<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Receive/Transmit &#187; Networks</title>
	<atom:link href="http://www.rxtx.co.uk/category/networks/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rxtx.co.uk</link>
	<description></description>
	<lastBuildDate>Sun, 10 Apr 2011 11:05:42 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Getting Started with Check Point &#8211; SmartCenter Server</title>
		<link>http://www.rxtx.co.uk/2011/01/17/getting-started-with-check-point-smartcenter-server/</link>
		<comments>http://www.rxtx.co.uk/2011/01/17/getting-started-with-check-point-smartcenter-server/#comments</comments>
		<pubDate>Mon, 17 Jan 2011 21:46:38 +0000</pubDate>
		<dc:creator>rxtx</dc:creator>
				<category><![CDATA[Networks]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[checkpoint]]></category>
		<category><![CDATA[gettingstartedwithcheckpoint]]></category>

		<guid isPermaLink="false">http://www.rxtx.co.uk/?p=266</guid>
		<description><![CDATA[The SmartCenter server is a key part of the Check Point infrastructure and without one you can&#8217;t do very much at all with your firewalls, so it should be one of the first things you set up. It can either be installed on the same hardware as one of your firewalls, or as a dedicated [...]]]></description>
			<content:encoded><![CDATA[<p>The SmartCenter server is a key part of the Check Point infrastructure and without one you can&#8217;t do very much at all with your firewalls, so it should be one of the first things you set up. It can either be installed on the same hardware as one of your firewalls, or as a dedicated management machine. In this case I&#8217;m going to set it up on a dedicated Windows 2003 server.</p>
<p>The install is fairly straightforward, just mount/insert the disc and run the setup. I&#8217;ll run through a sample of an R65 SmartCenter install as some of the screens need a little explanation.</p>
<p>Skip past the first two screens until you hit this page:</p>
<p><a href="http://www.rxtx.co.uk/wp-content/uploads/2011/01/screen1.png"><img class="alignnone size-full wp-image-267" title="screen1" src="http://www.rxtx.co.uk/wp-content/uploads/2011/01/screen1.png" alt="" width="646" height="481" /></a></p>
<p>If you are installing the full firewall product, what you choose here will depend on your licensing. As we are just installing the SmartCenter it doesn&#8217;t matter for us. On the next page you can import a config if you have one, or choose a fresh install. After that you come to this page:</p>
<p><a href="http://www.rxtx.co.uk/wp-content/uploads/2011/01/screen2.png"><img class="alignnone size-full wp-image-268" title="screen2" src="http://www.rxtx.co.uk/wp-content/uploads/2011/01/screen2.png" alt="" width="651" height="487" /></a></p>
<p>This is where you choose the products you want to install. Here I&#8217;ve chosen the SmartCenter itself, plus the SmartConsole management tools. If you wanted to install the firewall software, you would choose the top box. On the next page you can choose if this will be a primary, secondary, or log server. You can install two SmartCenter servers in an HA cluster using the primary/secondary options. At this point the installer will run and complete. There are a few more steps before we can use it though.</p>
<p>Firstly it will ask you to install any licenses that you might have. The products come with a 15 day evaluation license if you are just playing around. If you have any license files you can either upload the files directly, or type in the keys manually.</p>
<p><a href="http://www.rxtx.co.uk/wp-content/uploads/2011/01/screen4.png"><img class="alignnone size-full wp-image-270" title="screen4" src="http://www.rxtx.co.uk/wp-content/uploads/2011/01/screen4.png" alt="" width="445" height="500" /></a></p>
<p>The next step is to create an admin user, which is followed by defining IP ranges which are allowed to access the management software on the server. The default is that any user can manage the server. Although I&#8217;ve selected to install the management tools locally on the server, you can also install them separately on another machine, in a similar way to a Microsoft MMC or the Cisco ASDM. Finally you&#8217;ll be given a signature key, which is used to verify the identity of the server once we start linking it up to remote firewalls.</p>
<p>At this point your SmartCenter server is up and running, its a fairly painless install. You can have a play with the management tools (they have a nice demo mode with predefined topologies), but until we link up our first firewall the server alone is pretty useless.</p>
<p><img src="file:///C:/Users/AG/AppData/Local/Temp/moz-screenshot.png" alt="" /></p>
]]></content:encoded>
			<wfw:commentRss>http://www.rxtx.co.uk/2011/01/17/getting-started-with-check-point-smartcenter-server/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Getting Started With Check Point &#8211; Product Overview</title>
		<link>http://www.rxtx.co.uk/2011/01/06/getting-started-with-check-point-product-overview/</link>
		<comments>http://www.rxtx.co.uk/2011/01/06/getting-started-with-check-point-product-overview/#comments</comments>
		<pubDate>Thu, 06 Jan 2011 20:31:54 +0000</pubDate>
		<dc:creator>rxtx</dc:creator>
				<category><![CDATA[Networks]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[checkpoint]]></category>
		<category><![CDATA[gettingstartedwithcheckpoint]]></category>

