Cisco SSH access hardening

It is 2019 and plenty of network devices still rely on old crypto algorithms and functions. Therefore, I decided to write down some best practices for hardening SSH on Cisco routers / switches. I tested these setting on IOS-XE 16.x releases.  This article is meant as a write-down of picked security practices. You can find more technical deep-dive meaning of the commands by internet research. In fact, when it comes

Snmpwalk tricks

snmpwalk xyz.network.local snmpwalk -v1 -c community xyz.network.local … snmpget -v 2c –c community xyz.network.local … rnetstat –ix xyz.network.local Interface description   Status of Interfaces   System uptime   Interface IP addresses   Last change of interfaces   TCP connection state – who is connected on which port   Other options ifAdminStatus ifOperStatus ifPhysAddress  (mac address) ifSpeed ifType sysContact.0 sysName.0 sysLocation.0

Cisco vs. HP ProCurve VLAN switch ports

Usually, when Cisco oriented networker sets off to the HP networking world, first confusing thing is VLAN port assignment. When speaking about VLAN ports in HP world, the ports can be tagged or untagged (despite the access / trunk ports in Cisco). As you may guess, tagging means 802.1q tagging in Ethernet frames. It is important to realize that Cisco is “port-centric”, whereas Procurve is is “vlan-centric” when speaking about

IPv6 Mobility testing topology

For better understanding and demonstrating of IPv6 mobility mechanisms I designed this simple but sufficient network topology. You can check it on the picture below. I used three routers to describe the mobility process, although one router with three connected networks should be also enough. However, with more routers you can easier monitor and trace the differences between direct and indirect communications with mobile node. There is connected one network switching device

IPv6 Mobility support in operating systems

As with every new standard or technology, also with MIPv6 there is a certain difference between a final RFC specification and real implementation in end devices. The implementation is often incomplete, inefficient or unstable. Therefore, after detailed analysis of MIPv6 specification we designed network topology in our lab environment for testing purposes. We built the topology using Cisco 2800 series routers and set link bandwidths to mirror real-life Internet conditions.

IPv6 Mobility overview

Introduction The term mobility is mentioned much more frequently in current business strategies and in needs of common Internet users. There has been rapid increase of mobile devices (e.g. smartphones, tablets, netbooks) on the market. Also, the movement among different physical locations has never been easier before. Therefore, the demands on modern IT infrastructures have changed completely and the companies want to use seamless services while moving in different locations. Common

IMDb rank your movies!

IMDb ranking is very helpful when you are searching for a good movie. IMDb ranking is made by IMDb users, who can vote for each movie on scale 0 – 10 points. Sure, everybody can have different opinion on the quality of the movie and IMDb ranking can differ from yours. However, this is the average of global opinion which can influence you while choosing the good movie. I have many movies