How to trunk ports on a Cisco Switch

Friday, February 5, 2010 by BBTUNA

Configure

In this section, you are presented with the information to configure the features described in this document.

Note: To find additional information on the commands used in this document, use the Command Lookup Tool ( registered customers only) .

Network Diagram

This document uses the network setup shown in the diagram below.

50a.jpg

Configurations

This document uses the configurations shown below.

Note: Router models with certain network modules may have different minimum Cisco IOS versions that support ISL trunking.

  • Catalyst 3512-XL

  • Cisco 2600 Router

  • 802.1Q Configuration on the Router for Cisco IOS Versions Earlier than 12.1(3)T

    switch#configure terminal
    Enter configuration commands, one per line. End with CNTL/Z.
    switch(config)#hostname 3512xl
    3512xl(config)#enable password mysecret
    3512xl(config)#line vty 0 4
    3512xl(config-line)#login
    3512xl(config-line)#password mysecret
    3512xl(config-line)#exit
    3512xl(config)#no logging console
    3512xl(config)#^Z
    !-- Set the IP address and default gateway for VLAN1 for management purposes.
    3512xl#configure terminal
    Enter configuration commands, one per line. End with CNTL/Z.
    3512xl(config)#int vlan 1
    3512xl(config-if)#ip address 10.10.10.2 255.255.255.0
    3512xl(config-if)#exit
    3512xl(config)#ip default-gateway 10.10.10.1
    3512xl(config)#end
    !-- Set the VTP Mode.
    !-- In our example, we have set the mode to be transparent.
    !-- Depending on your network, set the VTP Mode accordingly.
    !-- For details on VTP,
    !-- refer to
    !-- Creating and Maintaining VLANs on Catalyst 2900XL and 3500XL Switches.
    3512xl#vlan database
    3512xl(vlan)#vtp transparent
    Setting device to VTP TRANSPARENT mode.
    !-- Adding VLAN2. VLAN1 already exists by default.
    3512xl(vlan)#vlan 2
    VLAN 2 added:
    Name: VLAN0002
    3512xl(vlan)#exit
    APPLY completed.
    Exiting....
    !-- Enable trunking on the interface fastEthernet 0/1.
    3512xl#configure terminal
    Enter configuration commands, one per line. End with CNTL/Z.
    3512xl(config)#int fastEthernet 0/1
    3512xl(config-if)#switchport mode trunk
    !-- Enter the trunking encapsulation as either isl
    3512xl(config-if)#switchport trunk encapsulation isl
    !-- or as dot1q:
    3512xl(config-if)#switchport trunk encapsulation dot1q
    !-- In case of 2940/2950 series switches, none of the above two commands are used,
    !-- 2940/2950 series switches only support 802.1q encapsulation which is configured automatically,
    !-- when trunking is enabled on the interface by using switchport mode trunk command.
    !-- In case of dot1q, you need to make sure that
    !-- the native VLAN matches across the link.
    !-- On 3512XL, by default, the native VLAN is 1.
    !-- Depending on your network needs, you may change
    !-- the native VLAN to be other than VLAN1,
    !-- but it is very important that you change the native VLAN
    !-- on the router accordingly.
    !-- You may change the native VLAN, if needed, by using the following command:
    !-- 3512xl(config-if)#switchport trunk native vlan 

    !-- Allow all VLANs on the trunk.
    3512xl(config-if)#switchport trunk allowed vlan all
    3512xl(config-if)#exit
    !-- The following set of commands will place FastEthernet 0/2
    !-- into VLAN2 and enable portfast on the interface.

    3512xl(config)#int fastEthernet 0/2
    3512xl(config-if)#switchport access vlan 2
    3512xl(config-if)#spanning-tree portfast
    3512xl(config-if)#exit

    !-- FastEthernet 0/3 is already in VLAN1 by default.
    !-- Enable portfast on the interface.
    3512xl(config)#int fastEthernet 0/3
    3512xl(config-if)#spanning-tree portfast
    3512xl(config-if)#^Z

    !-- For details on why to enable portfast,
    !-- refer to:
    !-- Using PortFast and Other Commands to Fix Workstation Startup Connectivity Delays.
    !-- Remember to save the configuration.

    3512xl#write memory
    Building configuration...

    3512xl#
    --------------------------------------------------------------------------------

    3512xl#show running-config
    Building configuration...

