Saturday, August 23, 2014

Cisco 2960S FlexStack Module and Cable

I was asked to stack some few Cisco 2960S switches for a site.


You can stack 2 or more switches (depending on the switch platform) using the Cisco FlexStack module and cable. The StackWise technology is used by Cisco 3750 switches.




Switch(config)#switch ?
  <1-4>  Switch Number   // 2960S CAN STACK UP TO 4 SWITCHES

Switch(config)#switch 1 ?
  priority   Set the priority of the specified switch
  provision  Configure Switch provision / offline config
  renumber   Renumber the specified switch number

Switch(config)#switch 1 priority ?
  <1-15>  Switch Priority

Switch(config)#switch 1 priority 15
Changing the Switch Priority of Switch Number 1 to 15
Do you want to continue?[confirm]
New Priority has been set successfully

Switch(config)#switch 2 priority 12   
There is no switch number 2 in the stack   // CAN ONLY ACTIVATE THIS COMMAND ONCE FLEXSTACK MODULE/CABLE IS CONNECTED

Switch(config)#switch 3 priority 10
There is no switch number 3 in the stack

Switch(config)#switch 2 priority 12
Changing the Switch Priority of Switch Number 2 to 12
Do you want to continue?[confirm]
New Priority has been set successfully

Switch(config)#switch 3 priority 10
Changing the Switch Priority of Switch Number 3 to 10
Do you want to continue?[confirm]
New Priority has been set successfully


You can pre-configure ports on member switches using the switch x provision y command. You can stack a Cisco 2960S 24-port together with a 48-port switch.

I needed this command since the VLANs and ports on our 2960S switches were already configured. Once stacking is done and switches are rebooted, our VLAN 1 management IP address on member switches were gone. The config on the master switch remained intact.

Switch(config)#switch 2 provision ?
  ws-c2960s-24pd-l   provision a Catalyst 2960s switch with 24GPwr+2SFP+ interfaces
  ws-c2960s-24ps-l   provision a Catalyst 2960s switch with 24GPwr+4SFP interfaces
  ws-c2960s-24td-l   provision a Catalyst 2960s switch with 24G+2SFP+ interfaces
  ws-c2960s-24ts-l   provision a Catalyst 2960s switch with 24G+4SFP interfaces
  ws-c2960s-24ts-s   provision a Catalyst 2960s switch with 24G+2SFP interfaces
  ws-c2960s-48fpd-l  provision a Catalyst 2960s switch with 48GPwr+2SFP+ interfaces
  ws-c2960s-48fps-l  provision a Catalyst 2960s switch with 48GPwr+4SFP interfaces
  ws-c2960s-48lpd-l  provision a Catalyst 2960s switch with 48GPwr+2SFP+ interfaces
  ws-c2960s-48lps-l  provision a Catalyst 2960s switch with 48GPwr+4SFP interfaces
  ws-c2960s-48td-l   provision a Catalyst 2960s switch with 48G+2SFP+ interfaces
  ws-c2960s-48ts-l   provision a Catalyst 2960s switch with 48G+4SFP interfaces
  ws-c2960s-48ts-s   provision a Catalyst 2960s switch with 48G+2SFP interfaces

Switch(config)#switch 2 provision ws-c2960s-24ps-l
Switch(config)#interface range GigabitEthernet2/0/1-24     // SWITCH 2; TAKE NOTE OF THE MODULE NUMBER (IN BOLD)
Switch(config-if)#switchport access vlan 110
Switch(config-if)#switchport mode access
Switch(config-if)#spanning-tree portfast

Switch(config)#switch 3 provision ws-c2960s-24ps-l
Switch(config)#interface range GigabitEthernet3/0/1-24    // SWITCH 3
Switch(config-if)#switchport access vlan 110
Switch(config-if)#switchport mode access
Switch(config-if)#spanning-tree portfast


Here are some useful show commands:

Switch#show switch ?
  <1-4>        Switch Number
  detail       show detailed information about the stack ring
  neighbors    show each switch's neighbors
  stack-ports  show the status of the stack ports
  stack-ring   show stack ring
  |            Output modifiers
  <cr>

Switch#show switch detail
Switch/Stack Mac Address : 6c9c.ed9d.g200
                                           H/W   Current
Switch#  Role   Mac Address     Priority Version  State
----------------------------------------------------------
*1       Master 6c9c.ed9d.g200     15     1       Ready            //  BOOT UP MASTER SWITCH FIRST AND THEN BOOT UP MEMBER SWITCHES ACCORDINGLY
 2       Member 6c9c.edc2.4300    12      1       Ready              
 3       Member 2c36.f85e.6e00     10      1       Ready             
         Stack Port Status             Neighbors    
Switch#  Port 1     Port 2           Port 1   Port 2
--------------------------------------------------------
  1        Ok         Ok                2        3
  2        Ok         Ok                1        3
  3        Ok         Ok                2        1

Switch#show switch neighbor
  Switch #    Port 1       Port 2
  --------    ------       ------
      1         2             3 
      2         1             3 
      3         2             1 

Switch#show switch stack-ports
  Switch #    Port 1       Port 2
  --------    ------       ------
    1           Ok           Ok  
    2           Ok           Ok  
    3           Ok           Ok  

Switch#show switch stack-ring ?
  activity  show stack ring activity
  speed     show stack ring speed

Switch#show switch stack-ring speed  

Stack Ring Speed        : 10G     // AGGREGATED BACKPLANE BANDWIDTH
Stack Ring Configuration: Full
Stack Ring Protocol     : FlexStack   // YOU'LL SEE STACKWISE ON 3750

Switch#show switch

Switch/Stack Mac Address : 6c9c.ed9d.g200
                                           H/W   Current
Switch#  Role   Mac Address     Priority Version  State
----------------------------------------------------------
*1       Master 6c9c.ed9d.g200     15     1       Ready              
 2       Member 6c9c.edc2.4300    12      1       Ready              
 3       Member 2c36.f85e.6e00     10      1       Ready 

