1 / 6100%
Running Head: ROUTERS SECURITY FUNDAMANTALS 1
Network Security– CIS 311
Professor Andy Hinton
July 2nd, 2017
Routers Security fundamentals
Assignment - Week 4
Ayao Bocomehounou
ROUTERS SECURITY FUNDAMANTALS 2
Provide the definition for Access Control Lists (ACL) and how they are used on
servers and on a network. Explain any similarities and differences in how ACLs
are used. Research and describe at least two outside references that discusses
ACLs and their use for security.
Whether at home or in an organization, the use of routers is commonly known. A router
plays an important role on a network system environment. It is a device that forward
packets of data choosing the best way possible to a destination. It connects networks. It
acts as a dispatcher when sending information. It is one of the most targeted devices on
a network system. To protect the information, routers use access control lists as way to
control the flow of traffic data.
Router Access control lists (ACL) filter network traffic by controlling whether routed
packets are forwarded or blocked at the router's interfaces. . It provides traffic-flow
control and enhances network security. Furthermore, it is used to fine performance and
control client access to sensitive network segments. There are many type of ACL
depending on the use and rules. They are standard ACLs and extended IP ACLs. While
the standard ACLs offer minimal configuration options, the extended ACLs offer more
filtering options.
ROUTERS SECURITY FUNDAMANTALS 3
Reference:
http://www.cisco.com/c/en/us/td/docs/ios/12_2/security/configuration/guide/fsecur_c/scf
acls.html
http://www.cisco.com/c/en/us/support/docs/ip/access-lists/26448-ACLsamples.html
ROUTERS SECURITY FUNDAMANTALS 4
Provide an example of how a packet travels from a host computer and is routed
by a router. You should provide a basic overview of what steps are involved in the
routing of the packet to its final destination.
Routers use the IP layer (layer 3) and switches use the data-link layer (layer 2). Layer 1
is the physical 1s and 0s that go over a wire, Layer 2 is the data-link layer, which is
protocols like Ethernet and Point-To-Point Protocol (PPP), which carries information
between adjacent nodes about MAC address from and to and allows for error detection
and retransmission. Layer 3 is the IP layer, which carries information about where in the
whole network the packet is from and to, not just the current hop.
The transmission would go like this:
Machine A wants to send a packet to Machine B. Machine A knows Machine B's IP
address, so it places that in the layer 3 packet. Machine A needs to place the MAC
Address of the next hop in the layer 2 packet, however. If it does not know, then it will
send something called an ARP request (Address Resolution Protocol, read here:
http://www.tildefrugal.net/tech/arp.php to the network, with the destination IP. One of a
few things will happen. For one, the IP is local. The machine with that IP will reply back
to the sender with its MAC address. Or the IP is non-local. The gateway router will
detect this and send its MAC address.
Another option is that the IP is non-local and Machine A's default gateway and subnet
mask are set. Using this information Machine A can determine the non-locality of the IP
address and send it to the router's MAC address (ARPing if not known yet).
ROUTERS SECURITY FUNDAMANTALS 5
(If Machine A found this out earlier, it will be in the ARP cache and Machine A will just
use that.) Now that the MAC address is sent, the packet can be transferred (the
physical layer 1 performing the actual transfer of data on the wire). The next stop will be
the switch. The switch knows which outbound port the MAC address listed as the layer
2 destination is on, because it tracks every MAC address it's seen a packet come from
and which port it came on - if it does not know, then it will flood it out every single port,
guaranteeing it'll arrive.
As such, the packet arrives at the router. The cool thing about the IP model is that it
divides every single IP address in the network/world into a hierarchy - Subnets by
definition cannot overlap subnets partially, they either wholly contain them or are wholly
contained by them. So as long as subnets follow this hierarchy, the router can
unambiguously determine where each of the 4 billion possible IP addresses are on the
network just by looking at what subnet the IP will fall under in its table! The packet is
then sent out that port.
Reference:
https://web.archive.org/web/20120129120350/http://www.tildefrugal.net/tech/arp.php
http://en.wikipedia.org/wiki/Data_link_layer
ROUTERS SECURITY FUNDAMANTALS 6
http://en.wikipedia.org/wiki/Network_switch
http://en.wikipedia.org/wiki/Network_layer
http://en.wikipedia.org/wiki/Routing
Powered by TCPDF (www.tcpdf.org)
Students also viewed