
Wireless AP-Fa0/2010
Native VLAN of the trunk--99, empty

4The workbench

The network is already cabled and addressed, and ATACATOR already has a rogue DHCP server running - it is the hostile starting point. The extra switch is standing aside, unconnected; you will attach it yourselves, in the BPDU Guard section, from the Cables panel.

5Step 0: the network that works

on R1
Router(config)# hostname R1
R1(config)# interface gigabitEthernet 0/0/0
R1(config-if)# no ip address
R1(config-if)# no shutdown
R1(config-if)# exit
R1(config)# interface gigabitEthernet 0/0/0.10
R1(config-subif)# encapsulation dot1Q 10
R1(config-subif)# ip address 192.168.100.1 255.255.255.0
R1(config-subif)# exit
R1(config)# interface gigabitEthernet 0/0/0.99
R1(config-subif)# encapsulation dot1Q 99 native
R1(config-subif)# exit

R1(config)# ip dhcp excluded-address 192.168.100.1 192.168.100.19
R1(config)# ip dhcp pool LAN
R1(dhcp-config)# network 192.168.100.0 255.255.255.0
R1(dhcp-config)# default-router 192.168.100.1
R1(dhcp-config)# dns-server 192.168.100.10
R1(dhcp-config)# end
on SW-ACCES
Switch(config)# hostname SW-ACCES
SW-ACCES(config)# vlan 10
SW-ACCES(config-vlan)# name UTILIZATORI
SW-ACCES(config-vlan)# vlan 99
SW-ACCES(config-vlan)# name NATIV-GOL
SW-ACCES(config-vlan)# exit

SW-ACCES(config)# interface range fastEthernet 0/1 - 21
SW-ACCES(config-if-range)# switchport mode access
SW-ACCES(config-if-range)# switchport access vlan 10
SW-ACCES(config-if-range)# exit

SW-ACCES(config)# interface gigabitEthernet 0/1
SW-ACCES(config-if)# switchport mode trunk
SW-ACCES(config-if)# switchport trunk native vlan 99
SW-ACCES(config-if)# switchport trunk allowed vlan 10,99
SW-ACCES(config-if)# end
interface range spares you 21 repetitions Everything you type in config-if-range mode is applied to every port of the range at once. The prompt reminds you where you are. It is the command you will use most often in a real day of configuration.

Check that the network works: from PC-2, ipconfig /renew and then ping 192.168.100.10.

6Attack 1: the switch that becomes a hub

The switching table of a switch is finite. If it fills up, the switch can no longer learn new addresses and starts flooding unknown traffic out of every port - that is, it behaves like a hub, and the attacker sees everything.

  1. The initial situation
    on SW-ACCES
    SW-ACCES# show mac address-table
    SW-ACCES# show mac address-table count
    

    Note how many entries there are and what the capacity is. Generate traffic between PC-1 and SERVER and observe that the traffic does not reach ATACATOR.

  2. Demonstrating the effect

    Neither Packet Tracer nor the workbench in this page has a generator of frames with false MAC addresses, so we demonstrate the effect, not the attack: empty the table and look at what happens to the first frame.

    on SW-ACCES
    SW-ACCES# clear mac address-table dynamic
    

    Send a frame from PC-1 towards SERVER immediately. With the table empty, the destination is unknown, so the frame leaves out of every port, Fa0/10 included. This is exactly the state in which a CAM overflow attack keeps the switch, permanently.

  3. The countermeasure: port security
    on every access port
    SW-ACCES(config)# interface range fastEthernet 0/1 - 21
    SW-ACCES(config-if-range)# switchport mode access
    SW-ACCES(config-if-range)# switchport port-security
    SW-ACCES(config-if-range)# switchport port-security maximum 2
    SW-ACCES(config-if-range)# switchport port-security mac-address sticky
    SW-ACCES(config-if-range)# switchport port-security violation restrict
    SW-ACCES(config-if-range)# end
    
    SW-ACCES# show port-security
    SW-ACCES# show port-security address
    
    Why maximum 2 and not 1 A single MAC looks safer, but it breaks two perfectly normal situations: an IP telephone with a computer attached behind it, and a virtual machine with an address of its own. A value of 2 or 3 is the usual compromise in office networks.
  4. Compare the three violation actions
    ActionExcess framesCounterNotificationThe port
    protectdiscardednonostays up
    restrictdiscardedyesSNMP + syslogstays up
    shutdown-yesSNMP + syslogerr-disabled

    Test both behaviours: with restrict, check that only the counter of show port-security interface fastEthernet 0/1 changes; with shutdown, the port goes to err-disabled and must be brought back up by hand:

    bringing an err-disabled port back up
    SW-ACCES(config)# interface fastEthernet 0/1
    SW-ACCES(config-if)# shutdown
    SW-ACCES(config-if)# no shutdown
    
    Choose the action sensibly shutdown looks the safest, but it means that any user who changes their laptop is left without a network until somebody comes to bring the port back up. In most office networks, restrict is the right compromise: it blocks suspicious traffic, but reports instead of punishing.