		<guid isPermaLink="false">http://www.rxtx.co.uk/?p=259</guid>
		<description><![CDATA[As we all know the only thing constant in IT is change and as a result of that I&#8217;ve been using Check Point firewalls a lot lately, a departure from my usual ASA and ISA firewalls. I&#8217;m going to do a series of posts documenting what I find, as I haven&#8217;t seen a good resource [...]]]></description>
			<content:encoded><![CDATA[<p>As we all know the only thing constant in IT is change and as a result of that I&#8217;ve been using <a href="http://www.checkpoint.com/">Check Point</a> firewalls a lot lately, a departure from my usual ASA and ISA firewalls. I&#8217;m going to do a series of posts documenting what I find, as I haven&#8217;t seen a good resource which wasn&#8217;t either out of date or simply didn&#8217;t cover the basics.</p>
<p>With any new product there is always a little confusion, but with Check Point this seems to have been taken to a whole other level and I&#8217;ve had a great deal of difficulty working out what it is that they sell, what it actually does and how it all fits together. Check Point appear to have gone through a great deal re-branding, and with a lot of older versions still supported everything now has more than one name depending on which version of the software you are talking about. I&#8217;ll try and simplify it here as I understand things. The main thing to remember with Check Point is that, to a much greater extent than with other products, you are looking at two very different and separate things with regards to the <strong>hardware</strong> and the <strong>software</strong>.</p>
<h2>Hardware</h2>
<p>The hardware you choose for your firewalls will determine how fast and big it can go, as you might expect. It also determines which software features you can use on that particular bit of tin (which I&#8217;ll talk about shortly). Check Point give you a large number of options for your hardware depending on your needs.</p>
<ul>
<li><a href="http://www.checkpoint.com/products/ip-appliances/index.html">IP appliances</a> &#8211; the appliance formerly known as Nokia. These are the mid to high end firewalls and range from 1Gb to 30Gb of throughput (with the right model and expansion cards). For your money you get a piece of tin with various ports and space for extra modules. This is very much a pure networking appliance with support for all the basics such as VPN, plus support for advanced features like IPS, routing protocols, clustering, QoS and VoIP.</li>
<li><a href="http://www.checkpoint.com/products/power-1/index.html">Power-1 appliances</a> &#8211; these are more datacenter oriented, and run from 9Gb up to 30Gb throughput and are again a piece of tin. They support a few more edge defence features than the IP appliances such as URL filtering, antivirus, antispam, antimalware. Apart from this though they look very similar performance-wise to the high-end IP appliances.</li>
<li><a href="http://www.checkpoint.com/products/utm-1-appliances/index.html">UTM-1 appliances</a> &#8211; I see these as the low end version of the Power-1, tin again. Performance is from 1.5Gb to 4.5Gb, but you can get all the features of the Power-1 plus a few extra ones like built in management and monitoring.</li>
<li><a href="http://www.checkpoint.com/products/softwareblades/architecture/index.html">&#8220;Open server&#8221;</a> &#8211; also known as SPLAT (Secure PLATform). This is kind of like Bring Your own Box, you install the Check Point into a standard bit of server hardware. The license determines things like how many cores your server can have and what features you are allowed, but after that the performance is down to your hardware. SPLAT itself is a modified version of Linux into which various Check Point software modules can be installed.</li>
</ul>
<p>There are a few other variations including a virtualised version, but these are the main ones. For my testing I&#8217;ll be using a SPLAT system running in VMware.</p>
<h2>Software</h2>
<p>Check Point has gone through a lot of different versions of their software. The good news is that every device runs a version of the same software, and is managed through the same tools. Configuring rules on a SPLAT is exactly the same as configuring rules on one of the appliances. The bad news is that due to the number of iterations and the different licensing for them, you can be left scratching your head.</p>
<p>The first bit of confusion is that way back in 1994 when Check Point made their first firewall they decided to name it Firewall-1, and quickly followed with a VPN product called VPN-1. If you fast forward to today you&#8217;ll still find references to Firewall-1, VPN-1, and a whole raft of other things called xxx-1. The 1 has nothing to do with the version of the software as you might imagine, its simply the name of the product. It makes more sense if you think of these as identifiers of<strong> feature sets</strong>.</p>
<p>The way you differentiate between older and newer software is via the <strong>version number</strong> of the software. <a href="http://en.wikipedia.org/wiki/Check_Point_VPN-1#Version_History">Wikipedia</a> has the full details, but the numbering is roughly:</p>
<table cellpadding="2" width="300">
<tbody>
<tr>
<td>Version</td>
<td>Release Date</td>
</tr>
<tr>
<td>1.0</td>
<td>April 1994</td>
</tr>
<tr>
<td>2.0</td>
<td>Sep 1995</td>
</tr>
<tr>
<td>3.0</td>
<td>Oct 1996</td>
</tr>
<tr>
<td>4.0</td>
<td>1998</td>
</tr>
<tr>
<td>4.1</td>
<td>2000</td>
</tr>
<tr>
<td>NG</td>
<td>Jun 2001</td>
</tr>
<tr>
<td>NG AI R54</td>
<td>Jun 2003</td>
</tr>
<tr>
<td>NG AI R55</td>
<td>Nov 2003</td>
</tr>
<tr>
<td>NG AI R57</td>
<td>April 2005</td>
</tr>
<tr>
<td>NGX R60</td>
<td>Aug 2005</td>
</tr>
<tr>
<td>NGX R61</td>
<td>Mar 2006</td>
</tr>
<tr>
<td>NGX R62</td>
<td>Nov 2006</td>
</tr>
<tr>
<td>NGX R65</td>
<td>Mar 2007</td>
</tr>
<tr>
<td>R70</td>
<td>Feb 2009</td>
</tr>
<tr>
<td>R71</td>
<td>April 2010</td>
</tr>
<tr>
<td>R75</td>
<td>December 2010</td>
</tr>
</tbody>
</table>
<p>Anything prior to NGX R65 is end of life, NGX R65 itself is nearing end of life, and R75 has just been released. Lots of people are currently in the process of upgrading from NGX R65, and if you have existing licenses Check Point are currently running an <a href="http://www.checkpoint.com/products/promo/software-blades/upgrade/index.html">upgrade promotion</a>.</p>
<p>If you are looking at NGX products and earlier, you combine a feature set and a version number to label your software. Eg, a VPN-1 UTM NGX R65 has a defined set of features from the VPN-1 UTM label, and is the NGX R65 software version of those features.</p>
<p>With R71 and later Check Point have adopted a <a href="http://www.checkpoint.com/products/softwareblades/firewall.html">software blade architecture</a>. You still have a software version, but the features which you run inside of that are a lot more mix and match and are deployed as virtual blades (providing your <strong>hardware</strong> supports it).</p>
<h2>In Conclusion</h2>
<p>With all the different product names and the mix of people on different versions currently, Check Point is very confusing to the newcomer. Over the next few posts I&#8217;m going to go through some basic installation and configuration, starting with an NGX R65 set up. Depending on how things go I may throw in some more advanced stuff like the failover clustering and and upgrade to R71.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rxtx.co.uk/2011/01/06/getting-started-with-check-point-product-overview/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Useful IOS tricks (part 3) &#8211; the &#8216;do&#8217; command</title>
		<link>http://www.rxtx.co.uk/2011/01/03/useful-ios-tricks-part-3-the-do-command/</link>
		<comments>http://www.rxtx.co.uk/2011/01/03/useful-ios-tricks-part-3-the-do-command/#comments</comments>
		<pubDate>Mon, 03 Jan 2011 14:22:05 +0000</pubDate>
		<dc:creator>rxtx</dc:creator>
				<category><![CDATA[Networks]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[iostricks]]></category>

