The last exercise does something that is usually avoided: it carries out three real attacks on one's own network - a switch turned into a hub, a rogue DHCP server and a device that passes itself off as the gateway - and then closes their doors, one by one. At the end, you add a wireless network and compare its security with that of the cable.
1The golden rule of this exercise
The purpose of the exercise is not to teach you to attack, but to make you understand why the attacks work, because that is the only way in which defensive configurations stop being a memorized list and become understood decisions.
The three attacks have the same common denominator: the protocols of the local network were designed in an age in which anyone with physical access to the cable was, by definition, trustworthy. None of them has any authentication. All the countermeasures below add, in one form or another, exactly what is missing: a source of truth about who is allowed to say what.
| The attack | Why it works | The countermeasure |
|---|---|---|
| CAM overflow | the switching table is finite; once full, the switch floods everything | port-security |
| Rogue DHCP | DHCP has no authentication; the client believes the first answer | ip dhcp snooping |
| ARP poisoning | ARP accepts unsolicited replies, with no verification | ip arp inspection |
2Equipment needed
| Qty | Equipment | Model | Packet Tracer category | What it is for here |
|---|---|---|---|---|
| 1 | Router | 4331 | Network Devices → Routers | the gateway and the legitimate DHCP server |
| 1 | Access switch | 2960 | Network Devices → Switches | SW-ACCES, the device you are securing |
| 1 | Extra switch | 2960 | Network Devices → Switches | "the switch somebody brought in", for BPDU Guard |
| 2 | Computer | PC-PT | End Devices | PC-1 and PC-2, DHCP clients |
| 1 | Server | Server-PT | End Devices | SERVER, with a static address |
| 1 | Server (attacker) | Server-PT | End Devices | ATACATOR, with the DHCP service running |
| 1 | Access point | Access Point-PT | Network Devices → Wireless Devices | the wireless network |
| 1 | Laptop | Laptop-PT | End Devices | the wireless client - requires the WPC300N module |
| 1 | AAA server | Server-PT | End Devices | optional, for the RADIUS part |
WPC300N in its place → switch it back on. It is the step
everybody misses on the first attempt.3The topology
| Device | Address | Port | VLAN |
|---|---|---|---|
| R1 (gateway and DHCP server) | 192.168.100.1/24, on G0/0/0.10 | G0/0/0 (trunk) | 10 |
| PC-1, PC-2 | through DHCP | Fa0/1, Fa0/2 | 10 |
| SERVER | 192.168.100.10, static | Fa0/3 | 10 |
| ATACATOR | 192.168.100.66, static, with DHCP running | Fa0/10 | 10 |
| Wireless AP | - | Fa0/20 | 10 |
| Native VLAN of the trunk | - | - | 99, empty |
4The workbench
The network is already cabled and addressed, and ATACATOR already has a rogue DHCP server running - it is the hostile starting point. The extra switch is standing aside, unconnected; you will attach it yourselves, in the BPDU Guard section, from the Cables panel.
5Step 0: the network that works
Router(config)# hostname R1 R1(config)# interface gigabitEthernet 0/0/0 R1(config-if)# no ip address R1(config-if)# no shutdown R1(config-if)# exit R1(config)# interface gigabitEthernet 0/0/0.10 R1(config-subif)# encapsulation dot1Q 10 R1(config-subif)# ip address 192.168.100.1 255.255.255.0 R1(config-subif)# exit R1(config)# interface gigabitEthernet 0/0/0.99 R1(config-subif)# encapsulation dot1Q 99 native R1(config-subif)# exit R1(config)# ip dhcp excluded-address 192.168.100.1 192.168.100.19 R1(config)# ip dhcp pool LAN R1(dhcp-config)# network 192.168.100.0 255.255.255.0 R1(dhcp-config)# default-router 192.168.100.1 R1(dhcp-config)# dns-server 192.168.100.10 R1(dhcp-config)# end
Switch(config)# hostname SW-ACCES SW-ACCES(config)# vlan 10 SW-ACCES(config-vlan)# name UTILIZATORI SW-ACCES(config-vlan)# vlan 99 SW-ACCES(config-vlan)# name NATIV-GOL SW-ACCES(config-vlan)# exit SW-ACCES(config)# interface range fastEthernet 0/1 - 21 SW-ACCES(config-if-range)# switchport mode access SW-ACCES(config-if-range)# switchport access vlan 10 SW-ACCES(config-if-range)# exit SW-ACCES(config)# interface gigabitEthernet 0/1 SW-ACCES(config-if)# switchport mode trunk SW-ACCES(config-if)# switchport trunk native vlan 99 SW-ACCES(config-if)# switchport trunk allowed vlan 10,99 SW-ACCES(config-if)# end
interface range spares you 21 repetitions
Everything you type in config-if-range mode is applied to every port of the range at once. The
prompt reminds you where you are. It is the command you will use most often in a real day of
configuration.Check that the network works: from PC-2, ipconfig /renew and then
ping 192.168.100.10.