Switch#show switch stack-port
  Switch #    Port 1       Port 2
  --------    ------       ------
    1           Ok           Ok  
    2           Ok           Ok  
    3           Ok           Ok  

Switch#show switch detail       
Switch/Stack Mac Address : 6c9c.ed9d.g200
                                           H/W   Current
Switch#  Role   Mac Address     Priority Version  State
----------------------------------------------------------
*1       Master 6c9c.ed9d.g200     15     1       Ready              
 2       Member 6c9c.edc2.4300    12      1       Ready              
 3       Member 2c36.f85e.6e00     10      1       Ready              

         Stack Port Status             Neighbors    
Switch#  Port 1     Port 2           Port 1   Port 2
--------------------------------------------------------
  1        Ok         Ok                2        3
  2        Ok         Ok                1        3
  3        Ok         Ok                2        1

Friday, July 25, 2014

Rack Mounting My Network Lab Gear

The major components for my CCIE R/S rack are almost completed. I just need get my C3560 switches and serial cables for my WICs.

I bought an On Stage RS7030 12 RU rack from a local music store. It's meant for mounting musical/AV equipment but it can also be used for Cisco network gear.



I removed the rubber feet beneath the chassis to get an even spacing between the 1841s.


The rack mount ears (RCKMNT-19-CMPCT) can be used for both Cisco 3560 and 2960 8-port compact switch.
 


I noticed my rack is already heavy. I also want to make room for ventilation as well. So, I plan of getting another 12U rack for the heavier devices like the 2811 routers and 3560 switches.


I used a cover (for clothing hanger), which I bought from Daiso Japan, in order to prevent dust from getting in.

Friday, June 20, 2014

Configuring My Cisco 2511 Terminal Server

After updating the IOS for my 2511 terminal server on my previous post, it's time to configure and hook it up to my C2960 and C2940 switches.


2511-TS(config)#menu ?
  WORD  Name of this menu

2511-TS(config)#menu TS ?
  clear-screen  Use termcap database to clear screen
  command       Set menu command
  default       Item number to use for RETURN
  line-mode     require <enter> after typing selection
  options       Set per-item options
  prompt        Set prompt string
  single-space  single-space menu entries on display
  status-line   Display user status at top of screen
  text          Set text of menu line
  title         Set menu title

2511-TS(config)#menu TS title ?
  LINE  delimited text of title

2511-TS(config)#menu TS title #
menu TS title ^C     // "#" DOESN'T WORK, USE ^
+---------------------------------------------------+
|  John Lagura's CCIE R&S Lab Terminal Server       |
|                                                   |
| To exit a device, use CTRL+SHIFT+6 then press x   |
+---------------------------------------------------+
^C
2511-TS(config)#menu TS prompt ?
  LINE  delimited text of title

2511-TS(config)#menu TS prompt ^ Make a selection: ^    // "#" DOESN'T WORK, USE "^"
2511-TS(config)#menu TS text 1 Connect to Rack1 SW3 - 2960
2511-TS(config)#menu TS text 2 Connect to Rack1 SW2 - 2940
2511-TS(config)#menu TS text s Show all established sessions
2511-TS(config)#menu TS text e Exit Menu
2511-TS(config)#menu TS text c# Clear the session by number, example: c1
2511-TS(config)#menu TS text q Quit TS session

2511-TS(config)#menu TS command ?
  WORD  Menu item number or character

2511-TS(config)#menu TS command 1 resume ?
LINE    <cr>

2511-TS(config)#menu TS command 1 resume SW3 /connect Telnet SW3
2511-TS(config)#menu TS command 2 resume SW2 /connect Telnet SW2

2511-TS(config)#menu TS command s ?
  LINE  Command for this menu item

2511-TS(config)#menu TS command s show session
2511-TS(config)#menu TS options ?
  WORD  Menu item number or character

2511-TS(config)#menu TS options s ?
  login  Login required before command
  pause  pause after command, before redrawing menu
  <cr>

2511-TS(config)#menu TS options s pause
2511-TS(config)#menu TS command e menu-exit
2511-TS(config)#menu TS command q quit
2511-TS(config)#menu TS clear-screen
2511-TS(config)#menu TS line-mode
2511-TS(config)#menu TS command c1 c1
2511-TS(config)#menu TS command c2 c2