		<guid isPermaLink="false">http://www.rxtx.co.uk/?p=255</guid>
		<description><![CDATA[I have a very short but very useful command for you today. You&#8217;ll often find yourself working within the IOS config mode, and you might forget little things such as &#8216;what is the interface number I need&#8217;, or &#8216;what is the current IP assigned to this interface&#8217;. Following this you probably go through a series [...]]]></description>
			<content:encoded><![CDATA[<p>I have a very short but very useful command for you today. You&#8217;ll often find yourself working within the IOS config mode, and you might forget little things such as &#8216;what is the interface number I need&#8217;, or &#8216;what is the current IP assigned to this interface&#8217;. Following this you probably go through a series of commands like the ones below</p>
<pre>Router#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
Router(config)#int fa 0/^Z  &lt;---Arrgh forgot which interface it was, Ctrl+Z out of config mode
% Incomplete command.

Router#sh ip int brief
Interface                  IP-Address      OK? Method Status                Prot
ocol
FastEthernet0/0            10.10.10.1  YES NVRAM  up                    up

FastEthernet0/1            192.168.0.1   YES NVRAM  up                    up

Router#conf t  &lt;---OK found it, back into config mode
Enter configuration commands, one per line.  End with CNTL/Z.
Router(config)#int fa 0/0
etc
</pre>
<p>This gets annoying pretty fast, but luckily you can execute exec commands from within config mode by preceding them with &#8216;do&#8217;! This is a lot nicer:</p>
<pre>
<pre>Router#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
Router(config)#int fa 0/  &lt;---Arrgh forgot which interface it was, lets try 'do'
% Incomplete command.

Router(config)#do sh ip int brief
Interface                  IP-Address      OK? Method Status                Prot
ocol
FastEthernet0/0            10.10.10.1  YES NVRAM  up                    up

FastEthernet0/1            192.168.0.1   YES NVRAM  up                    up

Router(config)#int fa 0/0
</pre>
</pre>
<p>Much easier right? There are of course a few caveats, the main one being that you can&#8217;t <a href="http://www.rxtx.co.uk/2010/09/16/useful-ios-tricks-part-1/">use the &#8216;?&#8217; symbol</a> to remind you of the commands but its still a great little time saver.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rxtx.co.uk/2011/01/03/useful-ios-tricks-part-3-the-do-command/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>WEP cracking with BackTrack 4 R1</title>
		<link>http://www.rxtx.co.uk/2010/11/03/wep-cracking-with-backtrack-4-r1/</link>
		<comments>http://www.rxtx.co.uk/2010/11/03/wep-cracking-with-backtrack-4-r1/#comments</comments>
		<pubDate>Wed, 03 Nov 2010 15:25:17 +0000</pubDate>
		<dc:creator>rxtx</dc:creator>
				<category><![CDATA[Networks]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[WEP]]></category>
		<category><![CDATA[wireless]]></category>

