networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 18 posts ] 
Author Message
 Post subject: Lock-and-Key Security
PostPosted: Mon Apr 04, 2011 1:35 pm 
Offline
Site Admin
Site Admin
User avatar

Joined: Mon Dec 06, 2004 6:46 pm
Posts: 10310
Location: McKinney, TX
Certs: CCNA
Comments for Lock-and-Key Security.

_________________
Find networking-forum.com on Facebook, LinkedIn, Twitter, Google+,or subscribe to the site's RSS feeds.


Top
 Profile  
 
PostPosted: Mon Apr 04, 2011 1:56 pm 
Offline
Cisco Inferno
Cisco Inferno
User avatar

Joined: Mon Jul 10, 2006 12:58 am
Posts: 10201
Location: Seattle
Nice blog, Infinite!

I had never even heard of that feature, and couldn't really think of a useful situation in which to deploy it (other than perhaps some insane Rube Goldberg Machine of networks), yet it's still pretty cool that it's out there.

_________________
Reasonably un-nerdy blog:
americanwerewolfinbelgrade.wordpress.com/


Top
 Profile  
 
PostPosted: Mon Apr 04, 2011 1:58 pm 
Offline
Cisco Inferno
Cisco Inferno
User avatar

Joined: Mon Jul 10, 2006 12:58 am
Posts: 10201
Location: Seattle
Which reminds me... why haven't we at networking-forum come up with some insane Rube Goldberg Machine of networks?

_________________
Reasonably un-nerdy blog:
americanwerewolfinbelgrade.wordpress.com/


Top
 Profile  
 
PostPosted: Mon Apr 04, 2011 2:30 pm 
Offline
Moderator
Moderator
User avatar

Joined: Mon Apr 07, 2008 10:38 am
Posts: 9390
Location: Orlando, FL
Certs: CCNP RS, CCNP DC, CCDP, CCIP
Nice post. The transparency in your screenshots makes me hate you though.

_________________
http://blog.alwaysthenetwork.com


Top
 Profile  
 
PostPosted: Mon Apr 04, 2011 2:43 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Mon Jan 17, 2005 11:01 pm
Posts: 5148
Location: Canada eh
Certs: 350-001, CCNP, CXFF, ITILv3F
Thanks guys.

Yeh I noticed the transparency bit after I finished and couldn't be bothered to take them all over again. On the machine I'm on now I can't even see them... But I know on some you can see through them. Blame Apple. It's their terminal program.

_________________
blog.brokennetwork.ca


Top
 Profile  
 
PostPosted: Mon Apr 04, 2011 2:47 pm 
Offline
Moderator
Moderator
User avatar

Joined: Mon Apr 07, 2008 10:38 am
Posts: 9390
Location: Orlando, FL
Certs: CCNP RS, CCNP DC, CCDP, CCIP
I keep trying to figure out what's behind them.

_________________
http://blog.alwaysthenetwork.com


Top
 Profile  
 
PostPosted: Mon Apr 04, 2011 2:48 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Mon Jan 17, 2005 11:01 pm
Posts: 5148
Location: Canada eh
Certs: 350-001, CCNP, CXFF, ITILv3F
I think it was another terminal window or the OpenOffice document I drafted the blog post in.

_________________
blog.brokennetwork.ca


Top
 Profile  
 
PostPosted: Mon Apr 04, 2011 2:53 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Mon Jan 17, 2005 11:01 pm
Posts: 5148
Location: Canada eh
Certs: 350-001, CCNP, CXFF, ITILv3F
ibarrere wrote:
Which reminds me... why haven't we at networking-forum come up with some insane Rube Goldberg Machine of networks?

Did you not see Steve's Creative Routing Contest?

_________________
blog.brokennetwork.ca


Top
 Profile  
 
PostPosted: Mon Apr 04, 2011 4:34 pm 
Offline
Cisco Inferno
Cisco Inferno
User avatar

Joined: Mon Jul 10, 2006 12:58 am
Posts: 10201
Location: Seattle
Yeah, I thought I saw something about a Catalyst in one of the background windows...

That creative routing contest is pretty cool. But, we definitely need to include hosts that sit there listening and slicing packets in half and forwarding some data to one location, some to another, eventually the packet will be reconstructed on another host who'll insert the payload into a database and have an ETL chew it up and return something else to a SOAP API, blah blah blah. I think the end result should be posting a topic to this forum though.

_________________
Reasonably un-nerdy blog:
americanwerewolfinbelgrade.wordpress.com/


Top
 Profile  
 
PostPosted: Mon Apr 04, 2011 4:53 pm 
Offline
Cisco Inferno
Cisco Inferno
User avatar

Joined: Mon Jul 10, 2006 12:58 am
Posts: 10201
Location: Seattle
ibarrere wrote:
we definitely need to include hosts that sit there listening and slicing packets in half and forwarding some data to one location, some to another, eventually the packet will be reconstructed on another host who'll insert the payload into a database and have an ETL chew it up and return something else to a SOAP API, blah blah blah. I think the end result should be posting a topic to this forum though.


That sounds startlingly like the standard application logic of a former customer, actually.