2511-TS(config)#alias ?
  aaa-user                 AAA user definition
  accept-dialin            VPDN group accept dialin configuration mode
  accept-dialout           VPDN group accept dialout configuration mode
  address-family           Address Family configuration mode
  alps-ascu                ALPS ASCU configuration mode
  alps-circuit             ALPS circuit configuration mode
  bba-group                BBA Group configuration mode
  boomerang                Boomerang configuration mode
  clid-group               CLID group configuration mode
  cns-connect-intf-config  CNS Connect Intf Info Mode
  config-rtr-http-rr       RTR HTTP raw request Configuration
  config-x25-huntgroup     X.25 hunt group configuration mode
  configure                Global configuration mode
  congestion               Frame Relay congestion configuration mode
  dhcp                     DHCP pool configuration mode
  dnis-group               DNIS group configuration mode
  exec                     Exec mode
  filterserver             AAA filter server definitions
  flow-cache               Flow aggregation cache config mode
  fr-fr                    FR/FR connection configuration mode
  fr-vcb-bmode             FR VC Bundle mode
  fr-vcb-mmode             FR VC Bundle Member mode
  funi-vc-config           FUNI virtual circuit configuration mode
  interface                Interface configuration mode
  interface                Interface range configuration mode
  interface-dlci           Frame Relay dlci configuration mode
  ip-vrf                   Configure IP VRF parameters
  ipenacl                  IP named extended access-list configuration mode
  ipnat-pool               IP NAT pool configuration mode
  ipnat-snat               IP SNAT configuration mode
  ipnat-snat-backup        IP SNAT Backup configuration mode
  ipnat-snat-primary       IP SNAT Primary configuration mode
  ipnat-snat-redundancy    IP SNAT Redundancy configuration mode
  ipsnacl                  IP named simple access-list configuration mode
  ipv6-router              IPv6 router configuration mode
  ipv6acl                  IPv6 access-list configuration mode
  key-chain                Key-chain configuration mode
  key-chain-key            Key-chain key configuration mode
  line                     Line configuration mode
  map-class                Map class configuration mode
  map-list                 Map list configuration mode
  mobile-networks          Mobile Networks mode
  mobile-router            Mobile Router mode
  mrm-manager              IP Multicast Routing Monitor config mode
  null-interface           Null interface configuration mode
  policy-list              IP Policy List configuration mode
  preauth                  AAA Preauth definitions
  qosclassmap              QoS Class Map configuration mode
  qosclasspolice           QoS Class Police configuration mode
  qospolicymap             QoS Policy Map configuration mode
  qospolicymapclass        QoS Policy Map class configuration mode
  radius-attrl             Radius Attribute-List Definition
  request-dialin           VPDN group request dialin configuration mode
  request-dialout          VPDN group request dialout configuration mode
  route-map                Route map config mode
  router                   Router configuration mode
  rsvp-local-policy        RSVP local policy configuration mode
  rtr                      SAA entry configuration
  saa-dhcp                 SAA dhcp configuration
  saa-dlsw                 SAA dlsw configuration
  saa-dns                  SAA dns configuration
  saa-echo                 SAA echo configuration
  saa-frameRelay           SAA FrameRelay configuration
  saa-ftp                  SAA ftp configuration
  saa-http                 SAA http configuration
  saa-jitter               SAA jitter configuration
  saa-pathEcho             SAA pathEcho configuration
  saa-pathJitter           SAA pathJitter configuration
  saa-tcpConnect           SAA tcpConnect configuration
  saa-udpEcho              SAA udpEcho configuration
  sg-radius                Radius Server-group Definition
  sg-tacacs+               Tacacs+ Server-group Definition
  sss-subscriber           SSS subscriber configuration mode
  subinterface             Subinterface configuration mode
  template                 Template configuration mode
  tracking-config          Tracking configuration mode
  trange                   time-range configuration mode
  vc-class                 VC class configuration mode
  vpdn-group               VPDN group configuration mode
  vpdn-template            VPDN template configuration mode
  x25-profile              X.25 profile configuration mode

2511-TS(config)#alias exec ?
  WORD  Alias name

2511-TS(config)#alias exec c1 ?
  LINE  New alias

2511-TS(config)#alias exec c1 disconnect SW3
2511-TS(config)#alias exec c2 disconnect SW2


2511-TS(config)#int loopback0
*Mar  1 00:03:42.503: %LINK-3-UPDOWN: Interface Loopback0, changed state to up
*Mar  1 00:03:43.503: %LINEPROTO-5-UPDOWN: Line protocol on Interface Loopback0, changed state to up
2511-TS(config-if)#ip address 1.1.1.1 255.255.255.255    // IP FOR REVERSE TELNET
2511-TS(config-if)#exit
2511-TS(config)#ip host ?
  WORD  Name of host

2511-TS(config)#ip host SW3 ?
  <0-65535>   Default telnet port number
  A.B.C.D     Host IP address
  additional  Append addresses

2511-TS(config)#ip host SW3 2001 ?
  A.B.C.D     Host IP address
  additional  Append addresses

2511-TS(config)#ip host SW3 2001 1.1.1.1     // PORT 2001 TO OCTAL CABLE 1
2511-TS(config)#ip host SW2 2002 1.1.1.1    // PORT 2001 TO OCTAL CABLE 2

2511-TS#show line
   Tty Typ     Tx/Rx    A Modem  Roty AccO AccI   Uses   Noise  Overruns   Int
*    0 CTY              -    -      -    -    -      0       0     0/0       -
     1 TTY   9600/9600  -    -      -    -    -      0       0     0/0       -
     2 TTY   9600/9600  -    -      -    -    -      0       0     0/0       -
     3 TTY   9600/9600  -    -      -    -    -      0       0     0/0       -
     4 TTY   9600/9600  -    -      -    -    -      0       0     0/0       -
     5 TTY   9600/9600  -    -      -    -    -      0       0     0/0       -
     6 TTY   9600/9600  -    -      -    -    -      0       0     0/0       -
     7 TTY   9600/9600  -    -      -    -    -      0       0     0/0       -
     8 TTY   9600/9600  -    -      -    -    -      0       0     0/0       -
     9 TTY   9600/9600  -    -      -    -    -      0       0     0/0       -
    10 TTY   9600/9600  -    -      -    -    -      0       0     0/0       -
    11 TTY   9600/9600  -    -      -    -    -      0       0     0/0       -
    12 TTY   9600/9600  -    -      -    -    -      0       0     0/0       -
    13 TTY   9600/9600  -    -      -    -    -      0       0     0/0       -
    14 TTY   9600/9600  -    -      -    -    -      0       0     0/0       -
    15 TTY   9600/9600  -    -      -    -    -      0       0     0/0       -
    16 TTY   9600/9600  -    -      -    -    -      0       0     0/0       -
    17 AUX   9600/9600  -    -      -    -    -      0       0     0/0       -
    18 VTY              -    -      -    -    -      0       0     0/0       -
    19 VTY              -    -      -    -    -      0       0     0/0       -
    20 VTY              -    -      -    -    -      0       0     0/0       -
    21 VTY              -    -      -    -    -      0       0     0/0       -
   Tty Typ     Tx/Rx    A Modem  Roty AccO AccI   Uses   Noise  Overruns   Int