7Attack 2: the rogue DHCP server

An attacker starts a DHCP server on their computer and answers faster than the legitimate one. Every host that connects afterwards receives from them an address, a mask - and, above all, a gateway which is the attacker.

  1. Carry out the attack

    In the workbench in this page, ATACATOR already has the service running. In Packet Tracer, replace the host with a Server-PT, give it the address 192.168.100.66 and enable DHCP from the Services → DHCP tab, with these values:

    ParameterValue at the attackerLegitimate value
    Default Gateway192.168.100.66 - itself192.168.100.1
    DNS Server192.168.100.66192.168.100.10
    Start IP192.168.100.150192.168.100.20

    On PC-1, ask for a new address:

    on PC-1
    ipconfig /release
    ipconfig /renew
    ipconfig
    

    Look at the Default Gateway field. If it shows 192.168.100.66, the attack succeeded: all its traffic towards the outside now passes through the attacker, who can read it and forward it on.

    Why it works DHCP has no authentication whatsoever. The client accepts the first offer received and has no way of telling a legitimate server from a rogue one. It is exactly the same category of problem as with ARP: a protocol designed in an age in which the local network was considered a trusted space.
  2. The countermeasure: DHCP snooping
    on SW-ACCES
    SW-ACCES(config)# ip dhcp snooping
    SW-ACCES(config)# ip dhcp snooping vlan 10
    SW-ACCES(config)# no ip dhcp snooping information option
    
    SW-ACCES(config)# interface gigabitEthernet 0/1
    SW-ACCES(config-if)# ip dhcp snooping trust
    SW-ACCES(config-if)# exit
    
    SW-ACCES(config)# interface range fastEthernet 0/1 - 21
    SW-ACCES(config-if-range)# ip dhcp snooping limit rate 10
    SW-ACCES(config-if-range)# end
    
    SW-ACCES# show ip dhcp snooping
    

    The idea, in one sentence: only the ports declared trusted are allowed to send DHCP replies. The uplink towards the router is trusted; every user port is not, and Offer messages coming from there are discarded by the switch.

    Repeat the attack, from PC-2:

    on PC-2
    ipconfig /release
    ipconfig /renew
    ipconfig
    

    This time the gateway must be 192.168.100.1. Check on the router as well, with show ip dhcp binding, that the allocation came from it.

    Look also at show ip dhcp snooping binding: the switch has built a record of the (MAC, IP, VLAN, port) tuples observed in the legitimate transactions. That table is the foundation of the next step.

8Attack 3: ARP poisoning

The attacker sends unsolicited ARP messages, claiming that the IP address of the gateway belongs to them. The hosts update their cache and start sending them all the traffic destined for the outside.

  1. The normal situation
    on PC-1
    ping 192.168.100.1
    arp -a
    

    Note the MAC address associated with the gateway. Compare it with the real MAC address of the interface of R1, from show arp on the router or from the configuration panel of the host.

  2. The effect of the attack

    Neither Packet Tracer nor the workbench in this page has a generator of forged ARP, so the demonstration is conceptual: if the attacker sent an ARP reply with 192.168.100.1 → their own MAC, the cache of PC-1 would show that MAC address next to the gateway. From then on, every frame destined for the outside would leave towards the attacker, who could read it and then forward it on - so that nothing would look broken.

    Check your understanding

    After the attack, what would change in the output of arp -a on PC-1? What would stay unchanged, and why?

    See the answer

    Only the MAC address next to 192.168.100.1 would change. The IP address of the gateway would stay the same, a ping to it would still work, browsing would work, and the user would notice absolutely nothing. This is the quality that makes the attack dangerous: it breaks nothing visible.

    The only clue, for anyone who looks, is that the same MAC address would appear next to several IP addresses - or that the MAC of the gateway would change for no reason at all.