_________________
Reasonably un-nerdy blog:
americanwerewolfinbelgrade.wordpress.com/


Top
 Profile  
 
PostPosted: Mon Apr 04, 2011 5:08 pm 
Offline
Post Whore
Post Whore
User avatar

Joined: Wed Feb 10, 2010 2:45 am
Posts: 1639
Location: Arizona
Certs: CCNA
Nice Blog! That's a cool feature I would have never probably know about otherwise.


Top
 Profile  
 
PostPosted: Tue Apr 05, 2011 3:10 am 
Offline
CCIE #38070
CCIE #38070
User avatar

Joined: Wed Jun 18, 2008 7:49 am
Posts: 12433
Location: London, UK
Certs: CCIE ,CC-NP/IP, JNCIP-SP, JNCIS-ENT, BC-/SPNE/NP
Interesting. Not sure I'd ever use it though

_________________
www.mellowd.co.uk/ccie/


Top
 Profile  
 
PostPosted: Tue Apr 05, 2011 4:32 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Tue Mar 31, 2009 4:15 pm
Posts: 4439
Location: South Florida
Certs: More than none
Very cool blog Infinite. The technology kind of reminds me of port-knocking.

_________________
"See packet, be packet, you are packet. Ignore all else!" -The Networker
packetsdropped.wordpress.com


Top
 Profile  
 
PostPosted: Tue Apr 05, 2011 5:28 am 
Offline
Senior Member
Senior Member

Joined: Sat May 06, 2006 4:00 pm
Posts: 350
Location: Sweden
Certs: CCIE #37149 , CCNP, CCDA
Can this be combined with time-based ACL? Like allowing someone to open a port at certain times but only if they know the password?

_________________
http://lostintransit.se


Top
 Profile  
 
PostPosted: Tue Apr 05, 2011 9:11 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Mon Jan 17, 2005 11:01 pm
Posts: 5148
Location: Canada eh
Certs: 350-001, CCNP, CXFF, ITILv3F
Interesting idea... I don't know. I'll have to try and lab that if I get some free time today.

_________________
blog.brokennetwork.ca


Top
 Profile  
 
PostPosted: Tue Apr 05, 2011 10:22 am 
Offline
Post Whore
Post Whore
User avatar

Joined: Mon Jan 17, 2005 11:01 pm
Posts: 5148
Location: Canada eh
Certs: 350-001, CCNP, CXFF, ITILv3F
reaper: Yes.
Code:
R1#sh access-list 101
Extended IP access list 101
    10 Dynamic LOCK permit tcp any any eq telnet time-range LOCK (inactive)
    20 permit tcp any host 1.1.1.1 eq telnet (50 matches)
    30 deny ip any any
R1#sh tim
R1#sh time-range
time-range entry: LOCK (inactive)
   periodic weekdays 9:20 to 9:30
   used in: IP ACL entry
R1#sh clock
09:17:12.667 MST Tue Apr 5 2011

Code:
R2#telnet 1.1.1.1
Trying 1.1.1.1 ... Open


User Access Verification

Username: test
Password:
[Connection to 1.1.1.1 closed by foreign host]
R2#telnet 3.3.3.3
Trying 3.3.3.3 ...
% Destination unreachable; gateway or host down

R2#

Code:
R1#sh access-list 101
Extended IP access list 101
    10 Dynamic LOCK permit tcp any any eq telnet time-range LOCK (inactive)
       permit tcp any any eq telnet time-range LOCK (inactive)
    20 permit tcp any host 1.1.1.1 eq telnet (72 matches)
    30 deny ip any any (1 match)
R1#sh clock
09:19:59.019 MST Tue Apr 5 2011

Code:
R1#sh access-list 101
Extended IP access list 101
    10 Dynamic LOCK permit tcp any any eq telnet time-range LOCK (active)
       permit tcp any any eq telnet time-range LOCK (active)
    20 permit tcp any host 1.1.1.1 eq telnet (72 matches)
    30 deny ip any any (1 match)
R1#sh clock
09:21:37.151 MST Tue Apr 5 2011

Code:
R2#telnet 3.3.3.3
Trying 3.3.3.3 ... Open


User Access Verification

Username: test
Password:
R3>

_________________
blog.brokennetwork.ca


Top
 Profile  
 
PostPosted: Tue Apr 05, 2011 11:14 am 
Offline
Senior Member
Senior Member

Joined: Sat May 06, 2006 4:00 pm
Posts: 350
Location: Sweden
Certs: CCIE #37149 , CCNP, CCDA
Cool, thanks for testing that out. Maybe when my kid gets older I'll have to stop him from playing WoW all night long. Then I can implement a time-based lock and key ACL and change the password on occasion and make him find it out through doing some math or something :)

Devious plans...:)

_________________
http://lostintransit.se


Top
 Profile  
 
PostPosted: Wed Dec 14, 2011 7:35 pm 
Offline
New Member
New Member

Joined: Thu Dec 08, 2011 11:52 pm
Posts: 1
Certs: nope
It is obvious that I really want to be part of your site. I really love how you make people to have an interest in your site which helps me a lot. Thank you so much for this.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 18 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group