2511-TS#configure terminal
2511-TS(config)#line con 0
2511-TS(config-line)#logging synchronous
2511-TS(config-line)#
Enter configuration commands, one per line.  End with CNTL/Z.
2511-TS(config)#line ?
  <0-22>   First Line number
  aux      Auxiliary line
  console  Primary terminal line
  tty      Terminal controller
  vty      Virtual terminal

2511-TS(config)#line 1 ?
  <2-22>  Last Line number
  <cr>

2511-TS(config)#line 1 16
2511-TS(config-line)#?
Line configuration commands:
  absolute-timeout            Set absolute timeout for line disconnection
  access-class                Filter connections based on an IP access list
  activation-character        Define the activation character
  autobaud                    Set line to normal autobaud
  autocommand                 Automatically execute an EXEC command
  autocommand-options         Autocommand options
  autohangup                  Automatically hangup when last connection closes
  autoselect                  Set line to autoselect
  buffer-length               Set DMA buffer length
  callback                    Callback settings
  data-character-bits         Size of characters being handled
  databits                    Set number of data bits per character
  default                     Set a command to its defaults
  disconnect-character        Define the disconnect character
  dispatch-character          Define the dispatch character
  dispatch-machine            Reference a TCP dispatch state machine
  dispatch-timeout            Set the dispatch timer
  domain-lookup               Enable domain lookups in show commands
  editing                     Enable command line editing
  escape-character            Change the current line's escape character
  exec                        Configure EXEC
  exec-banner                 Enable the display of the EXEC banner
  exec-character-bits         Size of characters to the command exec
  exec-timeout                Set the EXEC timeout
  exit                        Exit from line configuration mode
  flowcontrol                 Set the flow control
  flush-at-activation         Clear input stream at activation
  full-help                   Provide help to unprivileged user
  help                        Description of the interactive help system
  history                     Enable and control the command history function
  hold-character              Define the hold character
  insecure                    Mark line as 'insecure' for LAT
  international               Enable international 8-bit character support
  ip                          IP options
  ipv6                        IPv6 options
  length                      Set number of lines on a screen
  location                    Enter terminal location description
  lockable                    Allow users to lock a line
  logging                     Modify message logging facilities
  login                       Enable password checking
  logout-warning              Set Warning countdown for absolute timeout of
                              line
  modem                       Configure the Modem Control Lines
  monitor                     Copy debug output to the current terminal line
  motd-banner                 Enable the display of the MOTD banner
  no                          Negate a command or set its defaults
  notify                      Inform users of output from concurrent sessions
  ntp                         Configure NTP
  padding                     Set padding for a specified output character
  parity                      Set terminal parity
  password                    Set a password
  private                     Configuration options that user can set will
                              remain in effect between terminal sessions
  privilege                   Change privilege level for line
  refuse-message              Define a refuse banner
  rotary                      Add line to a rotary group
  rxspeed                     Set the receive speed
  script                      specify event related chat scripts to run on the
                              line
  session-disconnect-warning  Set warning countdown for session-timeout
  session-limit               Set maximum number of sessions
  session-timeout             Set interval for closing connection when there is
                              no input traffic
  special-character-bits      Size of the escape (and other special) characters
  speed                       Set the transmit and receive speeds
  start-character             Define the start character
  stop-character              Define the stop character
  stopbits                    Set async line stop bits
  telnet                      Telnet protocol-specific configuration
  terminal-type               Set the terminal type
  timeout                     Timeouts for the line
  transport                   Define transport protocols for line
  txspeed                     Set the transmit speeds
  vacant-message              Define a vacant banner
  width                       Set width of the display terminal
  x25                         X25 protocol-specific configuration

2511-TS(config-line)#transport ?
  input      Define which protocols to use when connecting to the terminal
             server
  output     Define which protocols to use for outgoing connections
  preferred  Specify the preferred protocol to use

2511-TS(config-line)#transport input ?
  all     All protocols
  none    No protocols
  pad     X.3 PAD
  rlogin  Unix rlogin protocol
  telnet  TCP/IP Telnet protocol
  udptn   UDPTN async via UDP protocol
  v120    Async over ISDN

2511-TS(config-line)#transport input telnet
2511-TS(config-line)#no exec ?
  prompt  EXEC prompt
  <cr>

2511-TS(config-line)#no exec
2511-TS(config-line)#exec-timeout ?
  <0-35791>  Timeout in minutes

2511-TS(config-line)#exec-timeout 0
2511-TS(config-line)#end
2511-TS#menu ?
  WORD  Name of menu to run

2511-TS#menu TS ?
  <cr>

2511-TS#menu TS     // LOAD TS MENU MANUALLY


+---------------------------------------------------+
|  John Lagura's CCIE R&S Lab Terminal Server       |
|                                                   |
| To exit a device, use CTRL+SHIFT+6 then press x   |
+---------------------------------------------------+


    1          Connect to Rack1 SW2 - 2940

    2          Connect to Rack1 SW3 - 2960

    s          Show all established sessions

    e          Exit Menu

    q          Quit TS session

    c#         Clear the session by number, example: c1

 Make a selection:


OR

2511-TS(config)#line vty 0 4
2511-TS(config-line)#?
Line configuration commands:
  absolute-timeout            Set absolute timeout for line disconnection
  access-class                Filter connections based on an IP access list
  activation-character        Define the activation character
  autobaud                    Set line to normal autobaud
  autocommand                 Automatically execute an EXEC command
  autocommand-options         Autocommand options
  autohangup                  Automatically hangup when last connection closes
  autoselect                  Set line to autoselect
  buffer-length               Set DMA buffer length
  data-character-bits         Size of characters being handled
  databits                    Set number of data bits per character
  default                     Set a command to its defaults
  disconnect-character        Define the disconnect character
  dispatch-character          Define the dispatch character
  dispatch-machine            Reference a TCP dispatch state machine
  dispatch-timeout            Set the dispatch timer
  domain-lookup               Enable domain lookups in show commands
  editing                     Enable command line editing
  escape-character            Change the current line's escape character
  exec                        Configure EXEC
  exec-banner                 Enable the display of the EXEC banner
  exec-character-bits         Size of characters to the command exec
  exec-timeout                Set the EXEC timeout
  exit                        Exit from line configuration mode
  flowcontrol                 Set the flow control
  flush-at-activation         Clear input stream at activation
  full-help                   Provide help to unprivileged user
  help                        Description of the interactive help system
  history                     Enable and control the command history function
  hold-character              Define the hold character
  insecure                    Mark line as 'insecure' for LAT
  international               Enable international 8-bit character support
  ip                          IP options
  ipv6                        IPv6 options
  length                      Set number of lines on a screen
  location                    Enter terminal location description
  lockable                    Allow users to lock a line
  logging                     Modify message logging facilities
  login                       Enable password checking
  logout-warning              Set Warning countdown for absolute timeout of
                              line
  modem                       Configure the Modem Control Lines
  monitor                     Copy debug output to the current terminal line
  motd-banner                 Enable the display of the MOTD banner
  no                          Negate a command or set its defaults
  notify                      Inform users of output from concurrent sessions
  ntp                         Configure NTP
  padding                     Set padding for a specified output character
  parity                      Set terminal parity
  password                    Set a password
  private                     Configuration options that user can set will
                              remain in effect between terminal sessions
  privilege                   Change privilege level for line
  refuse-message              Define a refuse banner
  rotary                      Add line to a rotary group
  rxspeed                     Set the receive speed
  script                      specify event related chat scripts to run on the
                              line
  session-disconnect-warning  Set warning countdown for session-timeout
  session-limit               Set maximum number of sessions
  session-timeout             Set interval for closing connection when there is
                              no input traffic
  special-character-bits      Size of the escape (and other special) characters
  speed                       Set the transmit and receive speeds
  start-character             Define the start character
  stop-character              Define the stop character
  stopbits                    Set async line stop bits
  telnet                      Telnet protocol-specific configuration
  terminal-type               Set the terminal type
  timeout                     Timeouts for the line
  transport                   Define transport protocols for line
  txspeed                     Set the transmit speeds
  vacant-message              Define a vacant banner
  width                       Set width of the display terminal
  x25                         X25 protocol-specific configuration

2511-TS(config-line)#autocommand ?
  LINE                    Appropriate EXEC command
  no-suppress-linenumber  Display service linenumber message

2511-TS(config-line)#autocommand menu ?
LINE    <cr>

2511-TS(config-line)#autocommand menu TS    // LOAD MENU WHEN USING TELNET


----


 Make a selection: 1
Trying SW3 (1.1.1.1, 2001)... Open     // AT THIS POINT, IT JUST REMAINED AS OPEN



+---------------------------------------------------+
|  John Lagura's CCIE R&S Lab Terminal Server       |
|                                                   |
| To exit a device, use CTRL+SHIFT+6 then press x   |
+---------------------------------------------------+


    1          Connect to Rack1 SW3 - 2960

    2          Connect to Rack1 SW2 - 2940

    s          Show all established sessions

    e          Exit Menu

    c#         Clear the session by number, example: c1

    q          Quit TS session

 Make a selection: s
% No connections open


--------

The TS connection to the swtich remained "open" so I checked the config and cable connection. Found out I was connected to Async 9-16. I got a console prompt after changing the octal cable connection to Async 1-8 and tightened the screws.


+---------------------------------------------------+
|  John Lagura's CCIE R&S Lab Terminal Server       |
|                                                   |
| To exit a device, use CTRL+SHIFT+6 then press x   |
+---------------------------------------------------+


    1          Connect to Rack1 SW3 - 2960

    2          Connect to Rack1 SW2 - 2940

    s          Show all established sessions

    e          Exit Menu

    c#         Clear the session by number, example: c1

    q          Quit TS session

 Make a selection: 1
Trying SW3 (1.1.1.1, 2001)... Open

SW3>
SW3>enable
Password:
SW3#who
    Line       User       Host(s)              Idle       Location
*  0 con 0                idle                 00:00:00

  Interface      User        Mode                     Idle     Peer Address

SW3#


+---------------------------------------------------+
|  John Lagura's CCIE R&S Lab Terminal Server       |
|                                                   |
| To exit a device, use CTRL+SHIFT+6 then press x   |
+---------------------------------------------------+


    1          Connect to Rack1 SW3 - 2960

    2          Connect to Rack1 SW2 - 2940

    s          Show all established sessions

    e          Exit Menu

    c#         Clear the session by number, example: c1

    q          Quit TS session

 Make a selection: 2
Trying SW2 (1.1.1.1, 2002)... Open

SW2>enable
Password:
SW2#who
    Line       User       Host(s)              Idle       Location
*  0 con 0                idle                 00:00:00

  Interface      User        Mode                     Idle     Peer Address


+---------------------------------------------------+
|  John Lagura's CCIE R&S Lab Terminal Server       |
|                                                   |
| To exit a device, use CTRL+SHIFT+6 then press x   |
+---------------------------------------------------+


    1          Connect to Rack1 SW3 - 2960

    2          Connect to Rack1 SW2 - 2940

    s          Show all established sessions

    e          Exit Menu

    c#         Clear the session by number, example: c1

    q          Quit TS session

 Make a selection: s
Conn Host                Address             Byte  Idle Conn Name
   1 SW3                 1.1.1.1                0     1 SW3
*  2 SW2                 1.1.1.1                0     0 SW2


+---------------------------------------------------+
|  John Lagura's CCIE R&S Lab Terminal Server       |
|                                                   |
| To exit a device, use CTRL+SHIFT+6 then press x   |
+---------------------------------------------------+


    1          Connect to Rack1 SW3 - 2960

    2          Connect to Rack1 SW2 - 2940

    s          Show all established sessions

    e          Exit Menu

    c#         Clear the session by number, example: c1

    q          Quit TS session

 Make a selection: c1
Closing connection to SW3 [confirm]


+---------------------------------------------------+
|  John Lagura's CCIE R&S Lab Terminal Server       |
|                                                   |
| To exit a device, use CTRL+SHIFT+6 then press x   |
+---------------------------------------------------+


    1          Connect to Rack1 SW3 - 2960

    2          Connect to Rack1 SW2 - 2940

    s          Show all established sessions

    e          Exit Menu

    c#         Clear the session by number, example: c1

    q          Quit TS session

 Make a selection: s
Conn Host                Address             Byte  Idle Conn Name
*  2 SW2                 1.1.1.1                0     0 SW2


Here's the full running-config output:


2511-TS#show running-config
Building configuration...