  3. The countermeasure: Dynamic ARP Inspection
    on SW-ACCES - requires DHCP snooping to be active
    SW-ACCES(config)# ip arp inspection vlan 10
    
    SW-ACCES(config)# interface gigabitEthernet 0/1
    SW-ACCES(config-if)# ip arp inspection trust
    SW-ACCES(config-if)# exit
    
    SW-ACCES(config)# arp access-list SERVERE
    SW-ACCES(config-arp-nacl)# permit ip host 192.168.100.10 mac host 000A.0B0C.0D0E
    SW-ACCES(config)# ip arp inspection filter SERVERE vlan 10
    SW-ACCES(config)# end
    
    SW-ACCES# show ip arp inspection
    
    Mind the hosts with static addresses DAI checks ARP messages against the record built by DHCP snooping. A statically configured host does not appear there, so its legitimate ARP messages would be discarded. It has to be declared explicitly, through an ARP ACL - as in the example above for SERVER. It is the most frequent reason why "DAI broke the network".

9Closing the other doors

VLAN hopping

on SW-ACCES
SW-ACCES(config)# interface range fastEthernet 0/1 - 21
SW-ACCES(config-if-range)# switchport mode access
SW-ACCES(config-if-range)# switchport nonegotiate
SW-ACCES(config-if-range)# exit

SW-ACCES(config)# interface gigabitEthernet 0/1
SW-ACCES(config-if)# switchport nonegotiate
SW-ACCES(config-if)# exit

SW-ACCES(config)# vlan 999
SW-ACCES(config-vlan)# name NEFOLOSIT
SW-ACCES(config-vlan)# exit
SW-ACCES(config)# interface fastEthernet 0/21
SW-ACCES(config-if)# switchport access vlan 999
SW-ACCES(config-if)# shutdown
The measureThe attack it closes
switchport nonegotiate on the access portsswitch spoofing: the port can no longer be talked into becoming a trunk
native VLAN 99, empty (configured at step 0)double tagging: there are no hosts left in the native VLAN
switchport trunk allowed vlan 10,99limits what anyone can inject on the trunk
unused ports shut down, in a dead VLANphysical access to a free socket gains nothing any more

Attacks on Spanning Tree

on SW-ACCES
SW-ACCES(config)# interface range fastEthernet 0/1 - 21
SW-ACCES(config-if-range)# spanning-tree portfast
SW-ACCES(config-if-range)# spanning-tree bpduguard enable

Test it in the workbench: pick SW-STRAIN, in the Cables panel press connect on Fa0/1 and choose SW-ACCES : Fa0/15. Then, on SW-ACCES:

on SW-ACCES
SW-ACCES# show interfaces fastEthernet 0/15 status

The port appears as err-disabled at once: a user port has no reason to receive BPDUs, and if it does, a switch has been attached there - legitimate or not. Take the cable out and bring the port back up with shutdown / no shutdown.

Managing the switch

on SW-ACCES
SW-ACCES(config)# ip domain-name retele.local
SW-ACCES(config)# crypto key generate rsa
SW-ACCES(config)# username admin privilege 15 secret Admin123
SW-ACCES(config)# enable secret Enable123
SW-ACCES(config)# service password-encryption
SW-ACCES(config)# line vty 0 4
SW-ACCES(config-line)# transport input ssh
SW-ACCES(config-line)# login local
SW-ACCES(config-line)# exec-timeout 5 0
SW-ACCES(config-line)# exit
SW-ACCES(config)# banner motd #Authorized access only. Activity is logged.#
SW-ACCES(config)# end
SW-ACCES# copy running-config startup-config

10The wireless network

An access point is, at layer 2, a hub in the air: everything a client transmits reaches everybody else within its range. The difference from an ordinary hub is that you do not have to get into the building in order to attach to it. That is why encryption is not optional.

In the workbench in this page, the laptop is already associated: check with ping 192.168.100.10 and look at the Path of the last packet table - the segment through the AP appears just like any other, because from the point of view of the network it really is the same.

  1. An access point with WPA2-PSK in Packet Tracer

    Add an Access Point-PT on Fa0/20 and a laptop with a wireless card. Configure the AP from the Config → Port 1 tab:

    ParameterValue
    SSIDRL-LAB
    AuthenticationWPA2-PSK
    EncryptionAES
    Pass PhraseParolaLung4Lab2026
    Channel1, 6 or 11

    On the laptop, from Desktop → PC Wireless, connect to the network. Check with ipconfig that it received an address through DHCP and ping SERVER.

  2. Four security experiments
    ExperimentWhat you observeThe conclusion
    Set the authentication to Disabledanybody connects instantlyan open network is exactly that: open
    Set WEP with a 10-character hexadecimal keyit works, and Packet Tracer accepts it without hesitationWEP gives the impression of security; in reality it is broken in minutes
    Disable the broadcasting of the SSIDthe network no longer appears in the list, but connecting by hand workshiding is not security: the SSID appears in the frames of legitimate clients
    Enable MAC filtering and add only the laptopother devices are rejecteduseful as hygiene, useless against somebody who can copy a MAC address
  3. Individual authentication, with RADIUS

    Add an AAA server in the wired network, enable the AAA service from the Services tab and create two users. Register the AP as a RADIUS client, then change the authentication of the AP to WPA2 with a RADIUS server.