    Current configuration:
    !
    version 12.0
    no service pad
    service timestamps debug uptime
    service timestamps log uptime
    no service password-encryption
    !
    hostname 3512xl
    !
    no logging console
    enable password mysecret
    !
    !
    !
    !
    !
    ip subnet-zero
    !
    !
    !
    interface FastEthernet0/1
      switchport mode trunk
    !
    !-- If 802.1Q is configured,
    !-- you will instead see the following output
    !-- under interface FastEthernet0/1:
    !-- interface FastEthernet0/1
    !-- switchport trunk encapsulation dot1q
    !-- switchport mode trunk

    !
    interface FastEthernet0/2
     switchport access vlan 2
     spanning-tree portfast
    !
    interface FastEthernet0/3
     spanning-tree portfast
    !
    interface FastEthernet0/4
    !
    interface FastEthernet0/5
    !
    interface FastEthernet0/6
    !
    interface FastEthernet0/7
    !
    interface FastEthernet0/8
    !
    interface FastEthernet0/9
    !
    interface FastEthernet0/10
    !
    interface FastEthernet0/11
    !
    interface FastEthernet0/12
    !
    interface GigabitEthernet0/1
    !
    interface GigabitEthernet0/2
    !
    interface VLAN1
     ip address 10.10.10.2 255.255.255.0
     no ip directed-broadcast
     no ip route-cache
    !
    ip default-gateway 10.10.10.1
    !
    line con 0
     transport input none
     stopbits 1
    line vty 0 4
     password mysecret
     login
    line vty 5 15
     login
    !
    end

Posted in | 0 Comments »

Linux Kiosk system

by BBTUNA

This is part of an experiment to use Linux as a kiosk system. 'Kiosk System' can mean a couple of things, but here we assume that it's a computer that runs just one application - a web browser - and does not allow the user to do anything else but use that browser. That way, the computer can be left unattended, e.g. in public places (public libraries, ... )

One of the appoaches often taken to accomplish this, is to install Windows, then lock it down and present the user with a limited menu-like user interface - often with specilised software (e.g. WinU). But that feels a bit like wasting resources and money : you'd have to buy a Windows License for a computer that will hardly be used (just a browser ...), and on top of that you pay for additional software to make it run nothing but that one browser. So we looked at it from a different angle : is this something Linux could do, without all the overkill ?


What do we need ?

To run just a web browser we don't need a full-blown desktop : a minimal x-windows system will do : all we need is 1 window in which the browser can run. This approach is also used in this "minimal GUI" setup for a Linux server where we provide a web browser to take advantage of the graphical front-ends to configure the system. Building on that approach, we will set up a base Linux system (install nothing but the operating system - e.g. Debian 3) and add some x-window components so that we can run a web browser (firefox).

Assuming this computer will be unattended, we don't want users to go and play with it, and we definitly don't want users to crack it or try to get escalate their privilegues or install their own software so that the machine becomes a zombie or what not - so we deny them all access to the system. For this, we use 'Bastille'. Bastille is a program that takes you trough the motions of locking down the system. (see Bastille home)

Finally, we want everything to work more or less automaticvally, so we'll take advantage of runlevels and startup scripts.

Installing the software and basic configuration

the base setup

We install nothing but a base system, then add the packages we need / want. The os used here is Debian 3.0, network installation. We add bastille, firefox, and some components from the x-windows system : just enough to create windows and provide a GUI logon for the user. We also add ssh for remote administration by root and vim to edit text files.

 apt-get install x-window-system fvwm vim ssh   

System requirements : any pc capable of running (text mode) linux + xwindows. Hard disk space : ... mb (system + software) + swap + room for browser cache /temporary files. Meaning : any old pc will do.

create a user

We create 1 user (www) with password www. This account will be used to use the PC as a web client.

 useradd -m -s /bin/false -p `mkpasswd www SD` www  

the windows setup

Setting up X-windows means you will have to provide some input (monitor, keyboard, mouse, ...). To modify the configuration : dpkg-reconfigure xserver-xfree86 , or edit the configuration file (/etc/X11/X86config-4).

The configuration of the windows environment is found in the user's home directory (~/.xinitrc), and if that is missing, the system default is used :/usr/X11R6/lib/X11/xinit/xinitrc (re. XFree86 HOWTO). (On Debian) all this xinitrc does is call /etc/X11/Xsession, which in turn refers to files in /etc/X11/Xsession.d and ~/.Xsession. In /etc/X11/Xsession.d we find a script 99xfree86-common_start with an exec $STARTUP statemenent. Assuming that this is where we can put the programs we want to run in X, we replace exec $STARTUP with 'exec firefox'. This way, Firefox will start as soon as the xserver is started, and closing Firefox will stop the xwindows session as well.