Current configuration : 1772 bytes
!
version 12.2
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
service udp-small-servers
service tcp-small-servers
!
hostname 2511-TS
!
logging queue-limit 100
!
ip subnet-zero
ip host SW2 2002 1.1.1.1
ip host SW3 2001 1.1.1.1
!
!
!
!
interface Loopback0
 ip address 1.1.1.1 255.255.255.255
!
interface Ethernet0
 no ip address
 no ip route-cache
 no ip mroute-cache
!
interface Serial0
 no ip address
 no ip route-cache
 no ip mroute-cache
 shutdown
 no fair-queue
!
interface Serial1
 no ip address
 no ip route-cache
 no ip mroute-cache
 shutdown
!
no ip http server
ip classless
!
!
!
!
menu TS title ^C
+---------------------------------------------------+
|  John Lagura's CCIE R&S Lab Terminal Server       |
|                                                   |
| To exit a device, use CTRL+SHIFT+6 then press x   |
+---------------------------------------------------+
^C
menu TS prompt ^C Make a selection: ^C
menu TS text 1 Connect to Rack1 SW3 - 2960
menu TS command 1 resume SW3 /connect Telnet SW3
menu TS text 2 Connect to Rack1 SW2 - 2940
menu TS command 2 resume SW2 /connect Telnet SW2
menu TS text s Show all established sessions
menu TS command s show session
menu TS options s pause
menu TS text e Exit Menu
menu TS command e menu-exit
menu TS text c# Clear the session by number, example: c1
menu TS text q Quit TS session
menu TS command q quit
menu TS command c1 c1
menu TS command c2 c2
menu TS clear-screen
menu TS line-mode
!
alias exec c1 disconnect SW3
alias exec c2 disconnect SW2
!
line con 0
 logging synchronous
line 1 16
 exec-timeout 0 0
 no flush-at-activation
 no exec
 transport input telnet
line aux 0
 transport input all
line vty 0 4
 login
 autocommand  menu TS
!
end



Friday, May 9, 2014

Configure 871w for Certificate Authority (CA) Server

I've configured my 871w router to be my root Certficate Authority (CA) / Public Key Infrastructure (PKI) server. Also, using the PKI solution helps provide a more scalable authentication for my VPN lab.


I performed the following tasks to implement a CA server on an IOS-based router:

871W#show run | inc ntp    // ENSURE NTP RUNS ON BOTH CA SERVER AND CLIENTS FOR CERT TO BE IN SYNC
ntp clock-period 17182401
ntp server 203.123.48.6
871W#show clock
10:37:49.407 SGT Sun Mar 9 2014

871W(config)#crypto key generate rsa ?
  encryption    Generate a general purpose RSA key pair for signing and encryption
  exportable    Allow the key to be exported
  general-keys  Generate a general purpose RSA key pair for signing and encryption
  label         Provide a label
  modulus       Provide number of modulus bits on the command line
  on            create key on specified device.
  signature     Generate a general purpose RSA key pair for signing and encryption
  storage       Store key on specified device
  usage-keys    Generate separate RSA key pairs for signing and encryption
  <cr>

871W(config)#crypto key generate rsa label ?
  WORD  RSA keypair label

871W(config)#crypto key generate rsa label VPN-KEY ?
  encryption    Generate a general purpose RSA key pair for signing and encryption
  exportable    Allow the key to be exported
  general-keys  Generate a general purpose RSA key pair for signing and encryption
  modulus       Provide number of modulus bits on the command line
  on            create key on specified device.
  signature     Generate a general purpose RSA key pair for signing and encryption
  storage       Store key on specified device
  usage-keys    Generate separate RSA key pairs for signing and encryption
  <cr>

871W(config)#crypto key generate rsa label VPN-KEY modulus ?
  <360-2048>  size of the key modulus [360-2048]

871W(config)#crypto key generate rsa label VPN-KEY modulus 1024 exportable   // RSA KEYS CAN BE EXPORTED IN PRIVACY ENHANCED MAIL (PEM) FORMAT

The name for the keys will be: VPN-KEY

% The key modulus size is 1024 bits
% Generating 1024 bit RSA keys, keys will be exportable...[OK]

871W(config)#crypto key export rsa ?
  WORD  RSA key label

871W(config)#crypto key export rsa VPN-KEY ?
  pem  File type to export

871W(config)#crypto key export rsa VPN-KEY pem ?
  terminal  Export via the terminal (cut-and-paste)
  url       Export via the file systems

871W(config)#crypto key export rsa VPN-KEY pem terminal ?
  3des  Encrypt the private key with 3DES
  des   Encrypt the private key with DES

871W(config)#crypto key export rsa VPN-KEY pem terminal 3des ?
  LINE  Passphrase used to protect the private key