6Attack 1: the switch that becomes a hub
The switching table of a switch is finite. If it fills up, the switch can no longer learn new addresses and starts flooding unknown traffic out of every port - that is, it behaves like a hub, and the attacker sees everything.
- The initial situation
on SW-ACCES
SW-ACCES# show mac address-table SW-ACCES# show mac address-table count
Note how many entries there are and what the capacity is. Generate traffic between PC-1 and SERVER and observe that the traffic does not reach ATACATOR.
- Demonstrating the effect
Neither Packet Tracer nor the workbench in this page has a generator of frames with false MAC addresses, so we demonstrate the effect, not the attack: empty the table and look at what happens to the first frame.
on SW-ACCESSW-ACCES# clear mac address-table dynamic
Send a frame from PC-1 towards SERVER immediately. With the table empty, the destination is unknown, so the frame leaves out of every port, Fa0/10 included. This is exactly the state in which a CAM overflow attack keeps the switch, permanently.
- The countermeasure: port security
on every access port
SW-ACCES(config)# interface range fastEthernet 0/1 - 21 SW-ACCES(config-if-range)# switchport mode access SW-ACCES(config-if-range)# switchport port-security SW-ACCES(config-if-range)# switchport port-security maximum 2 SW-ACCES(config-if-range)# switchport port-security mac-address sticky SW-ACCES(config-if-range)# switchport port-security violation restrict SW-ACCES(config-if-range)# end SW-ACCES# show port-security SW-ACCES# show port-security address
Whymaximum 2and not 1 A single MAC looks safer, but it breaks two perfectly normal situations: an IP telephone with a computer attached behind it, and a virtual machine with an address of its own. A value of 2 or 3 is the usual compromise in office networks. - Compare the three violation actions
Action Excess frames Counter Notification The port protectdiscarded no no stays up restrictdiscarded yes SNMP + syslog stays up shutdown- yes SNMP + syslog err-disabled Test both behaviours: with
restrict, check that only the counter ofshow port-security interface fastEthernet 0/1changes; withshutdown, the port goes toerr-disabledand must be brought back up by hand:bringing an err-disabled port back upSW-ACCES(config)# interface fastEthernet 0/1 SW-ACCES(config-if)# shutdown SW-ACCES(config-if)# no shutdown
Choose the action sensiblyshutdownlooks the safest, but it means that any user who changes their laptop is left without a network until somebody comes to bring the port back up. In most office networks,restrictis the right compromise: it blocks suspicious traffic, but reports instead of punishing.
7Attack 2: the rogue DHCP server
An attacker starts a DHCP server on their computer and answers faster than the legitimate one. Every host that connects afterwards receives from them an address, a mask - and, above all, a gateway which is the attacker.