To do :
read Debian documentation on how to configure window managers and find out how all these x11 files relate to each other.
find a way to force height and width on Firefox. We want it fullscreen. "firefox -height 600 -width 800" should work ? Workaround : run firefox once, configure preferences and windows - it will use those settings the next time

the runlevels

You may now find that your system now offers a graphical login and starts Firefox rightaway which is what we wanted anyway, except that root prefers a command prompt to set up the system firther. So we change the default runlevel to 3 (in /etc/inittab) and disable the X startup scripts in rc2.d (runlevel 2). Now, the system will boot to runlevel 3 (with GUI login for user www and Firefox started immediately) - root can boot init 2 for a command prompt and no worries.

the bonus

While you have now have a GUI, why not include a screensaver ? 'The Matrix' is a nice one.

the Bastille

Bastille is a program that will walk you through a large number of configuration settings to make your system more secure. Some have to do with networking, e.g. it sets up a firewall which - in the case of a web kiosk - should only allow outgoing http, and accept only replies to outgoing traffic. Another set of settings secures the system as such, by means of 'chroot', modyfing some file system permissions, and tightening the use of SUID. One feature is extremely useful for an unattended PC : setting a (root) password to runlevel 1 ('single user mode', 'root mode', 'recovery mode'; 'maintenance mode'). In single user mode, one could reset the root password and consequently log on as root - clearly a threath for an unattended computer : just pull the plug or hit the power button and you bypass all security, even with ctrl+alt+del disabled and shutdown/reboot only available to the root user.

Another point is the disabling of printers and /or give the ability to manage print jobs to root only. You'll have to figure this out depending on what this PC will be used for and whether the www user needs printing or not. In this locked down Ubunto/Gnome desktop kiosk system are some details about appropriate settings.

example


The web front-end of a major company's application site, running on a cluster of Citrix Metaframe servers
and presented on a "firefox only" linux system.

Things to do ...

Still needs some work :
to do : make sure that firefox is limited (e.g. don't allow browsing the filesystem ?). Establish 'ideal' firefox configuration and set it (preferences, history, cookies, ...). Privacy of consecutive users ? Import a predefined Firefox profile ? Firefox lockdown.

Roll-up : automate this

automate it : put all of the above in a script.

 #!/bin/bash   echo starting KIOSK setup   sleep 3   # reconfigure the base system if needed  # /usr/sbin/base-config    #download and install software  apt-get update  apt-get install aptitude vim ssh  apt-get install x-window-system twm  aptitude install --with-recommends bastille  aptitude install --with-recommends mozilla-firefox  #apt-get clean   #reconfigure the x-server in case you missed something (keyboard layout, ...)  #dpkg-reconfigure xserver-xfree86   #create a user:password www:www  useradd -m -s /bin/false -p `mkpasswd www SD` www  tail -n1 /etc/passwd     #just checking  tail -n1 /etc/shadow  sleep 2       #manage runlevels and xwindows environment  #+ quick&dirty : replace 99xfree86-common_start completely  echo exec firefox > /etc/X11/Xsession.d/99xfree86-common_start   #+ no GUI in runlevel 2  mv /etc/rc2.d/S99xdm /etc/rc2.d/s99xdm  mv /etc/rc2.d/S20xfs /etc/rc2.d/s20xfs  mv /etc/rc2.d/S20xprint /etc/rc2.d/s20xprint`  ln -s /etc/init.d/xdm /etc/rc2.d/K01xdm   #run bastille to lock down the system  #+ interactive run, save a copy of config in /root for future use in unattended mode  echo starting bastille in interactive mode   echo this will take some time and you'll have to answer a lot of questions  sleep 4  bastille -c   cp /etc/Bastille/config /root/bastille_config || echo failed to safe copy of bastille config file  cp /var/log/Bastille/TODO /root/bastille_todo || echo failed to safe copy of bastille to do list  less /var/log/Bastille/TODO   #+ alternative : run bastille preconfigured ; requires conf file from previous interactive setup   #need to copy config file to /etc/Bastille first - from where if this is a virgin system ? USB stick ? CD ?   #bastille -b   # changing default runlevel  cp /etc/inittab /etc/inittab.rmwebterm  sed -i -e 's/id:2:initdefault:/id:3:initdefault:/'  /etc/inittab   exit 0  

Check Out

Posted in | 0 Comments »

Trunking ports on switches

by BBTUNA
DEFINITION - A trunk is a line or link designed to handle many signals simultaneously, and that connects major switching centers or nodes in a communications system. The transmitted data can be voice (as in the conventional telephone system) data, computer programs, images, video or control signals.