871W(config)#crypto key export rsa VPN-KEY pem terminal 3des cisco
% Passphrase is too short, needs to be at least 8 chars
871W(config)#crypto key export rsa VPN-KEY pem terminal 3des cisco123
% Key name: VPN-KEY
   Usage: General Purpose Key
   Key data:
-----BEGIN PUBLIC KEY-----
MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCZq+SNIRShVFMDYW0ebZRhhPQW
PwzB1g8+IneNAhbeWOrLG8TpNYBG8zX55iGK/xHZdL+RMeCEp2JtWfAfZ7oxoH6r
VUgQ6reI7Bpenc80PIoa8mt61cHShWJKfGGxvxrJHMSqTQnBRCpTlFhYpIgYorbm
UOBHFBibH6IXo03+BQIDAQAB
-----END PUBLIC KEY-----
-----BEGIN RSA PRIVATE KEY----
-
Proc-Type: 4,ENCRYPTED
DEK-Info: DES-EDE3-CBC,5D2BF9B679BF6C23

r0Qr9opRVvT9KuJxjIjVXQulGI4glBFQMBdbp2M2LcbUymMFh8P+YtQaf+0HAqZg
HhYl/YQd2i4N7BeyLhRR1/HlUhrTSLDRpzTFRBDPYiFd4mUgJc668uiq3TOd/gA1
W4SPmS8DBxUh4OQQS5SRsDJQ/LDoZhvU8O9yBvVrFC0UYue7EgobK/FgSS2UwYm8
BII2KT6cKFWnoqwBhqbowa+cYWGRFWAd4rpohbColZbL/0SEylPCBnSeR8JlPVxr
/d47gVH3/SX1LE+fxAp2zH6cnKgyRy2P5AG4Ux7gxmJrJb6j4w2u9Qpqua74de4e
GRdzCAsutCIiPdGl07WACCvPnas85fhfxB5XDYJZEuEqHs2QOUof4xcKh7vFnw1X
0J4J/OroV+HFf//n9KsuO1Q2gMZMOwvrN8Rm22GTPZWxa8gS4Sipa9H08+qUy9O1
afxl8/g2W9WxGlgerpFqlMgNQQC6RG5r1l0/VbwrrAvUBVSUJwYzhd3Vk2+ubLuZ
rCCm6SPEdVJ+EYTBCiPYrLdBhSgtyGOhBXLz6T6wvnIRMQjJrVnQ4uHoYphLkFYr
kTAOFH8g2Fj9zNbrpJVp0pXqPSusCvIzv43WGSavS2srovA8stLdYOKYKV3tHlYs
wvigYS5WX5iOf7Z6QLr9KWZiegssNpcHmYo0idD+YK3WBF0OMrt6WceYy5siWYYd
3h/a0Q7P+NR/Co3CTy+bks+wU+oBqFzOqzhfMH/olOXem3DwA4KL5R+POHc6l7ZA
6HewPmI6pfJsT/NNAjRLn8/pCFlIX3BcEhD47UYBJ4oaXlC1HU89dw==
-----END RSA PRIVATE KEY-----


871W(config)#do show crypto key mypubkey rsa
% Key pair was generated at: 04:02:21 SGT May 20 2010
Key name: TP-self-signed-593184536
 Storage Device: private-config
 Usage: General Purpose Key
 Key is not exportable.
 Key Data:
  30819F30 0D06092A 864886F7 0D010101 05000381 8D003081 89028181 00B636CD
  63236065 4243B8A4 6FB3C6CB 3C26214D C152A07F E91558D3 042AEACE 61DA605A
  DFB58A89 7E039325 68B4DDB2 2CEA9D29 DF64B7DB 47AC2EDF 817373C7 B1061E8C
  5DBF5089 FDCB40D6 005B32BA 32705838 A9F97F3D AB377608 411EC0A0 7EBC979C
  10AC0BB5 C66346BF D41819E5 06AFE357 DF9D5F17 BFC72237 E06D27EB 8B020301 0001
% Key pair was generated at: 10:25:14 SGT Mar 9 2014
Key name: TP-self-signed-593184536.server
Temporary key
 Usage: Encryption Key
 Key is not exportable.
 Key Data:
  307C300D 06092A86 4886F70D 01010105 00036B00 30680261 00E56ABA 03F314E3
  DCB0301F 8D89F4FA 8B6423E3 708938A7 B64F1BDE 57B2F464 BE99EB09 70AEEB0C
  6CDF9303 65593F0F 34FAA8A2 685C1538 508E9115 928C76E9 ED683698 C4196DAF
  25AB29AC 7C0E67A5 D91436A2 99D1CB3B 8CE45877 B7D88E62 27020301 0001
% Key pair was generated at: 10:50:03 SGT Mar 9 2014
Key name: VPN-KEY
 Storage Device: not specified
 Usage: General Purpose Key
 Key is exportable.
 Key Data:
  30819F30 0D06092A 864886F7 0D010101 05000381 8D003081 89028181 0099ABE4
  8D2114A1 54530361 6D1E6D94 6184F416 3F0CC1D6 0F3E2277 8D0216DE 58EACB1B
  C4E93580 46F335F9 E6218AFF 11D974BF 9131E084 A7626D59 F01F67BA 31A07EAB
  554810EA B788EC1A 5E9DCF34 3C8A1AF2 6B7AD5C1 D285624A 7C61B1BF 1AC91CC4
  AA4D09C1 442A5394 5858A488 18A2B6E6 50E04714 189B1FA2 17A34DFE 05020301 0001

871W(config)#do sh run | inc ip http   // ENABLE HTTP SERVER FOR CLIENTS TO ENROLL
ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000

871W(config)#crypto pki ?
  authenticate  Get the CA certificate
  certificate   Actions on certificates
  crl           Actions on certificate revocation lists
  enroll        Request a certificate from a CA
  export        Export certificate or PKCS12 file
  import        Import certificate or PKCS12 file
  profile       Define a certificate profile
  server        Enable IOS Certificate server
  token         Configure cryptographic token
  trustpoint    Define a CA trustpoint

