Differences
This shows you the differences between two versions of the page.
Both sides previous revision Previous revision Next revision | Previous revision | ||
cisco [2006/01/31 13:45] 212.18.42.18 |
cisco [2015/05/21 15:01] (current) zagi [Cisco config tips] |
||
---|---|---|---|
Line 1: | Line 1: | ||
====== Cisco stuff on need to know bases ====== | ====== Cisco stuff on need to know bases ====== | ||
- | ==== Related documents ==== | + | see also: **[[cisco: |
+ | |||
+ | |||
+ | ==== Related documents ==== | ||
+ | [[http:// | ||
[[http:// | [[http:// | ||
[[http:// | [[http:// | ||
Line 10: | Line 14: | ||
Cisco pppoe [[http:// | Cisco pppoe [[http:// | ||
Password recovery[[http:// | Password recovery[[http:// | ||
+ | [[http:// | ||
==== Password reset and configuration reset ==== | ==== Password reset and configuration reset ==== | ||
Line 50: | Line 55: | ||
login | login | ||
password xxx | password xxx | ||
+ | | ||
+ | | ||
+ | === Corrupt/ | ||
+ | |||
+ | * set BAUD 115200 | ||
+ | * upload vix Xmodem | ||
+ | |||
+ | ==== Cisco security tips ==== | ||
+ | **Disable: | ||
+ | |||
+ | * BOOTP server | ||
+ | * Cisco Discovery Protocol (CDP) | ||
+ | * HTTP Configuration and Monitoring | ||
+ | * Domain Name System (DNS) | ||
+ | * Packet Assembler / Disassembler (PAD) | ||
+ | * Internet Control Message Protocol (ICMP) Redirects | ||
+ | * IP Source Routing | ||
+ | * Finger Service | ||
+ | * Proxy ARP | ||
+ | * IP Directed Broadcast | ||
+ | |||
+ | ==== Cisco config tips ==== | ||
- | ==== Cisco tips ==== | + | ** Cisco PIX *** |
+ | no fixup protocol smtp 25 | ||
**General security template:** | **General security template:** | ||
Line 91: | Line 119: | ||
ip cef | ip cef | ||
- | **NTP** | + | **NTP** |
clock timezone CET 1 | clock timezone CET 1 | ||
clock summer-time CEST recurring last Sun Mar 2:00 last Sun Oct 3:00 | clock summer-time CEST recurring last Sun Mar 2:00 last Sun Oct 3:00 | ||
Line 211: | Line 239: | ||
router bgp 109 | router bgp 109 | ||
neighbor 145.2.2.2 remove-private-AS | neighbor 145.2.2.2 remove-private-AS | ||
+ | |||
+ | ==DHCP== | ||
+ | ip dhcp excluded-address 192.168.10.1 | ||
+ | ip dhcp pool my.lan | ||
+ | | ||
+ | | ||
+ | | ||
+ | | ||
+ | lease 14 0 | ||
**OSPF** | **OSPF** | ||
Line 224: | Line 261: | ||
| | ||
+ | == ACL renumbering == | ||
+ | |||
+ | Router(config)# | ||
+ | |||
+ | == vlan up/ | ||
+ | |||
+ | no autostate | ||
+ | no keepalive | ||
+ | |||
+ | == Wireless == | ||
+ | dot11 ssid TEST1 | ||
+ | mbssid guest-mode | ||
+ | |||
+ | dot11 ssid TEST2 | ||
+ | mbssid guest-mode | ||
+ | |||
+ | Then you have to enable mbssid globally on your radio-interface: | ||
+ | |||
+ | interface Dot11Radio0 | ||
+ | mbssid | ||
+ | ssid TEST1 | ||
+ | ssid TEST2 | ||
+ | | ||
+ | interface Dot11Radio1 | ||
+ | mbssid | ||
+ | ssid TEST1 | ||
+ | ssid TEST2 | ||
+ | | ||
+ | ==== Cisco bash policer script ==== | ||
+ | |||
+ | <code bash> | ||
+ | #!/bin/bash | ||
+ | # tnt.aufbix.org | ||
+ | # | ||
+ | cir=$(($1*1024*1000)) | ||
+ | nburst=$(($cir*3/ | ||
+ | eburst=$(($nburst*2)) | ||
+ | echo " | ||
+ | echo "class class-default" | ||
+ | echo " | ||
+ | |||
+ | </ | ||