Trunks are used to interconnect switches to form networks, and to interconnect local area networks (LANs) to form wide area networks (WANs) or virtual LANs (VLANs). A trunk often consists of multiple wires, cables, or fiber optic strands to maximize the available bandwidth and the number of channels that can be accommodated. A trunk can also be abroadband wireless link. The use and management of trunks in a communications system is known as trunking. It minimizes the number of physical signal paths, and thus the total amount of cable hardware, required to serve a given number of subscribers in a network.

In Cisco networks, trunking is a special function that can be assigned to aport, making that port capable of carrying traffic for any or all of the VLANs accessible by a particular switch. Such a port is called a trunk port, in contrast to an access port, which carries traffic only to and from the specific VLAN assigned to it. A trunk port marks frames with special identifying tags (either ISL tags or 802.1Q tags) as they pass between switches, so each frame can be routed to its intended VLAN. An access port does not provide such tags, because the VLAN for it is pre-assigned, and identifying markers are therefore unnecessary.

Posted in | 0 Comments »

How to disable Last Logon Name in Windows 2000,XP&2003

by BBTUNA
One of the least looked at securityfeature in Windows is the last login name. When you login on your Windows PC (either standalone or a Domain attached PC), it can display the last logged in user. This can be a security issue especially in adomain attached environment.

This can be disabled from the LocalSecurity Policy snap-in or from Windows Registry.

To disable displaying the Las Logon ID in Windows from the Local Security Policy:

1. Click Start – Control Panel – Administrative Tools.

2. Open the Local Security Policy object.

3. Expand Local Policies – Security in the left pane.

4. Double-click the “Interactive Logon: Do not display last user name”

5. Select Enabled, Click Apply & OK

6. Close the Local Security Policy Editor

Disable Last Logon Display from Local Security policy

Restart the computer and you should no more see the Last logged in username.

To do this from the Windows Registry,

1. Click Start – Run, type “regedit”

2. Navigate to

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]

HKEY_LOCAL_MACHINE
\Software
\Microsoft
\Windows
\CurrentVersion
\Policies
\System

3. In the right-pane, look for the key “DontDisplayLastUserName” and set it to “1″

4. Close Windows Registry Editor and restart Windows.

Last Logged in user name would have now disappeared.

Disable Last Logon Display from Windows Registry

Posted in | 0 Comments »

Metasploit 3.2 VBA Support for generating payloads

by BBTUNA
Well Metasploit 3.2 is looking every time better and better, one feature I missed was that now you can encode your payloads in to VBA (visual basic for applications) code and inbed the code into a Office Document for clientside attacks during a pentest.

Usage: ./msfpayload [var=val]

you can even create a Javascript payload for generating malicious webpages or HTML documents that can be send to targets.

an example would be:
/msf3/msfpayload windows/shell_bind_tcp LPORT=5555 V > evilmacro.vba
then we take the content of the file generated and paste it in Tools >Macros >Visual Basic Editor in Word or Excel and send our file to our target machine, the default policy of the latest version of Office is to disable macros but thru human weakness and a bit of social engenieering the target may enable or already enabled himself Macros and set the security to low. Once open our payload will execute.

But what if we whant to use something like a Core Impact Agent or any other tool, well whe just head over to the tools folder and inside we will find exe2vba.rb

Usage: ./exe2vba.rb [exe] [vba]
Posted in | 0 Comments »

Installing NaviAgent on ESX 3.x and 3.5x

by BBTUNA

Purpose

By installing the NaviAgent on the ESX host Console, it automatically registers and logs in the hosts initiators records on the Clariion so there is no need for manual registration. You do, however, need to add the host to the corresponding Storage Group.
This article provides instructions for installing the NaviAgents on an ESX host.

Resolution

To install the NaviAgents on an ESX host:
  1. Log in to the ESX host as root
  2. Run the following command to determine if there is any existing Host Agent software installed:

    rpm -qa | grep navi

  3. If there is an older version of the software installed, you must remove it. Run the following command to remove the older version:

    rpm -e naviagent- version

    Where version is the version of the older software.

  4. Mount the CD-ROM and cd to the installation directory.
  5. Run the following command to install the Host Agent and CLI packages:

    rpm -ivh naviagentcli.rpm

  6. Run the following commands to start and stop the service:

    /etc/init.d/naviagent start

    /etc/init.d/naviagent stop
Posted in | 0 Comments »

About Me

Blog Archive