- Carry out the attack
In the workbench in this page, ATACATOR already has the service running. In Packet Tracer, replace the host with a Server-PT, give it the address
192.168.100.66and enable DHCP from the Services → DHCP tab, with these values:Parameter Value at the attacker Legitimate value Default Gateway 192.168.100.66 - itself 192.168.100.1 DNS Server 192.168.100.66 192.168.100.10 Start IP 192.168.100.150 192.168.100.20 On PC-1, ask for a new address:
on PC-1ipconfig /release ipconfig /renew ipconfig
Look at the Default Gateway field. If it shows
192.168.100.66, the attack succeeded: all its traffic towards the outside now passes through the attacker, who can read it and forward it on.Why it works DHCP has no authentication whatsoever. The client accepts the first offer received and has no way of telling a legitimate server from a rogue one. It is exactly the same category of problem as with ARP: a protocol designed in an age in which the local network was considered a trusted space. - The countermeasure: DHCP snooping
on SW-ACCES
SW-ACCES(config)# ip dhcp snooping SW-ACCES(config)# ip dhcp snooping vlan 10 SW-ACCES(config)# no ip dhcp snooping information option SW-ACCES(config)# interface gigabitEthernet 0/1 SW-ACCES(config-if)# ip dhcp snooping trust SW-ACCES(config-if)# exit SW-ACCES(config)# interface range fastEthernet 0/1 - 21 SW-ACCES(config-if-range)# ip dhcp snooping limit rate 10 SW-ACCES(config-if-range)# end SW-ACCES# show ip dhcp snooping
The idea, in one sentence: only the ports declared trusted are allowed to send DHCP replies. The uplink towards the router is trusted; every user port is not, and Offer messages coming from there are discarded by the switch.
Repeat the attack, from PC-2:
on PC-2ipconfig /release ipconfig /renew ipconfig
This time the gateway must be
192.168.100.1. Check on the router as well, withshow ip dhcp binding, that the allocation came from it.Look also at
show ip dhcp snooping binding: the switch has built a record of the (MAC, IP, VLAN, port) tuples observed in the legitimate transactions. That table is the foundation of the next step.
8Attack 3: ARP poisoning
The attacker sends unsolicited ARP messages, claiming that the IP address of the gateway belongs to them. The hosts update their cache and start sending them all the traffic destined for the outside.
- The normal situation
on PC-1
ping 192.168.100.1 arp -a
Note the MAC address associated with the gateway. Compare it with the real MAC address of the interface of R1, from
show arpon the router or from the configuration panel of the host. - The effect of the attack
Neither Packet Tracer nor the workbench in this page has a generator of forged ARP, so the demonstration is conceptual: if the attacker sent an ARP reply with
192.168.100.1 → their own MAC, the cache of PC-1 would show that MAC address next to the gateway. From then on, every frame destined for the outside would leave towards the attacker, who could read it and then forward it on - so that nothing would look broken.Check your understandingAfter the attack, what would change in the output of
arp -aon PC-1? What would stay unchanged, and why?See the answer
Only the MAC address next to
192.168.100.1would change. The IP address of the gateway would stay the same, a ping to it would still work, browsing would work, and the user would notice absolutely nothing. This is the quality that makes the attack dangerous: it breaks nothing visible.The only clue, for anyone who looks, is that the same MAC address would appear next to several IP addresses - or that the MAC of the gateway would change for no reason at all.
- The countermeasure: Dynamic ARP Inspection
on SW-ACCES - requires DHCP snooping to be active
SW-ACCES(config)# ip arp inspection vlan 10 SW-ACCES(config)# interface gigabitEthernet 0/1 SW-ACCES(config-if)# ip arp inspection trust SW-ACCES(config-if)# exit SW-ACCES(config)# arp access-list SERVERE SW-ACCES(config-arp-nacl)# permit ip host 192.168.100.10 mac host 000A.0B0C.0D0E SW-ACCES(config)# ip arp inspection filter SERVERE vlan 10 SW-ACCES(config)# end SW-ACCES# show ip arp inspection
Mind the hosts with static addresses DAI checks ARP messages against the record built by DHCP snooping. A statically configured host does not appear there, so its legitimate ARP messages would be discarded. It has to be declared explicitly, through an ARP ACL - as in the example above for SERVER. It is the most frequent reason why "DAI broke the network".