		<guid isPermaLink="false">http://www.rxtx.co.uk/?p=235</guid>
		<description><![CDATA[Its a well known fact that WEP is fundamentally broken, and its also a well known fact that it can be cracked very easily. Unfortunately it doesn&#8217;t seem to be well known enough, as I frequently come across friends who only use WEP encryption on their wireless. The best way to convince them to change [...]]]></description>
			<content:encoded><![CDATA[<p>Its a well known fact that WEP is fundamentally broken, and its also a well known fact that it can be cracked very easily. Unfortunately it doesn&#8217;t seem to be well known enough, as I frequently come across friends who only use WEP encryption on their wireless. The best way to convince them to change it is to demonstrate how easy it is to break, which is what this post is about. This post is for my benefit as much as anyone else&#8217;s. I realise its been done to death and there&#8217;s hundreds of tutorials already out there, but whenever I need to do this I can never remember the commands and the stuff online never seems to be quite correct or is slightly out of date regarding command switches etc.</p>
<p>I&#8217;ll be using a standard laptop running <a href="http://www.backtrack-linux.org/">BackTrack</a> 4 R1, with an Alfa USB wireless adaptor (AWUS036H). Using a well-tested adaptor such as this will solve a lot of headaches as it is literally plug and play.</p>
<p>I&#8217;ll split this into four steps: finding the target; performing the attack; cracking the key; and connecting to the network. For the purposes of this I&#8217;ve set up an access point running 64 bit WEP so the capturing goes a little faster. I&#8217;m going to skim over a lot of the theory since this is available elsewhere in much better detail than I&#8217;ll be able to go into.</p>
<p><span id="more-235"></span></p>
<h2>Finding a target</h2>
<p>This bit is pretty easy. Boot your BackTrack live cd, type &#8216;startx&#8217; to get into the GUI and then open a shell window. The tool we&#8217;ll use to scope out available APs is called Kismet. Before we run this we need to identify our wireless interface but running iwconfig. In my case the interface is called &#8216;wlan0&#8242;.</p>
<p>Then we start Kismet. It has a server and client component, which you can run separately. If you run just the client and the server isn&#8217;t running, it will prompt you to start it anyway. I&#8217;ll use the option of running the server separately:</p>
<pre>kismet_server
</pre>
<p>Then in a new shell run the client:</p>
<pre>kismet
</pre>
<p>The client will warn you that you are running as root, and then ask you to choose a capture interface since none is defined. This is the interface you found from iwconfig, type in its name exactly as it was written. If you get an error you might be using the wrong interface, so keep trying wireless adaptors until you find the one that works. Once Kismet is running we can see a list of the available wireless neworks plus a ton of information. There is a lot of stuff to explore, but the info we are concerned with is the bssid, the essid and the channel it is on. Below we can see my test network as seen by Kismet. Feel free to try the other menus and options to get a handle for the tool.</p>
<p><a href="http://www.rxtx.co.uk/wp-content/uploads/2010/11/kismet.png"><img class="alignnone size-full wp-image-245" title="kismet" src="http://www.rxtx.co.uk/wp-content/uploads/2010/11/kismet.png" alt="" width="607" height="365" /></a></p>
<p>From this then we can see the info we need to make a note of:</p>
<ul>
<li>essid: test</li>
<li>bssid: 00:14:6C:6E:B4:7C</li>
<li>channel: 11</li>
</ul>
<h2>Performing the attack</h2>
<p>To crack WEP we need to capture a special kind of packet, known as an Initialisation Vector. Once we have enough of these we can attempt to crack the key. If you just set off something to monitor you&#8217;ll find that these naturally occur, but to get the amount required for cracking we can do a few tricks to speed up the process. We are going to send packets to the AP which will cause it to send out IVs at a much faster rate than normal. I&#8217;ll also show you how to fake an association with the AP from the laptop &#8211; usually you can use already connected clients to perform the attack but if there aren&#8217;t any this is a handy trick.</p>
<p>If at any point during this part things don&#8217;t work or you get errors, I&#8217;ve found the best way is to just reset the wireless adapter by disconnecting/reconnecting it.</p>
<p>First close Kismet so it doesn&#8217;t interfere, and run the following command in a shell window to start the IV capture:</p>
<pre>airodump-ng --channel 11 --bssid 00:14:6C:6E:B4:7C --write /testcap --ivs wlan0
</pre>
<p><strong>&#8211;channel 11</strong> means capture on channel 11<br />
<strong>&#8211;bssid 00:14:6C:6E:B4:7C</strong> means capture traffic from the given bssid<br />
-<strong>-write /testcap</strong> is where we want the output saving<br />
<strong>&#8211;ivs</strong> means only capture packets containing IVs<br />
<strong>wlan0</strong> is the interface to capture on</p>
<p>You&#8217;ll get a screen with some stats, but assuming there are no clients connected it won&#8217;t show much traffic yet. Now we are going to set off an association attack against the AP in another shell window. This will cause our laptop to associate with the AP so we can use it to generate IVs:</p>
<pre>aireplay-ng -1 0 -e test -a 00:14:6C:6E:B4:7C -h 00:C0:CA:11:22:33 wlan0
</pre>
<p>-<strong>-1 0</strong> use attack 1 (fake auth) with 0 delay, or only associate once<br />
<strong>-e test</strong> is the target essid of the fake auth<br />
<strong>-a 00:14:6C:BE:B4:7C </strong>is the target bssid<br />
<strong>-h 00:C0:CA:11:22:33</strong> is the mac address of the wireless card (got via ifconfig, need to run ifup wlan0 if it doesn&#8217;t show up)<br />
<strong>wlan0 </strong>is once again the source interface</p>
<p>So now we are capturing traffic and have a client to use for the attack. The next command is:</p>
<pre>aireplay-ng -3 -b 00:14:6C:6E:B4:7C -h 00:C0:CA:11:22:33 wlan0
</pre>
<p>-<strong>-3</strong> use attack 3 (ARP replay)<br />
<strong></strong><strong>-b 00:14:6C:BE:B4:7C </strong>is the target bssid<br />
<strong>-h 00:C0:CA:11:22:33</strong> is the mac address of the wireless card<br />
<strong>wlan0 </strong>is once again the source interface</p>
<p><a href="http://www.rxtx.co.uk/wp-content/uploads/2010/11/capture.png"><img class="alignnone size-full wp-image-244" title="capture" src="http://www.rxtx.co.uk/wp-content/uploads/2010/11/capture.png" alt="" width="614" height="461" /></a></p>
<p>Eventually you should see some ARP replies (it may take a while to start). Now if you look in the airodump window, we are watching for the column labelled <strong>#Data</strong>. This is the number of packets we&#8217;ve captured, which all happen to be IVs due to our airodump filters. The amount you need to perform a crack may vary. I find the best approach is to try to crack every 50,000, which leads us onto the next part.</p>
<h2>Cracking the key</h2>
<p>Really easy this bit, just run the following command:</p>
<pre>aircrack-ng -s /testcap-01.ivs
</pre>
<p>If it takes more that a couple of seconds, wait until you have more IVs. Now we have all the info we need to connect to the network</p>
<p><a href="http://www.rxtx.co.uk/wp-content/uploads/2010/11/crack.png"><img class="alignnone size-full wp-image-240" title="crack" src="http://www.rxtx.co.uk/wp-content/uploads/2010/11/crack.png" alt="" width="596" height="451" /></a></p>
<h2>Connecting to the network</h2>
<p>Nothing surprising here, just using the info we already have to get on the network.</p>
<pre>ifdown wlan0
iwconfig wlan0 mode managed
iwconfig wlan0 channel 11
iwconfig wlan0 essid test
iwconfig wlan0 key 1b9dda483d
ifup wlan0
</pre>
<p>At this point you should get an IP via DHCP, if not try running &#8220;<strong>dhcpd wlan0</strong>&#8220;. If you do this a few times you can get pretty fast at it, and 5-10 minutes will be all you&#8217;ll need to perform the full attack.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rxtx.co.uk/2010/11/03/wep-cracking-with-backtrack-4-r1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Stratix 8000 IOS recovery (or how dd saved the day)</title>
		<link>http://www.rxtx.co.uk/2010/10/15/stratix-8000-ios-recovery-or-how-dd-saved-the-day/</link>
		<comments>http://www.rxtx.co.uk/2010/10/15/stratix-8000-ios-recovery-or-how-dd-saved-the-day/#comments</comments>
		<pubDate>Fri, 15 Oct 2010 08:48:36 +0000</pubDate>
		<dc:creator>rxtx</dc:creator>
				<category><![CDATA[Networks]]></category>
		<category><![CDATA[Sysadmin]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[recovery]]></category>
		<category><![CDATA[stratix]]></category>

