Skip to main content

Fun With Wireshark: Packet Analysis and Ethical Hacking Part 3: Troubleshooting




Here is the part you want to see - Troubleshooting!


Question: Do trunks form between SW1 / SW2 and SW2 / S3?

Remember: VLAN trunks are the highway that every bit of information can pass upon, no matter what VLAN it came from. When the VLAN frame gets closer to its destination, it will travel on roads only avaliable for that VLAN.

The packets for SW1/2 so far show DTP and PAgP. Now, PAgP is Cisco-proprietary Etherchannel, but DTP is for trunking negotiation between switches.

Wait!




Clicking the packet and reading the drop-down for Dynamic Trunk Protocol:


This is SW1

SW2 has similar output.

" Dynamic Auto" = Our side will negotiate with the other side, whatever that is.
"Access" = No VLAN tagging, trunk won't be formed.

Essentially: "We can talk about the possibility of trunking, but I'm waiting for you to make a move about trunking", except they say that to each other.

It's the IT equivalent of a middle school dance.

What about SW2/SW3? That's for you to buy the course and find out.


Next is CDP (Cisco Discovery Protocol) & LLDP (Link layer Discovery Protocol). I check the VTP domain, software version, and other things.

Fun fact: You can see what a device is capable of;



The entire troubleshooting section is looking at packets to glean information; If I can't figure out the information from the questions presented, I'll show you what I had to receive the answer to. Otherwise, I'm showing you most of the course.


OSPF


Routing protocols are prioritized over other traffic types.

One question was "What protocol is OSPF using" It's an Interior Gateway Protocol




And protocol # 89!

There are more passwords in clear text. Don't do it!

DR and BDR can be found in the Hello packet information on said Hello Packet. DRs (Designated Router) and BDRs(Backup Designated Router) are dictated by a set OSPF Router priority. Highest number wins, 0 sits out of the game.

OSPF does not use TCP, instead it has it's own mechanism to communicate and makes sure that data gets through.

Make sure the area numbers are the same, or the OSPF routers will not become neighbors.

They must also share the same subnet mask on interfaces that wish to neighbor.

One of the routers sets itself as a backup designated router...how does that work in the real world? Does it work? I feel it could if you had two NIC cards and one would just pick up the slack.

EIGRP


EIGRP has K values, used to scale numbers in the metric calculation of finding the best route.
https://tools.ietf.org/html/rfc7868#section-5.5

They must match for routes to be shared.

K1 and K3 are defaults. The Authentication is in MD5 - Not plain text!

Check the routes being advertised:




BGP


BGP Identifiery = Router ID

Fun Fact - Autonomous Systems for BGP are reserved, much like port numbers. Each one used here is reserved for Private use.


https://www.inetdaemon.com/tutorials/internet/ip/routing/bgp/autonomous_system_number.shtml

https://en.wikipedia.org/wiki/Autonomous_system_%28Internet%29#Assignment.

Using the filters are especially helpful here. Type in
bgp.
And check out the many options.

How was a certain route learned? Through IGP.

Comments

Popular posts from this blog

Making KPI Dashboards with PowerBI

 While this is the free tier, I cannot share or collaborate with others, nor can I publish content to other people's workspaces, but they will not stop me from screenshooting and recording these self-taught adventures,so! I'm doing this because I idly searched "Mattel careers" and "Information Technology", and seeing a bulletpoint saying the following: Analytical and reporting skills such as creating dashboards and establishing KPIs such as experience with PowerBI, Cognos, Tableau, and Google Data Lake/AWS is preferred And thought "Well, I've used Tableau, and I've heard about PowerBI,  even if its in-demandness is questionable , so how similar is it? And can I write about it?"  First, PowerBI (PIB) does have a downloadable, local version, but apparently Windows-only. I could download the .exe but I couldn't run it / drag it to applications on my MacBook.  Not a problem, we'll use the online SaaS version, and a dataset found here, ...

A 2-week Trial of T-Mobile Home Internet

     The Xfinity app showed usage of the past 3 months: We used less than 40% each month, for about $80 USD a month.   No thanks! That cuts into the movie budget! Before we save some money (about $15/mo), let's test how T-Mobile Internet unlimited data works for 2 weeks.    There are 15 devices for this test; Smart TVs: 4 Laptops: 4 Printer: 1 Smart Home Speakers: 3 Game Consoles: 1 Phones: 1 (There are other phones in the home but they stick with data) Other: 1 Total : 15  I made tables for 3 entries a day across 3 days to test the Xfinity service we have. Here's one;   Xfinity is pretty speedy - Download times are between 227 - 236 Mbps, Latency between 24.5 - 25.5, Jitter between 5 - 6.68, and 0 packet loss.  Let's quickly define the terms in the table;    Date/Time - The date and time of the data gathered. Download (Mpbs) - How fast your network gets data. Upload (Mbps) - How fast your network uploads data. Latency ...

Recon and SSID - Mapping With VisiWave Site Survey

My laptop is refurbished. I've written about how there are a few ... quirks. Being a technology professional, I felt okay with adopting an older machine, knowing I had the skill to fix moderate issues. From dying drivers to monitor massacres, I've ID'd, solved, and documented a lot of issues.  The newest one was my Wi-Fi adapter dropping the connection to a specific extender. While troubleshooting, I was curious about doing recon of WiFi networks and broadcasting devices anyway. That issue? A power setting. It was so determined to save power, it would disconnect. The extender is also flirting with the older end of 6 years old.  The battery needs to be replaced, but that's new to me. As a Windows laptop, there are a plethora of options to pick. How do you decide which one is safest?  I am suddenly concerned about this despite having 3 unofficial, 15$ Macbook Air chargers from eBay, and no explosions. But let's move onto the Site Survey - Where can I find the stronges...