Guia Laboratorio Seguridad Redes
Guia Laboratorio Seguridad Redes
Guia Laboratorio Seguridad Redes
Router:
Servidor:
Paso 3: Configurar el Router para Bloquear o inhabilitar el
protocol ICMP y habilitar el protocol TCP
Router>enable
Router#configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
Router(config)#access-list 101 deny icmp any any host-unreachable
Router(config)#access-list 101 permit tcp any any eq www
Router(config)#interface fa0/0
Router(config-if)#ip access-group 101 in
Router(config-if)#exit
Router(config)#exit
Router#
%SYS-5-CONFIG_I: Configured from console by console
En el imagen se observa que el protocol ICMP, está bloqueado, ósea no hay conexión
En el imagen se observa que el protocol TCP, esta activado, y hay conexión
Switch>enable
Switch#conf ter
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)#int fa0/1
Switch(config-if)#switchport port-security
Command rejected: FastEthernet0/1 is a dynamic port.
Switch(config-if)#switchport mode access
Switch(config-if)#switchport port-security
Switch(config-if)#switchport port-security mac-address 0002.4A4A.51EA
Switch(config-if)#exit
Switch(config)#exit
Switch#show port-security interface fa0/2
Port Security : Enabled
Port Status : Secure-up
Violation Mode : Shutdown
Aging Time : 0 mins
Aging Type : Absolute
SecureStatic Address Aging : Disabled
Maximum MAC Addresses : 1
Total MAC Addresses :1
Configured MAC Addresses : 1
Sticky MAC Addresses :0
Last Source Address:Vlan : 0000.0000.0000:0
Security Violation Count : 0
Switch#
Haga lo siguiente:
En el PC0 abrir y seleccionar la opción Command Prompt
Switch>enable
Switch#configure terminal
Enter configuration commands, one per line. End with CNTL/Z.
Switch(config)#int fa0/4
Switch(config-if)#switchport port-security
Command rejected: FastEthernet0/4 is a dynamic port.
Switch(config-if)#switchport mode access
Switch(config-if)#switchport port-security
Switch(config-if)#switchport port-security maximum 1
Switch(config-if)#switchport port-security violation restrict
Switch(config-if)#switchport port-security mac-address 0030.A352.A8AD
Switch(config-if)#exit
Switch(config)#exit
Switch#show port-security
Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action
(Count) (Count) (Count)
--------------------------------------------------------------------
Fa0/2 1 1 1 Shutdown
Fa0/4 1 1 0 Restrict
----------------------------------------------------------------------
Switch#show port-security interface fa0/4
Port Security : Enabled
Port Status : Secure-up
Violation Mode : Restrict
Aging Time : 0 mins
Aging Type : Absolute
SecureStatic Address Aging : Disabled
Maximum MAC Addresses : 1
Total MAC Addresses :1
Configured MAC Addresses : 1
Sticky MAC Addresses :0
Last Source Address:Vlan : 0000.0000.0000:0
Security Violation Count : 0
Switch#
Switch#