		<guid isPermaLink="false">http://www.rxtx.co.uk/?p=228</guid>
		<description><![CDATA[I&#8217;ve been playing with some Stratix 8000 switches lately &#8211; if you&#8217;ve never come across them they are built for heavy duty environments and are a result of a collaboration between Rockwell and Cisco. They run a Catalyst OS so if you&#8217;ve used a Cisco switch you&#8217;ll be in familiar territory. During my work with [...]]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve been playing with some Stratix 8000 switches lately &#8211; if you&#8217;ve never come across them they are built for heavy duty environments and are a result of a collaboration between Rockwell and Cisco. They run a Catalyst OS so if you&#8217;ve used a Cisco switch you&#8217;ll be in familiar territory. During my work with them I somehow ended up with a corrupt IOS following an upgrade and the switch would no longer boot, giving the console error message below</p>
<pre>...
mifs[7]: 684 files, 26 directories
mifs[7]: Total bytes     :   64094208
mifs[7]: Bytes used      :   11614208
mifs[7]: Bytes available :   52480000
mifs[7]: mifs fsck took 60 seconds.
...done Initializing Flash.
done.
Loading "flash:/ies-lanbase-mz.122-50.SE2/ies-lanbase-mz.122-50.SE2.bin"...flash:/ies-lan
base-mz.122-50.SE2/ies-lanbase-mz.122-50.SE2.bin: magic number mismatch: bad mzip file

Error loading "flash:/ies-lanbase-mz.122-50.SE2/ies-lanbase-mz.122-50.SE2.bin"

Interrupt within 5 seconds to abort boot process.
Boot process failed...

The system is unable to boot automatically.  The BOOT
environment variable needs to be set to a bootable
image.
</pre>
<p>No problem I thought, I&#8217;ll just use Rommon and suck down a clean image from a TFTP server. How wrong I was! These switches don&#8217;t have Rommon, instead they have their own boot OS which bizarrely doesn&#8217;t seem to support any kind of networking whatsoever. It can format the filesystem and do basic file operations, but thats it as far as I can tell. You quickly find yourself stuck with no way to upload an image, and the scant documentation unhelpfully suggests that you reset your switch to factory defaults. If you follow this advice you now have a switch with no config and still a corrupt IOS. There doesn&#8217;t appear to be any documentation at all about the strange little OS you find yourself stuck in, so its time to experiment.</p>
<p>Plugging the flash card into my Windows machine showed that it wasn&#8217;t formatted in a way that Windows could read it, so you can&#8217;t copy an image that way. Formatting it as FAT resulted in a strange situation where both Windows and the switch could write to the flash card, but neither could see the others files. Unfortunately I didn&#8217;t have easy access to a Linux machine to see if it was readable on there, I needed another way to get the right data onto the card. I did have other working Stratixes, so I had the idea of cloning a working flash card. You can&#8217;t do this natively in Windows so I had to find a <a href="http://www.chrysocome.net/dd">Windows version</a> of the well known Linux tool, dd.</p>
<p>dd is a very low level tool that copies data at a block level. It doesn&#8217;t see files or folders or even disk formats, it just sees the raw bits. The plan was to make an image of a working flash card, and then dump that onto the failed one. In theory you should end up with a perfect clone, and this way Windows doesn&#8217;t need to be able to read the disk format. I used the tool as follows, first listing the available drives, second making an image of a good flash card and finally writing that image onto the corrupt one:</p>
<pre>
D:\Programs\dd&gt;dd --list
rawwrite dd for windows version 0.6beta3.
Written by John Newbigin &lt;jn@it.swin.edu.au&gt;
This program is covered by terms of the GPL Version 2.

Win32 Available Volume Information

[snip]

\\.\Volume{43371b24-d6a0-11df-b040-005056c00008}\
 link to \\?\Device\HarddiskVolume10
 removeable media
 Mounted on \\.\l:

[snip]

D:\Programs\dd&gt;dd if=\\.\l: of=stratix.img
rawwrite dd for windows version 0.6beta3.
Written by John Newbigin &lt;jn@it.swin.edu.au&gt;
This program is covered by terms of the GPL Version 2.

125440+0 records in
125440+0 records out

D:\Programs\dd&gt;dd if=stratix.img of=\\.\l:
rawwrite dd for windows version 0.6beta3.
Written by John Newbigin &lt;jn@it.swin.edu.au&gt;
This program is covered by terms of the GPL Version 2.

125440+0 records in
125440+0 records out

D:\Programs\dd&gt;
</pre>
<p>Happily it worked flawlessly, the cloned flash card contained an exact copy of the working IOS and I was able to get my switch working again. I&#8217;d love to know the manufacturer&#8217;s recommended restore method, but as is often the case the documentation is lacking.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rxtx.co.uk/2010/10/15/stratix-8000-ios-recovery-or-how-dd-saved-the-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Useful IOS tricks (part 2) &#8211; access list editing</title>
		<link>http://www.rxtx.co.uk/2010/10/05/useful-ios-tricks-part-2-access-list-editing/</link>
		<comments>http://www.rxtx.co.uk/2010/10/05/useful-ios-tricks-part-2-access-list-editing/#comments</comments>
		<pubDate>Tue, 05 Oct 2010 21:46:17 +0000</pubDate>
		<dc:creator>rxtx</dc:creator>
				<category><![CDATA[Networks]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[iostricks]]></category>

