Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

84
Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck

Transcript of Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Page 1: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Packet AnalysisFluke Protocol Expert & Misc

Applications

Brian D. Sterck

Page 2: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Where to find your updates

Page 3: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Promotions Page for CiscoNA

Page 4: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Promotions Page for CiscoNA

Page 5: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Beginning the Installation

Page 6: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Readme File contains passwordLaunching OPV-PE======================

Login and Password-----------------------A valid, case sensitive, user name and password is required to launch OPV-PE software. The password for the defaultsuper user is shown below. The passwords for these users should bechanged after the first launch of OPV-PE. To change the defaultpassword for these users, or create new users, choose the menuitem Host>Access Privileges>User Manager, highlight the first userand click "Modify". Enter a new password for the following users.

User Name: su Password : manager (hidden)

User Name: guest Password : public (hidden)

**Note: A checkbox is provided to select a default User Name (not password) for easier Login.

Page 7: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Initial Login Screen

Page 8: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Capture and Monitoring Mode(Opening View)

Page 9: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

NIC Description

Page 10: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Secondary NIC Description

Page 11: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Hide Resource BrowserRename Network Adapters

Page 12: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

System Settings

Page 13: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Module Settings

Page 14: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Monitor View Preferences

Page 15: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Expert Configuration

Page 16: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Host Table

Page 17: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Protocol Distribution

Page 18: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

MAC Statistics

Page 19: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Size Distribution

Page 20: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Name Table

Page 21: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Remote vs. Local

Page 22: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Expert View – Symptoms Overview

Page 23: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Expert View – Symptoms Overview

Page 24: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Expert View – Transport Symptoms

Page 25: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Expert View – Network Symptoms

Page 26: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Expert View – Session Anaysis

Page 27: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Expert View – Transport Entities

Page 28: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Host, Network, App Matrix

Page 29: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Display Filter

Page 30: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Capture Filter

Page 31: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Stopping the Capture

Page 32: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Capture View

Page 33: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Buffer Limit with Education Version

Page 34: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Viewing Captured Frames

Page 35: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Viewing Captured Frames (Cont.)

Page 36: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.
Page 37: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.
Page 38: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

MAC Address – Source & Destination

Page 39: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Change Capture View to Include Network Address

Page 40: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Capture View with L3 Addressing

Page 41: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Telnet Capture

Page 42: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Username? Interesting…

Page 43: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Display Filter to Remove Clutter

Page 44: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Username Capture

Page 45: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Return of Keystroke by Switch

Page 46: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Sending ‘l’ keystroke

Page 47: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Sending ‘u’ keystroke

Page 48: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Sending ‘k’ keystroke

Page 49: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Sending ‘e’ keystroke

Page 50: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Actual Terminal of User

Page 51: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Password Prompt sent by Switch

Page 52: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Passwords Are Not Echoed By Cisco Switch (1st Char = ‘t’)

Page 53: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

2nd Char = ‘e’

Page 54: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

3rd Char = ‘S’

Page 55: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

4th Char = ‘t’

Page 56: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

5th Char = ‘P’

Page 57: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

6th Char = ‘a’

Page 58: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

7th Char = ‘s’

Page 59: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

8th Char = ‘s’

Page 60: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

9th Char = ‘!’

Page 61: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Switch Prompt is Displayed

Page 62: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Capture of Show Run Output

Page 63: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.
Page 64: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Fluke Password in Config

Page 65: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Http://www.astalavista.netAdvanced Security Member Portal

Page 66: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Advanced Security Member PortalTools Database

Page 67: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Get Pass

Page 68: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Hex Reveals Lowercase and Uppercase Difference

Page 69: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Unload Display Filter

Page 70: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Protocol Distribution for ACL Design

Page 71: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

ACL influenced byProtocol Distribution

HOMEOFFICE831(config)#ip access-list extended TESTACLHOMEOFFICE831(config-ext-nacl)#permit tcp 192.168.111.0 0.0.0.255 any eq 119HOMEOFFICE831(config-ext-nacl)#permit tcp 192.168.111.0 0.0.0.255 any eq 80HOMEOFFICE831(config-ext-nacl)#permit tcp 192.168.111.0 0.0.0.255 any eq 3389HOMEOFFICE831(config-ext-nacl)#permit tcp 192.168.111.0 0.0.0.255 any range 5631 5632HOMEOFFICE831(config-ext-nacl)#permit udp 192.168.111.0 0.0.0.255 any range 5631 5632HOMEOFFICE831(config-ext-nacl)#permit tcp 192.168.111.0 0.0.0.255 any eq 25HOMEOFFICE831(config-ext-nacl)#permit tcp 192.168.111.0 0.0.0.255 any eq 110HOMEOFFICE831(config-ext-nacl)#permit udp 192.168.111.0 0.0.0.255 any eq 53HOMEOFFICE831(config-ext-nacl)#permit icmp any any echoHOMEOFFICE831(config-ext-nacl)#permit icmp any any echo-HOMEOFFICE831(config-ext-nacl)#permit icmp any any echo-replyHOMEOFFICE831(config-ext-nacl)#permit icmp any any echo-reply unreaHOMEOFFICE831(config-ext-nacl)#permit icmp any any echo-reply unreachable

Page 72: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Etherpeek User Capture

Page 73: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Etherpeek Password Capture

Page 74: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Etherpeek Filters

Page 75: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.
Page 76: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Ethereal

• To get up and running with Ethereal, you will need to download and install Ethereal, and will also need to download and install WinPcap if you plan to capture packets with Ethereal. If you don't install WinPcap, you will not be able to capture packets with Ethereal!

Page 77: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Ethereal Interface Capture

Page 78: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Begin Capture (Ethereal)

Page 79: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Capture Buffer (Ethereal)

Page 80: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Filtering with Ethereal

Page 81: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Ethereal Password Capture

Page 82: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Follow TCP Stream

Page 83: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Follow TCP Stream (Cont.)

Page 84: Packet Analysis Fluke Protocol Expert & Misc Applications Brian D. Sterck.

Questions?