Cisco

What is stateful and stateless IPv6, what does it do?

What is stateful and stateless IPv6, what does it do?

Fadıl

First of all, I want to quickly answer the question of what is DHCP. DHCP is a service called Dynamic Host Configuration Protocol that allows devices on the network to automatically obtain information such as IP, Default Gateway and DNS. Normally, we now use DHCP with IPv4, but IPv6 introduces two different DHCP services, Stateful and Stateless.

In Stateful DHCP, just like the DHCP server in IPv4, all the necessary information is provided by the DHCP server, and user information (IP and lease, etc.) is stored on the server. In Stateless DHCP, only DNS, etc. information is received from the DHCP server, IP and GW information are automatically generated by the user computer and user information (IP and lease, etc.) is not stored on the server. A computer on an IPv6 network automatically adjusts IP and GW information by utilizing NDP (Neighbor Discovery Protocol) packets from the router on the respective network.

BGP Commands

Fadıl

BGP Finite State Machine: Troubleshooting

(See page 108 of the Halabi book for a diagram).

1. Idle

Waiting for Start event, normally initiated by the operator (establishing new BGP session or resetting an existing session). After errors, BGP falls back to the Idle state.

After a Start event, BGP initializes, resets connect retry timer, initiates TCP transport connection, and listens for connections initiated by a remote peer.

2. Connect

BGP is waiting for a transition protocol connection to complete. If TCP transport succeeds, transition to State 4, OpenSent, and send OPEN. If not, transition to Active. If the connect retry timer expires, remain in Connect, reset the timer, and initiate a transport connection. In case of any other event, transition back to Idle.

Cisco Router Management Configuration Template

Cisco Router Management Configuration Template

Fadıl

Introduction

When a site is implementing new router connectivity, it is useful to work from a configuration template to enhance productivity. This is particularly important in large-scale Frame Relay networks because auditing and altering router configurations to obtain consistency between hundreds of routers can be very tedious and time-consuming.

It is also useful for established sites to occasionally audit their router configurations to verify they are configured consistently, and that they are making best use of management and security features on the routers.

IPsec Simplified

Fadıl

IPsec Security Association Choices

The previous article did not have space to cover some basic choices you have to make when deciding how to run IPsec.

One of the choices is whether you wish to use the Authentication Header (AH) or Encapsulating Security Payload (ESP). Each of these is an IP protocol, just as TCP and UDP are. The protocol codes are 51 and 50, for AH and ESP respectively. Thus IPsec packets will normally have 50 or 51 in the IP protocol field, and there will be an AH or ESP header between the IP header and the payload data.

NetFlow File and Directory Structure

Fadıl

/home/nfcuser — user created to drive NetFlow Analyzer, user working directory

configs — router configs for NFA use (it’s not happy with them)
exports — directory, sym link to directory where NFA drops exported CSV files. Don’t delete!
images — directory to dump screen capture GIF/JPEG saves into


/opt/CSCOnfa — Cisco Flow Data Analyzer

check.All — script to check Java, DisplayServer, UtilityServer are running
start.All — script to start DisplayServer, UtilityServer
stop.All — stops themcisco — mojo (ASN.1/SNMP toolset) — not for user use

NFADisplay — NFA Display UI

bin — programs, scripts, also *.class = Java classes

start.Display script — starts NFA Display screen (UI)

helpRuntimeJava

RuntimeJavaWin95

NFAServer — NFA DisplayServer (Display talks to)

AliasDefn — known AS’s, ports, protocols

[not well documented: see perhaps the UsePortText flag in the NFADS.resources file]

bin — programs, scripts

check.DisplayServer — script to check DisplayServer
DisplayServer — program
NFADS.resources — options for DisplayServer, MaxMB, UsePortText
start.DisplayServer — starts just DisplayServer
stop.DisplayServer — stops it

Cache — cached infoexported_files — where exported CSV files go, /home/nfcuser/exports sym link to this

logs — misc log files (server)

RouterGroup — tree file sets and router groups

util — utilities

mgmt_NFC.exp — expect script (is expect installed?).Appears to copy specified collected info to another directory. Looking at the script, from another machine. Probably used behind the scenes to bring in data from another DisplayServer.

NFAUtility — NFA UtilityServer (does all backend dirty work, talks to NFCGW)

bin — scripts, programs, Java classes

check.UtilityServer
start.UtilityServer
stop.UtilityServer

config — config files for UtilityServer

HostPreferences.txt — address à name translation
NFCCC.txt — NetFlow collectors and userid and port
RouterConfig.txt — address, SNMP community, tms/netflow

Conjecture when NFA looks at directory of router configs, it populates this file. (Not very documented?)

data — AS.txt_0, HostAliases.txt — purpose not clear, probably not user fileslogs — log files for UtilityServer

NFAU.log — log file

state — directory to hold .pid file for UtilityServeroriginals — directory of original config/script files (install probably put locations of things into them)

/opt/CSCOnfc — Cisco FlowCollector