		<guid isPermaLink="false">http://www.rxtx.co.uk/?p=222</guid>
		<description><![CDATA[This time we are talking about those pesky things that all the server guys blame when their apps don&#8217;t work &#8211; access lists! Until you know the tricks I&#8217;m about to show you, you&#8217;ve probably had a feeling of dread when you&#8217;ve been asked to add a rule at the end of the 200 entry [...]]]></description>
			<content:encoded><![CDATA[<p>This time we are talking about those pesky things that all the server guys blame when their apps don&#8217;t work &#8211; access lists! Until you know the tricks I&#8217;m about to show you, you&#8217;ve probably had a feeling of dread when you&#8217;ve been asked to add a rule at the end of the 200 entry ACL (but before the deny ip any any of course). We&#8217;ll use this simple access list to demonstrate</p>
<pre>Router#sh access-lists 100
Extended IP access list 100
 10 permit tcp any host 192.168.0.10 eq www
 20 permit tcp any host 192.168.0.10 eq 443
 30 deny ip any any
</pre>
<p>First lets examine this output. Note that we are looking at an extended access list, although our trick will work with standard ACLs too. Also note that there are numbers before each rule. We are going to learn how to harness the power of these numbers. Lets say we want to add another rule, permitting mail to the 192.168.0.10 host. If you try and just add in the rule using the way they teach you in your CCNA, you end up with the following:</p>
<pre>Router#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
Router(config)#access-list 100 permit tcp any host 192.168.0.10 eq 25
Router(config)#do sh access-l 100
Extended IP access list 100
 10 permit tcp any host 192.168.0.10 eq www
 20 permit tcp any host 192.168.0.10 eq 443
 30 deny ip any any
 40 permit tcp any host 192.168.0.10 eq smtp
Router(config)#
</pre>
<p>So not too good really, that rule will never get hit as its been put after the deny. Luckily theres another way, using the &#8220;ip access-list&#8221; configuration command. Take note here of the rule numbers &#8211; first we&#8217;ll remove the rule that was put at the end of the ACL, and then we&#8217;ll re-add it before the deny:</p>
<pre>Router(config)#ip access-list extended 100
Router(config-ext-nacl)#no 40
Router(config-ext-nacl)#25 permit tcp any host 192.168.0.10 eq smtp
Router(config-ext-nacl)#do show access-list 100
Extended IP access list 100
 10 permit tcp any host 192.168.0.10 eq www
 20 permit tcp any host 192.168.0.10 eq 443
 25 permit tcp any host 192.168.0.10 eq smtp
 30 deny ip any any
Router(config-ext-nacl)#
</pre>
<p>After entering the first command note that we go into config-ext-nacl mode which is where we add and remove rules. Its quite easy &#8211; you add a rule by starting with the sequence number of where you want it go and then entering the rest of the rule as normal. You remove a rule with &#8220;no&#8221; followed by the sequence number.</p>
<p>You might have realised that we can only add so many rules like this before we run out of numbers, but thats fine too as IOS includes a command to let you resequence the list. For example</p>
<pre>Router#sh access-lists 100
Extended IP access list 100
 1 permit tcp any host 192.168.0.10 eq www
 2 permit tcp any host 192.168.0.10 eq 443
 3 permit tcp any host 192.168.0.10 eq smtp
 4 deny ip any any
Router#conf t
Enter configuration commands, one per line.  End with CNTL/Z.
Router(config)#ip access-list resequence 100 10 10
Router(config)#do sh access-l 100
Extended IP access list 100
 10 permit tcp any host 192.168.0.10 eq www
 20 permit tcp any host 192.168.0.10 eq 443
 30 permit tcp any host 192.168.0.10 eq smtp
 40 deny ip any any
Router(config)#
</pre>
<p>So the key command there is &#8220;ip access-list resequence 100 10 10&#8243;. Don&#8217;t get worried by the raft of numbers, its really simple. The first number (100) is the access list we want to resequence; the second number (10) is what number we want the first rule to start at; the third number (10) is what we want the increment to be for each following rule. Lets try another example, we want the list to start at 50 and have increments of 5:</p>
<pre>Router(config)#ip access-list resequence 100 50 5
Router(config)#do sh access-l 100
Extended IP access list 100
 50 permit tcp any host 192.168.0.10 eq www
 55 permit tcp any host 192.168.0.10 eq 443
 60 permit tcp any host 192.168.0.10 eq smtp
 65 deny ip any any
Router(config)#
</pre>
<p>These few commands have come in incredibly useful for me and have saved me a great deal of ACL related headaches, I recommend you learn them!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rxtx.co.uk/2010/10/05/useful-ios-tricks-part-2-access-list-editing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Useful IOS tricks (part 1)</title>
		<link>http://www.rxtx.co.uk/2010/09/16/useful-ios-tricks-part-1/</link>
		<comments>http://www.rxtx.co.uk/2010/09/16/useful-ios-tricks-part-1/#comments</comments>
		<pubDate>Thu, 16 Sep 2010 15:27:47 +0000</pubDate>
		<dc:creator>rxtx</dc:creator>
				<category><![CDATA[Networks]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[ios]]></category>
		<category><![CDATA[iostricks]]></category>

		<guid isPermaLink="false">http://www.rxtx.co.uk/?p=217</guid>
		<description><![CDATA[This is going to be a series of short posts on little features in IOS which make your life easier. These won&#8217;t change your life or anything, but knowing them will make you much more proficient when sitting at a console. The first feature I&#8217;m going to discuss I hope everyone is aware of, the [...]]]></description>
			<content:encoded><![CDATA[<p>This is going to be a series of short posts on little features in IOS which make your life easier. These won&#8217;t change your life or anything, but knowing them will make you much more proficient when sitting at a console. The first feature I&#8217;m going to discuss I hope everyone is aware of, the command lookup. This is incredibly useful when you can&#8217;t quite remember what command you need and it can be used in two slightly different ways.</p>
<p>The first way is when you have no clue at all what you need to type, and just want a refresher of what options are available. Typing the &#8216;?&#8217; character will show you all possible commands with a brief description, eg</p>
<pre>Router#?
Exec commands:
 &lt;1-99&gt;           Session number to resume
 access-enable    Create a temporary Access-List entry
 access-profile   Apply user-profile to interface
 access-template  Create a temporary Access-List entry
 archive          manage archive files
 audio-prompt     load ivr prompt
 auto             Exec level Automation
 beep             Blocks Extensible Exchange Protocol commands
 bfe              For manual emergency modes setting
 calendar         Manage the hardware calendar
 call             Voice call
 ccm-manager      Call Manager Application exec commands
 cd               Change current directory
 cellular         cellular commands
 clear            Reset functions
 clock            Manage the system clock
 cns              CNS agents
 configure        Enter configuration mode
 connect          Open a terminal connection
 copy             Copy from one file to another
 credential       load the credential info from file system
 crypto           Encryption related commands.
 --More--
</pre>
<p>Press space to see more. You can also use this on a nested basis, eg</p>
<pre>Router#show access-lists ?
 &lt;1-2799&gt;    ACL number
 WORD        ACL name
 compiled    Compiled access-list statistics
 rate-limit  Show rate-limit access lists
 |           Output modifiers
 &lt;cr&gt;

