FlowViewer / SiLK handles IPv6. Web-based, graphical tracking and analysis. Free. http://sourceforge.net/projects/flowviewer/ http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst3850/software/release/3se/flexible_netflow/configuration_guide/b_fnf_3se_3850_cg/b_fnf_3se_3850_cg_chapter_010.html#reference_A9019899140647F2B3F87ABABCFC170D http://qosient.com/argus/

Continue reading Netflow viewers

In order to keep the same interfaces indexes, the only way to achieve that easily is moving the nvram:ifIndex-table from the old SUP to the new SUP. This document says that the file can be downloaded and viewed: http://www.cisco.com/c/en/us/support/docs/ip/simple-network-management-protocol-snmp/28420-ifIndex-Persistence.html   Procedure: Old SUP: #copy nvram:ifIndex-table disk0: New SUP: #delete nvram:ifIndex-table #copy disk0:ifIndex-table nvram: #reload

Continue reading Cisco IOS sup-720 SNMP

MAC bindings In the IPv4 world, the DHCP server allocates IPv4 addresses and thereby stores the MAC addresses of the clients. In the IPv6 world, if SLAAC (autoconfiguration) is used, no network or security device per se stores the binding between the MAC (layer 2) and the IPv6 (layer 3) addresses from the clients. That is, a subsequent …

Continue reading IPv6 security

Link ASA OS MIB ondersteuning Result of the command: “show snmp-server oidlist” ————————————————- [0] 1.3.6.1.2.1.1.1. sysDescr [1] 1.3.6.1.2.1.1.2. sysObjectID [2] 1.3.6.1.2.1.1.3. sysUpTime [3] 1.3.6.1.2.1.1.4. sysContact [4] 1.3.6.1.2.1.1.5. sysName [5] 1.3.6.1.2.1.1.6. sysLocation [6] 1.3.6.1.2.1.1.7. sysServices [7] 1.3.6.1.2.1.1.8. sysORLastChange [8] 1.3.6.1.2.1.1.9.1.2. sysORID [9] 1.3.6.1.2.1.1.9.1.3. sysORDescr [10] 1.3.6.1.2.1.1.9.1.4. sysORUpTime [11] 1.3.6.1.2.1.2.1. ifNumber [12] 1.3.6.1.2.1.2.2.1.1. ifIndex [13] 1.3.6.1.2.1.2.2.1.2. ifDescr …

Continue reading Cisco ASA SNMP

ipv6 inspect routing-header ipv6 inspect max-incomplete low 100 ipv6 inspect max-incomplete high 300 ipv6 inspect one-minute low 100 ipv6 inspect one-minute high 300 ipv6 inspect udp idle-time 60 ipv6 inspect tcp idle-time 1200 ipv6 inspect tcp finwait-time 8 ipv6 inspect tcp synwait-time 60 ipv6 inspect tcp max-incomplete host 100 block-time 1 ! interface dialer X …

Continue reading Cisco IPv6 IOS firewall

ipv6 unicast-routing ipv6 cef ! interface dialer 1 ipv6 address A:B:C:3::1/64 ! interface BVI1 ipv6 address A:B:C:1::1/64 ipv6 enable ipv6 nd managed-config-flag ipv6 nd other-config-flag ipv6 nd router-preference High ipv6 dhcp server LAN rapid-commit ! ipv6 dhcp pool LAN address prefix A:B:C:1::/64 dns-server A:B::C domain-name ipv6.org information refresh 0 12

Continue reading Cisco IPv6 config (met DHCP)

Handige site om de SSL sessie te onderzoeken en testen: https://www.ssllabs.com/ssltest/analyze.html Windows 2008r2 SSL Schannel  

Continue reading SSL test