9Closing the other doors
VLAN hopping
SW-ACCES(config)# interface range fastEthernet 0/1 - 21 SW-ACCES(config-if-range)# switchport mode access SW-ACCES(config-if-range)# switchport nonegotiate SW-ACCES(config-if-range)# exit SW-ACCES(config)# interface gigabitEthernet 0/1 SW-ACCES(config-if)# switchport nonegotiate SW-ACCES(config-if)# exit SW-ACCES(config)# vlan 999 SW-ACCES(config-vlan)# name NEFOLOSIT SW-ACCES(config-vlan)# exit SW-ACCES(config)# interface fastEthernet 0/21 SW-ACCES(config-if)# switchport access vlan 999 SW-ACCES(config-if)# shutdown
| The measure | The attack it closes |
|---|---|
switchport nonegotiate on the access ports | switch spoofing: the port can no longer be talked into becoming a trunk |
| native VLAN 99, empty (configured at step 0) | double tagging: there are no hosts left in the native VLAN |
switchport trunk allowed vlan 10,99 | limits what anyone can inject on the trunk |
| unused ports shut down, in a dead VLAN | physical access to a free socket gains nothing any more |
Attacks on Spanning Tree
SW-ACCES(config)# interface range fastEthernet 0/1 - 21 SW-ACCES(config-if-range)# spanning-tree portfast SW-ACCES(config-if-range)# spanning-tree bpduguard enable
Test it in the workbench: pick SW-STRAIN, in the Cables panel press connect on
Fa0/1 and choose SW-ACCES : Fa0/15. Then, on SW-ACCES:
SW-ACCES# show interfaces fastEthernet 0/15 status
The port appears as err-disabled at once: a user port has no reason to receive BPDUs, and if
it does, a switch has been attached there - legitimate or not. Take the cable out and bring the port back up
with shutdown / no shutdown.
Managing the switch
SW-ACCES(config)# ip domain-name retele.local SW-ACCES(config)# crypto key generate rsa SW-ACCES(config)# username admin privilege 15 secret Admin123 SW-ACCES(config)# enable secret Enable123 SW-ACCES(config)# service password-encryption SW-ACCES(config)# line vty 0 4 SW-ACCES(config-line)# transport input ssh SW-ACCES(config-line)# login local SW-ACCES(config-line)# exec-timeout 5 0 SW-ACCES(config-line)# exit SW-ACCES(config)# banner motd #Authorized access only. Activity is logged.# SW-ACCES(config)# end SW-ACCES# copy running-config startup-config
10The wireless network
An access point is, at layer 2, a hub in the air: everything a client transmits reaches everybody else within its range. The difference from an ordinary hub is that you do not have to get into the building in order to attach to it. That is why encryption is not optional.
In the workbench in this page, the laptop is already associated: check with
ping 192.168.100.10 and look at the Path of the last packet table - the segment through
the AP appears just like any other, because from the point of view of the network it really is the same.
- An access point with WPA2-PSK in Packet Tracer
Add an Access Point-PT on Fa0/20 and a laptop with a wireless card. Configure the AP from the Config → Port 1 tab:
Parameter Value SSID RL-LAB Authentication WPA2-PSK Encryption AES Pass Phrase ParolaLung4Lab2026 Channel 1, 6 or 11 On the laptop, from Desktop → PC Wireless, connect to the network. Check with
ipconfigthat it received an address through DHCP and ping SERVER. - Four security experiments
Experiment What you observe The conclusion Set the authentication to Disabledanybody connects instantly an open network is exactly that: open Set WEPwith a 10-character hexadecimal keyit works, and Packet Tracer accepts it without hesitation WEP gives the impression of security; in reality it is broken in minutes Disable the broadcasting of the SSID the network no longer appears in the list, but connecting by hand works hiding is not security: the SSID appears in the frames of legitimate clients Enable MAC filtering and add only the laptop other devices are rejected useful as hygiene, useless against somebody who can copy a MAC address - Individual authentication, with RADIUS
Add an AAA server in the wired network, enable the AAA service from the Services tab and create two users. Register the AP as a RADIUS client, then change the authentication of the AP to
WPA2with a RADIUS server.Connect the laptop with its own user name and password. Then delete the user from the server and try again.
The difference that matters With WPA2-PSK, everybody uses the same password. When an employee leaves, it must be changed for everybody - so, in practice, it is never changed.