Router#show access-lists
</pre>
<p>The second, slightly different way to use this is when halfway through a command, it will try and match based on what you have already typed</p>
<pre>Router#show ip in?
inspect  interface

Router#show ip i?
icmp  igmp  inspect  interface
ips   irdp

Router#show ip in?
inspect  interface

Router#show ip in
</pre>
<p>However note that in this case you don&#8217;t get the command descriptions.</p>
<p>You can use this from any mode, so it works in config, user exec, privileged exec. A lot of the commands you&#8217;ll come to learn by heart, but this is very useful for the ones you use less often.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rxtx.co.uk/2010/09/16/useful-ios-tricks-part-1/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Do you always need a firewall?</title>
		<link>http://www.rxtx.co.uk/2010/08/25/do-you-always-need-a-firewall/</link>
		<comments>http://www.rxtx.co.uk/2010/08/25/do-you-always-need-a-firewall/#comments</comments>
		<pubDate>Wed, 25 Aug 2010 18:49:47 +0000</pubDate>
		<dc:creator>rxtx</dc:creator>
				<category><![CDATA[Networks]]></category>
		<category><![CDATA[firewalls]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.rxtx.co.uk/?p=213</guid>
		<description><![CDATA[I recently read this post on Ivan Pepelnjak&#8217;s blog, where he discusses a pretty intense debate about whether or not firewalls are actually any good. The area where people are claiming they aren&#8217;t is in front of servers. One of the main benefits of a firewall is stateful packet inspection &#8211; the firewall monitors what [...]]]></description>
			<content:encoded><![CDATA[<p>I recently read this <a href="http://blog.ioshints.info/2010/08/i-dont-need-no-stinking-firewall-or-do.html">post</a> on Ivan Pepelnjak&#8217;s blog, where he discusses a pretty intense debate about whether or not firewalls are actually any good. The area where people are claiming they aren&#8217;t is in front of servers. One of the main benefits of a firewall is stateful packet inspection &#8211; the firewall monitors what connections are taking place and dynamically opens ports to let permitted return traffic through. However one opinion is that since all packets to a server are unsolicited, stateful tracking is useless and you should instead stick with basic routers and access lists (which don&#8217;t fall down as easily in the event of  a <a href="http://en.wikipedia.org/wiki/Denial-of-service_attack">DoS/DDoS</a>). I suppose this opinion is talking of servers in the classical sense, where they only ever take inbound connections and don&#8217;t initiate outbound ones. Its very interesting reading, especially the comments.</p>
<p>For my part I don&#8217;t deal with set ups big enough to hit some of the limits they are discussing but it&#8217;s certainly thought provoking. Most people&#8217;s standard response is that you should have a firewall in front of everything, but after following the discussion I&#8217;m now not so sure</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rxtx.co.uk/2010/08/25/do-you-always-need-a-firewall/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco NAT failing for non-connected subnets</title>
		<link>http://www.rxtx.co.uk/2010/08/17/cisco-nat-failing-for-non-connected-subnets/</link>
		<comments>http://www.rxtx.co.uk/2010/08/17/cisco-nat-failing-for-non-connected-subnets/#comments</comments>
		<pubDate>Tue, 17 Aug 2010 18:18:44 +0000</pubDate>
		<dc:creator>rxtx</dc:creator>
				<category><![CDATA[Networks]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[nat]]></category>