    Connect the laptop with its own user name and password. Then delete the user from the server and try again.

    The difference that matters With WPA2-PSK, everybody uses the same password. When an employee leaves, it must be changed for everybody - so, in practice, it is never changed.
    With WPA2-Enterprise, everybody has their own credentials. A user is revoked in ten seconds, individually, and the logs show who connected, when and from which device.

11The checklist

This is the most useful deliverable of the whole semester: what is configured on any access switch, before it is put into production.

#The measureWhy
1a name, a banner, passwords with enable secreta device without a name was never configured deliberately
2SSH instead of Telnet, with login local and exec-timeoutTelnet sends passwords in the clear
3access-class on the VTY lineslimits where a connection may be attempted from
4access ports: mode access + nonegotiatecloses switch spoofing
5an empty native VLAN, an explicit list of VLANs on the trunkcloses double tagging
6port-security with restrict and stickylimits CAM overflow and MAC spoofing
7portfast + bpduguard on the user portscloses the STP attacks
8ip dhcp snooping, with the uplink trustedcloses rogue DHCP
9ip arp inspection, plus an ARP ACL for the static hostscloses ARP poisoning
10unused ports: shut down, in a dead VLANa free socket is no longer a door

12Assignments

  • Build the topology and check normal operation, before any attack
  • Demonstrate the effect of an emptied CAM table and configure port security on every access port
  • Carry out the rogue DHCP server attack and demonstrate that DHCP snooping stops it
  • Explain in writing the mechanism of ARP poisoning and configure Dynamic ARP Inspection, including an ARP ACL for the static host
  • Apply all the measures against VLAN hopping and the STP attacks; demonstrate BPDU Guard in action
  • Configure administrative access through SSH, with a source restriction
  • Build the wireless network with WPA2-PSK, then migrate it to RADIUS authentication
  • Write the final checklist for securing an access switch, with the justification of every line

13Going further

An audit report

You are called in to assess the security of the network of a small company. You find the following configuration on the access switch:

the configuration found
hostname Switch
!
interface range FastEthernet0/1 - 24
 switchport mode dynamic auto
!
interface GigabitEthernet0/1
 switchport mode trunk
 switchport trunk native vlan 1
!
line vty 0 4
 password cisco
 login
 transport input all
!
enable password cisco

Requirements:

  1. Identify all the security problems in this configuration - there are at least seven.
  2. For each, state which attack becomes possible and which lecture it comes from.
  3. Write the corrected configuration, complete.
  4. Sort the problems by severity and argue the order.
See the list of problems
  1. switchport mode dynamic auto on every port - DTP is active, so switch spoofing is possible from any user port (lecture 12).
  2. Native VLAN 1 on the trunk, that is, the same as the VLAN of the hosts - double tagging is possible (lecture 12).
  3. No switchport trunk allowed vlan - the trunk carries all 4094 VLANs.
  4. transport input all - Telnet is permitted, so passwords travel in the clear (lecture 8).
  5. enable password instead of enable secret - the password is stored reversibly.
  6. The password cisco, in both places - broken instantly by any dictionary (lecture 12).
  7. No access-class on the VTY lines - anybody in the network can try to connect.
  8. No port security, no DHCP snooping, no DAI - CAM overflow, rogue DHCP and ARP poisoning are all possible.
  9. No portfast and no bpduguard - an STP attack is possible from any port.
  10. The unused ports are up and in VLAN 1 - anybody who plugs into a socket has immediate access to the network.
  11. The default name Switch and the absence of any banner - signs that the device was never configured deliberately.

For sorting by severity, think of three criteria: how easy it is to exploit, what the attacker gains, and how quickly they would be noticed. The weak password combined with Telnet being permitted is probably more severe than the absence of DAI - because it leads directly to complete control over the device, without anybody finding out.

14Self-check questions

15Deliverables

DeliverableFormatWeight
A fully secured Packet Tracer file, with a working wireless network.pkt30 %
The documentation of the three attacks: mechanism, effect observed, countermeasuredocument25 %
The checklist for securing a switch, with justificationsdocument15 %
The comparison WPA2-PSK / WPA2-Enterprise, with your own argumentsdocument10 %
The audit report from the challengedocument20 %