With WPA2-Enterprise, everybody has their own credentials. A user is revoked in ten seconds, individually, and the logs show who connected, when and from which device.
11The checklist
This is the most useful deliverable of the whole semester: what is configured on any access switch, before it is put into production.
| # | The measure | Why |
|---|---|---|
| 1 | a name, a banner, passwords with enable secret | a device without a name was never configured deliberately |
| 2 | SSH instead of Telnet, with login local and exec-timeout | Telnet sends passwords in the clear |
| 3 | access-class on the VTY lines | limits where a connection may be attempted from |
| 4 | access ports: mode access + nonegotiate | closes switch spoofing |
| 5 | an empty native VLAN, an explicit list of VLANs on the trunk | closes double tagging |
| 6 | port-security with restrict and sticky | limits CAM overflow and MAC spoofing |
| 7 | portfast + bpduguard on the user ports | closes the STP attacks |
| 8 | ip dhcp snooping, with the uplink trusted | closes rogue DHCP |
| 9 | ip arp inspection, plus an ARP ACL for the static hosts | closes ARP poisoning |
| 10 | unused ports: shut down, in a dead VLAN | a free socket is no longer a door |
12Assignments
- Build the topology and check normal operation, before any attack
- Demonstrate the effect of an emptied CAM table and configure port security on every access port
- Carry out the rogue DHCP server attack and demonstrate that DHCP snooping stops it
- Explain in writing the mechanism of ARP poisoning and configure Dynamic ARP Inspection, including an ARP ACL for the static host
- Apply all the measures against VLAN hopping and the STP attacks; demonstrate BPDU Guard in action
- Configure administrative access through SSH, with a source restriction
- Build the wireless network with WPA2-PSK, then migrate it to RADIUS authentication
- Write the final checklist for securing an access switch, with the justification of every line
13Going further
You are called in to assess the security of the network of a small company. You find the following configuration on the access switch:
hostname Switch ! interface range FastEthernet0/1 - 24 switchport mode dynamic auto ! interface GigabitEthernet0/1 switchport mode trunk switchport trunk native vlan 1 ! line vty 0 4 password cisco login transport input all ! enable password cisco
Requirements:
- Identify all the security problems in this configuration - there are at least seven.
- For each, state which attack becomes possible and which lecture it comes from.
- Write the corrected configuration, complete.
- Sort the problems by severity and argue the order.
See the list of problems
switchport mode dynamic autoon every port - DTP is active, so switch spoofing is possible from any user port (lecture 12).- Native VLAN 1 on the trunk, that is, the same as the VLAN of the hosts - double tagging is possible (lecture 12).
- No
switchport trunk allowed vlan- the trunk carries all 4094 VLANs. transport input all- Telnet is permitted, so passwords travel in the clear (lecture 8).enable passwordinstead ofenable secret- the password is stored reversibly.- The password
cisco, in both places - broken instantly by any dictionary (lecture 12). - No
access-classon the VTY lines - anybody in the network can try to connect. - No port security, no DHCP snooping, no DAI - CAM overflow, rogue DHCP and ARP poisoning are all possible.
- No
portfastand nobpduguard- an STP attack is possible from any port. - The unused ports are up and in VLAN 1 - anybody who plugs into a socket has immediate access to the network.
- The default name
Switchand the absence of any banner - signs that the device was never configured deliberately.
For sorting by severity, think of three criteria: how easy it is to exploit, what the attacker gains, and how quickly they would be noticed. The weak password combined with Telnet being permitted is probably more severe than the absence of DAI - because it leads directly to complete control over the device, without anybody finding out.
14Self-check questions
15Deliverables
| Deliverable | Format | Weight |
|---|---|---|
| A fully secured Packet Tracer file, with a working wireless network | .pkt | 30 % |
| The documentation of the three attacks: mechanism, effect observed, countermeasure | document | 25 % |
| The checklist for securing a switch, with justifications | document | 15 % |
| The comparison WPA2-PSK / WPA2-Enterprise, with your own arguments | document | 10 % |
| The audit report from the challenge | document | 20 % |