		<guid isPermaLink="false">http://www.rxtx.co.uk/?p=201</guid>
		<description><![CDATA[This little problem had me scratching my head for a while, and as usual the solution is pretty simple. The scenario is that you have some kind of link from an ISP with static addresses. At some point you have outgrown your original assignment and have requested a new block, which the ISP has set [...]]]></description>
			<content:encoded><![CDATA[<p>This little problem had me scratching my head for a while, and as usual the solution is pretty simple. The scenario is that you have some kind of link from an ISP with static addresses. At some point you have outgrown your original assignment and have requested a new block, which the ISP has set up at their end. You want NAT an address on the new external subnet to an internal address as shown below. Now on a PIX or ASA you just set up the NAT rules and everything works, but in IOS things are a little more subtle. First the diagram and relevant initial configs. Note that the customer router only has an external IP on the first subnet &#8211; in our case this was due to a lack of spare addresses:</p>
<p><a href="http://www.rxtx.co.uk/wp-content/uploads/2010/08/nat-nonconnected.jpg"><img class="alignnone size-full wp-image-202" title="nat-nonconnected" src="http://www.rxtx.co.uk/wp-content/uploads/2010/08/nat-nonconnected.jpg" alt="nat-nonconnected" width="622" height="262" /></a></p>
<p style="padding-left: 30px;"><span id="more-201"></span><br />
<strong>NAT target</strong></p>
<pre style="padding-left: 30px;">interface FastEthernet0/0
 ip address 10.0.0.1 255.255.255.0
 !
ip route 0.0.0.0 0.0.0.0 10.0.0.2</pre>
<p style="padding-left: 30px;"><strong>Customer router</strong></p>
<pre style="padding-left: 30px;">interface FastEthernet0/0
 ip address 10.0.0.2 255.255.255.0
 ip nat inside
 !
interface FastEthernet0/1
 ip address 172.0.0.2 255.255.255.0
 ip nat outside
 !
ip route 0.0.0.0 0.0.0.0 172.0.0.3
!
ip nat inside source static 10.0.0.1 172.0.1.2</pre>
<p style="padding-left: 30px;"><strong>ISP router</strong></p>
<pre style="padding-left: 30px;">interface FastEthernet0/1
 ip address 172.0.1.3 255.255.255.0 secondary
 ip address 172.0.0.3 255.255.255.0
</pre>
<p>Looks like it should work right? Not quite. If we try and ping 172.0.1.2 from the ISP router, there is no response. We can see the NAT translation in place on the router, and with a debug arp command we can see the arp requests hitting the customer router, but it doesn&#8217;t respond.</p>
<pre style="padding-left: 30px;">Customer#sh ip nat trans
Pro Inside global      Inside local       Outside local      Outside global
--- 172.0.1.2          10.0.0.1           ---                ---
Customer#debug arp
ARP packet debugging is on
Customer#
*Mar  1 00:40:20.147: IP ARP: rcvd req src 172.0.1.3 cc06.11b8.0001, dst 172.0.1.2 FastEthernet0/1
*Mar  1 00:40:22.147: IP ARP: rcvd req src 172.0.1.3 cc06.11b8.0001, dst 172.0.1.2 FastEthernet0/1
*Mar  1 00:40:24.147: IP ARP: rcvd req src 172.0.1.3 cc06.11b8.0001, dst 172.0.1.2 FastEthernet0/1
*Mar  1 00:40:26.111: IP ARP: rcvd req src 172.0.1.3 cc06.11b8.0001, dst 172.0.1.2 FastEthernet0/1
*Mar  1 00:40:28.135: IP ARP: rcvd req src 172.0.1.3 cc06.11b8.0001, dst 172.0.1.2 FastEthernet0/1
Customer#sh ip nat trans
Pro Inside global      Inside local       Outside local      Outside global
--- 172.0.1.2          10.0.0.1           ---                ---
Customer#
</pre>
<p>We can also look in the arp table on the ISP router and confirm that it has no entry for 172.0.1.2. If we change the NAT statement so that the external natted address is on the 172.0.0.0/24 subnet, everything works so we aren&#8217;t hitting proxy-arp issues.</p>
<pre style="padding-left: 30px;">Customer(config)#no ip nat inside source static 10.0.0.1 172.0.1.2
Customer(config)#ip nat inside source static 10.0.0.1 172.0.0.5</pre>
<pre style="padding-left: 30px;">ISP#ping 172.0.0.5
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.0.0.5, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 40/77/92 ms
ISP#
</pre>
<p>To cut a long story short, what we need to do is add the external natted address as a secondary IP on the customer router (or give it a different secondary IP on that subnet).</p>
<pre style="padding-left: 30px;">Customer(config)#int fa 0/1
Customer(config-if)#ip add 172.0.1.2 255.255.255.0 sec
Customer(config-if)#ip add 172.0.1.2 255.255.255.0 secondary</pre>
<pre style="padding-left: 30px;">ISP#ping 172.0.1.2
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.0.1.2, timeout is 2 seconds:
.!!!!
Success rate is 80 percent (4/5), round-trip min/avg/max = 20/49/72 ms
ISP#</pre>
<p>Incredibly obvious when you think about it, but it took me a while to work out due to the fact that on Cisco&#8217;s firewall line it works without secondary addresses. Hopefully this will save someone else the headaches I went through.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rxtx.co.uk/2010/08/17/cisco-nat-failing-for-non-connected-subnets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Debug ip packet with no output</title>
		<link>http://www.rxtx.co.uk/2010/07/08/debug-ip-packet-with-no-output/</link>
		<comments>http://www.rxtx.co.uk/2010/07/08/debug-ip-packet-with-no-output/#comments</comments>
		<pubDate>Thu, 08 Jul 2010 15:23:06 +0000</pubDate>
		<dc:creator>rxtx</dc:creator>
				<category><![CDATA[Networks]]></category>
		<category><![CDATA[cef]]></category>
		<category><![CDATA[cisco]]></category>
		<category><![CDATA[debug]]></category>
		<category><![CDATA[dynamips]]></category>

		<guid isPermaLink="false">http://www.rxtx.co.uk/?p=196</guid>
		<description><![CDATA[If you are working on a Cisco, it can be very useful to see details of the traffic going through it. Occasionally you can use a mirrored (SPAN) port to do this, but if you have exotic interfaces or are using Dynamips this can be more difficult. The &#8220;debug ip packet&#8221; command will dump packet [...]]]></description>
			<content:encoded><![CDATA[<p>If you are working on a Cisco, it can be very useful to see details of the traffic going through it. Occasionally you can use a mirrored (SPAN) port to do this, but if you have exotic interfaces or are using Dynamips this can be more difficult. The &#8220;<a href="http://www.cisco.com/en/US/docs/ios/12_3/debug/command/reference/dbg_i2g.html#wp1086651">debug ip packet</a>&#8221; command will dump packet information straight into your terminal. Occasionally though you will have traffic going through the device but no output shows up in the debug, whats that all about?</p>
<p>Well actually there are a couple of gotchas to bear in mind when doing this. The first is easy and you&#8217;ll probably be hitting yourself &#8211; if you are in a vty session (eg you are connected via telnet or ssh) you don&#8217;t see the console messages by default. Use the terminal monitor command to view the debug messages:</p>
<pre>Router#terminal monitor
</pre>
<p>The second issue is a bit less obvious (unless you&#8217;ve read the command description carefully). Only packets which are process-switched are included in the debug &#8211; this makes sense if you think about it because unless they are process switched the CPU never sees them. To see the traffic in your debug you need to somehow disable CEF which can be done globally or on a per interface basis:</p>
<pre>
Router(config)#no ip cef
Router(config)#int fa 0/0
Router(config-if)#no ip route-cache
</pre>
<p>If you do it on a per interface basis you need to do it on both the ingress and egress port of the traffic you want to capture, otherwise you will only see it in one direction.</p>
<p>As a final warning, think very carefully before disabling CEF on a production router! You could very easily overload the processor and crash the router.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.rxtx.co.uk/2010/07/08/debug-ip-packet-with-no-output/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

