In this video, we take a look at how EEM scripts can be utilized alongside Low Impact mode to enable ports to fail open.
Below are EEM Scripts that can be reused and modified for your environment.
Note: For single RADIUS Servers use the “%RADIUS-4-RADIUS_DEAD” syslog pattern and for a group of RADIUS servers use the “%RADIUS-3- ALLDEADSERVER” syslog pattern.
If your devices utilize command authorization then you need to ensure that the script can still run in the event of a failure. Enter the following command at the end of each applet to ensure command authorization is bypassed.
In this article we are going to take a look at how to capture Extensible Authentication Protocol Over LAN (EAPOL) and Remote Authentication Dial-In User Service (RADIUS) packets using Wireshark. This article can be useful for troubleshooting 802.1x within your environment and can also be used for learning purposes. The following topology has been used to gather the required output for this article. Note: This article will only cover the switch configurations that are required to gather EAPOL and RADIUS configuration. Overview of the Topology The supplicant is configured to perform 802.1x using EAP-TLS as the authentication method The user certificate on the supplicant will be used for authentication The supplicant has Wireshark installed Cisco ISE is used for authentication and authorisation The supplicant is assigned to VLAN 10 upon authentication and all other endpoint ports are assigned to VLAN 99 Sniffer device is running Wireshark in order to capture RADIUS flows via SPAN 802.1x ...
There comes a point in every engineers life where you find yourself having to load software onto a Cisco switch. More often than not we find ourselves doing this in 2019 to Cisco switches that are now used for labbing or even on Cisco switches that are still used in a production environment. The problem I’ve seen is that, we (as engineers) have some much to remember, we often forget the little things or better yet, we lose the skills we don’t use but fear not, this article hopes to bring back at least one of those skills! Whether a switch is corrupted with the wrong image or you’ve simply purchased a switch that doesn’t have a software image loaded, there isn’t a way to provide IP connectivity in order to load a new image so we have to do things a slightly different way…and that way is XMODEM. Now I’m not going to jump into the details of this ancient protocol because no doubt if you’re an engineer you’ll know all about it right 😉 but I will provide a link to more details on xmodem fo...
Hot Standby Router Protocol (HSRP) is a Cisco propitiatory router protocol that provides first-hop redundancy for IP hosts on a LAN. It enables a set of router interfaces once configured to present a single virtual default gateway for IP hosts on the LAN. HSRP has two modes: ACTIVE – Physical router acts as the main router, by default the highest IP Address is elected the active router STANDBY – The second physical router that participates in HSRP and becomes the active router when the elected active router fails HSRP priorities can be used to determine the active router. The default priority is 100 HSRP versions: The default version used for Cisco IOS 15 is Version 1 Version 2 expands the number of supported groups from 0-255 in version 1 to 0-4095 Version 2 also supports IPv6 HSRPv1 uses Multicast address 224.0.0.2 HSRPv2 uses Multicat address 224.0.0.102 for IPv4 and FF02::66 for IPv6 HSRPv2 adds support for MD5 authentication HSRP virtual MAC addresses: Along with virtual IP addr...
In this article I will explain demultiplexing and how it works by walking through a .pcap file taken from the lab in the screenshot below. We will focus on the data flowing from PC1 and SW1 to R1’s ingress port. Demultiplexing (DEMUX) is the method in which the TCP/IP stack uses to determine if datagrams have been received correctly and if so, how should they be processed. Demultiplexing looks at certain fields at each layer of the TCP/IP stack, these fields include MAC addresses, IP addresses, protocols and ports. Checksums are also accounted for to verify the datagram hasn’t been damaged during transit. Physical I sent a DHCP request from PC1 into the network and captured the request on the Gigabyte interface connecting SW1 and R1, we will use the DISCOVER .pcap file to walk through demultiplexing. As shown in figure .1 , the Ethernet frame enters the ingress interface of R1 from PC1. We have lots of information to accompany the datagram but our main focus is the Encaps...
In this article, I want to point out something that could save you time in the future and potentially save you a TAC case. Note: This article is perfect for environments where you wish to keep the same password for local user accounts. The Cisco Identity Services Engine (ISE) comes packed with many good features, some of which include handy default security features for local user accounts and in this article, I will touch on one of those features. By default, Cisco ISE will disable local user accounts after 60 days if the account passwords haven’t been changed. This behaviour can be changed within ISE but if you choose not to change this setting and you surpass the 60 days all user account will need to be re-enabled every 24-hours. Luckily ISE will allow you to disable this setting without having to change all the passwords for the local users, to do this follow the steps below. Log into ISE using the GUI Navigate to Administration >>> Identity Management >>>...