871W(config)#crypto pki server ?
  WORD  Certificate Server Name

871W(config)#crypto pki server CA-SERVER   // CREATE PKI SERVER
871W(cs-server)#?
CA Server configuration commands:
  auto-rollover  Rollover the CA key and certificate
  cdp-url        CRL Distribution Point to be included in the issued certs
  database       Certificate Server database config parameters
  default        Set a command to its defaults
  exit           Exit from Certificate Server entry mode
  grant          Certificate granting options
  hash           Hash algorithm
  issuer-name    Issuer name
  lifetime       Lifetime parameters
  mode           Mode
  no             Negate a command or set its defaults
  shutdown       Shutdown the Certificate Server

871W(cs-server)#database ?
  archive   Backup Certificate Server Signing Certificate and Keys
  level     Level of data stored in database
  url       URL the Certificate Server database information will be written to
  username  Database username to access the primary network storage

871W(cs-server)#database url ?
  WORD  URL of primary storage location
  cnm   Storage location for name file (*.cnm)
  crl   Storage location for certificate revocation list (*.crl)
  crt   Storage location for issued certificates (*.crt)
  p12   Storage location for P12 archives (*.p12)
  pem   Storage location for PEM archives (*.pem)
  ser   Storage location for main database files (*.ser)

871W(cs-server)#database url nvram:
% Server database url was changed. You need to move the
% existing database to the new location.
871W(cs-server)#database level ?
  complete  Each issued certificate is saved to the database
  minimum   Minimum certificate info is saved to the database
  names     Certificate serial-number & subject name is saved to the database

871W(cs-server)#database level minimum
871W(cs-server)#issuer-name ?
  LINE  Issuer name

871W(cs-server)#issuer-name CN=lagura.com L=Home C=SG
871W(cs-server)#lifetime ?
  ca-certificate      Lifetime of the Certificate Server signing certificate
  certificate         Lifetime of certificates issued by this Certificate Server
  crl                 Lifetime of CRL's published by this Certificate Server
  enrollment-request  Lifetime of an Enrollment Request

871W(cs-server)#lifetime ca-certificate ?
  <0-1825>  Lifetime in days

871W(cs-server)#lifetime ca-certificate 1825  // 5 YEARS
871W(cs-server)#grant ?
  auto     Automatically grant incoming SCEP enrollment requests
  none     Automatically reject any incoming SCEP enrollment request
  ra-auto  Automatically grant RA-authorized incoming SCEP enrollment request

871W(cs-server)#grant auto
871W(cs-server)#no shut
%Some server settings cannot be changed after CA certificate generation.
% Please enter a passphrase to protect the private key
% or type Return to exit
Password:cisco
% Password must be more than 7 characters. Try again
% or type Return to exit
Password:cisco123

% Generating 1024 bit RSA keys, keys will be non-exportable...[OK]
% Exporting Certificate Server signing certificate and keys...

% Certificate Server enabled.
871W(cs-server)#end

871W#show crypto pki certificates
CA Certificate
  Status: Available
  Certificate Serial Number: 0x1
  Certificate Usage: Signature
  Issuer:
    cn=lagura.com L\=Home C\=SG
  Subject:
    cn=lagura.com L\=Home C\=SG
  Validity Date:
    start date: 11:12:52 SGT Mar 9 2014
    end   date: 11:12:52 SGT Mar 8 2019
  Associated Trustpoints: CA-SERVER

871W#show crypto pki trustpoints status
Trustpoint CA-SERVER:
  Issuing CA certificate configured:
    Subject Name:
     cn=lagura.com L\=Home C\=SG
    Fingerprint MD5: 83F908A6 9E7E0C70 E83BC30F 76BA0762
    Fingerprint SHA1: 8D49A6CB BAE7EFE8 D7A0D8C1 D4AA6599 0F9DE16D
  State:
    Keys generated ............. Yes (General Purpose, non-exportable)
    Issuing CA authenticated ....... Yes
    Certificate request(s) ..... None


I tested my ASA 5505 firewall to join the PKI and added a CA Truspoint via Simple Certificate Enrollment Protocol (SCEP).

871W#sh run | inc ntp
ntp clock-period 17182307
ntp server 203.123.48.6   // PUBLIC SG NTP
871W#show clock
11:22:53.941 SGT Sun Mar 9 2014   


ASA5505# ping 192.168.1.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/6/10 ms
ASA5505# # show clock
17:14:01.949 UTC Sat Mar 8 2014
ASA5505# configure terminal
ASA5505(config)# ntp server ?

configure mode commands/options:
  Hostname or A.B.C.D  IP address of peer
ASA5505(config)# ntp server 192.168.1.1 ?

configure mode commands/options:
  key     Configure peer authentication key
  prefer  Prefer this peer when possible
  source  Interface for source address
  <cr>
ASA5505(config)# ntp server 192.168.1.1 source ?

configure mode commands/options:
Current available interface(s):
  inside   Name of interface Vlan1
  outside  Name of interface Vlan2
ASA5505(config)# ntp server 192.168.1.1 source outside   //  RUN NTP TO CA CLIENT TO SYNC CA CERT
ASA5505(config)# clock timezone ?

configure mode commands/options:
  WORD < 8 char  name of time zone
ASA5505(config)# clock timezone SGT 8
ASA5505(config)# show clock
11:24:05.533 SGT Sun Mar 9 2014
ASA5505(config)# show ntp status
Clock is synchronized, stratum 4, reference is 192.168.1.1
nominal freq is 99.9984 Hz, actual freq is 99.9984 Hz, precision is 2**6
reference time is d6c65d72.229a9871 (11:24:34.135 SGT Sun Mar 9 2014)
clock offset is 1.2502 msec, root delay is 108.67 msec
root dispersion is 3928.02 msec, peer dispersion is 3890.64 msec


Below are the screenshots in ASDM to configure NTP and add CA Certificates. Notice the Issued By and Expiry Date on the CA certificate details matched the CA server fields configured on the 871w router.