Monthly Archives: September 2007

Finding Hosts on Layer 2

September 27, 2007
By Aaron Conaway

Most firewalls should block ICMP requests to them, so how do you know that your router or server has layer-2 connectivity to one? It’s pretty elementary, actually, but I’ve found that not a lot of people know this trick. If you ping the firewall, it will receive the ICMP packet and drop it per...

Read more »

Filtering Outbound Traffic

September 24, 2007
By Aaron Conaway

I’ve seen a thousand firewalls in my time, and nearly all of them are poorly configured. The biggest culprit? No outbound filtering. I guess a lot of people think that firewalls are there to protect the network from the Internet, but that’s only part of it. The firewall is to protect every segment from...

Read more »

HSRP Interface Tracking

September 23, 2007
By Aaron Conaway

Remember the article on router-on-a-stick? And the one on HSRP? Let’s add to that example network, shall we? Let’s make those routers into edge routers so they connect your internal network to the Internet with some size circuit. Let’s just say they each terminate DS3s to different providers. Here’s our network now (I’m experimenting...

Read more »

SNMP v3 is Easy!

September 16, 2007
By Aaron Conaway

I finally got around to looking into SNMP v3 and was shocked at how easy it actually is. When I first looked up info on it so many moons ago, I saw table after tables of views and privilege levels and thought I would have to put in a billion hours getting it customized....

Read more »

Ideas That Seems Good At the Time

September 11, 2007
By Aaron Conaway

When I started in IT, I tried to get my gear as standardized as possible to impress everyone. I worked at it and worked at it until I realized that there were a handful of things that sound good but just won’t work. If you’re just getting started in the field, you may not...

Read more »

Setting Up SSH on IOS Devices

September 4, 2007
By Aaron Conaway

By default, most Cisco IOS devices come configured to be accessed via telnet. This is probably fine for your house, but I really cringe when I run across corporate networks that use telnet to access the devices. Telnet is old and out-dated and can be very dangerous. It’s in plain-text, which means that anyone...

Read more »

Calendar

September 2007
S M T W T F S
« Aug   Oct »
 1
2345678
9101112131415
16171819202122
23242526272829
30  

Switch to our mobile site