CAPSTONE

profilemakaveli
capstone_-_3.docx

Technical Writing Project Coversheet

Capstone Proposal Project Name: Cisco Security

Student Name: Jeremy Bartlett

Degree Program: Bachelor of Science, IT – Network Administration

Mentor Name: Michelle Vore

Signature Block:

Student Signature: ________________________________________________________

Table of Contents Technical Writing Project Coversheet 1 Capstone Proposal Summary 4 Review of Other Work 7 Rationale and Systems Analysis 8 Goals and Objectives 10 Project Deliverables 12 Project Plan and Timelines 14 Exhibit 1: Project Gantt Chart 14 References 15 Appendix A: My Professional Certifications 16

Capstone Proposal Summary

My Capstone project will be on Cisco security and the best ways to secure your network through wired or wireless routers. I will be hardening a Cisco 1941 router and a Netgear wireless router in my home network to showcase the advantages of network security. I will accomplish this through the process of adding ACLs, removing unsafe passwords, changing key configuration items, and using today’s most secure standards. Before starting this project I will be performing a security audit which will highlight any areas of concern when it comes to security. I will also be performing a penetration test to see just how vulnerable those areas are. Once the routers have been hardened with the latest methods of security, I will perform another security audit and will post the results. Cisco is a leader in home and business networks and there are many ways that they provide to keep your network secure from outside and inside threats. I have worked on securing networks for many various companies and each of them are a little bit different. I have also obtained several certifications that pertain to this Capstone including Cisco CCNA, Cisco CCNP, CompTIA Security+, CompTIA Network+ and CompTIA Project+.

This capstone project will attempt to accomplish the following:

· Perform a preliminary Security Audit

· A security audit will show any areas that need attention and that are possible targets for a hacker. It is very important to highlight these areas in this project so we can be sure we are using the proper security methods.

· Identify the different security standards

· There are many different standards that can be used to secure your network, both wired and wireless. I will go into detail on which standards are best for different situations.

· Identify different methods of securing your network

· There are multiple methods of securing a network, some of which can be combined for an even more secure network.

· Identify the Wireless Encryption standards

· Besides the security standards there are also many encryption standards that can be used. I will explain the benefits of encryption and the benefits of each different encryption standard.

· Explain other security issues within your network

· It is important to make sure you understand multiple ways that your network can be compromised. I will explain those methods in detail.

· Show different security methods on each layer of the OSI model

· The OSI model shows each layer that data has to travel through to go from point A to point B. I will show how to add additional security on each of these layers.

· Show which hardware is suitable for home and business networks

· There is a big difference between home networking equipment and business network equipment. I will show which products are better to secure your business and home networks in detail. I will also be configuring a Cisco 1941 ISM router and providing results.

· Alternative hardware and software methods for adding additional security

· There are many additional methods of adding security that do not have to do with configuring your router. There are also 3rd party software firewalls that can be configured per network device. Additionally you can use hardware firewalls to monitor traffic and block threats. I will show you in detail what can be done to configure these options.

· Hacking methods and tools that they can use to compromise your network

· I will show you ways that hackers can attempt to access your network and ways to counter their attacks.

· Penetration Testing

· It is very important to do penetration testing on your network so that you know the weak areas that hackers may try to compromise. I will explain in detail some methods of testing how secure your network really is.

· Identifying a potential attack

· I will explain how to find out if someone has entered into your network without consent.

· What to do after you have found that a hacker has entered your network

· There are many things you need to look for after you have found that your network has been compromised. I will list in detail things to look for and what can be done about each of them. I will also detail ways to prevent the same attack from being made again.

· Network Monitoring

· We will need to monitor the network after I have hardened the routers. This will allow us to see if the project was successful in providing more security to the network.

Review of Other Work

There are many books and websites about how to secure your network. A lot of these books will show you different ways of dealing with the issue of network security. One book that I read that goes into depth on the subject of network hardening is “Hardening Cisco Routers” by Thomas Akin. (Akin, 2002) This is actually an older book, but it really goes into detail about Cisco router security, ways to configure the router, and ways to better secure your network. This book goes into detail about IOS version security, ACLs, AAA, and passwords. I will be using some of these methods from this book in my project to add security to the routers. Also in this book the author goes into detail on what the consequences could be if your router was hacked. “Secure communication is as important for an organization’s survival as it is in military warfare. Routers are the communication medium for an organization and the consequences of their compromise can be disastrous. By compromising an organization’s routers, an attacker can:

· Disable the entire network

· Those who have experienced significant network outages can understand the loss of productivity and revenue this causes. Imagine how long it would take to fix the network if attackers disabled password recovery, changed the routers’ passwords, and deleted the configurations.

· Use the routers to attack internal systems

· Routers can give attackers a foothold into your internal network. By taking control of routers, attackers can often bypass intrusion detection systems, use the routers to gain access to trusted networks, and avoid or confuse any logging and monitoring used on the network.

· Use the routers to attack other sites

· Hackers like to hide their tracks. They do this by breaking into several networked systems and use those systems to launch other attacks. When attacks pass through six or seven servers, they can be hard to trace. Since routers usually have less protection and logging than servers, attacking through six or seven routers can be extremely difficult and costly to investigate. For organizations with insecure routers and no monitoring, an attacker will leave little or no trace.

· Reroute all traffic entering and leaving the network

· Compromised routers allow an attacker to reroute network traffic. Attackers can then monitor, record, and modify the redirected traffic. Imagine the effects of several weeks’ worth of online orders being redirected to a competitor or, worse, online financial transactions being rerouted to a bank somewhere in Nigeria.” (Akin, 2002)

I have taken and passed the testing requirements for many Cisco and CompTIA certifications. All of the certifications I have obtained relating to networking and network security have been listed below in Appendix A. While studying for these certifications I have purchased many books that helped me through the process of getting certified. One of these such books were “Cisco CCNA in 60 Days” by Paul Browning and Farai Tafa. (Tafa, 2014) This book goes through all the steps needed to properly study for the Cisco CCNA exam. It also covers basic Cisco security methods that I will be detailing in my capstone. For example this book was pivotal in teaching me to use the Cisco command line or CLI as it’s called. All configuration changes on a cisco router use the CLI to make those changes. I will be using the methods learned to change the default password, apply ACLs and to setup the router to connect to the radius server for AAA.

While I was working on getting my CCNP (Cisco Certified Network Professional” certification I watched many training videos to further enhance my skillset. One of those such videos was “CBT Nuggets CCNP 300-101 by Jeremy Cioara. (Cioara, 2015) Jeremy was very easy to listen to as he was not monotone and didn’t lull you to sleep. He kept the mood positive and tried to make it fun to learn. With the help of this video I obtained my CCNP certification. The CCNP is a professional level certification and with the knowledge that I learned from the videos, I passed the three tests required to obtain the certification. What I learned in the video that will help me along the way with this project are advanced techniques to secure your network even further than what I learned while obtaining my CCNA.

Rationale and Systems Analysis

Network security is a very important part of today’s society. With everyone using the internet for just about everything there can be some major security issues. With many people using online banking or investing services a potential security breach could leave their accounts compromised. I am going to use some very basic and then some more complex methods to secure a network.

Proper security goes beyond the encryption of the traffic. There are many other methods a person or business can do to further protect their network. Some steps to add additional security to your network are listed below:

· Implement Access Lists

· Implement MAC-Address filtering

· Implement AAA

· Use an Authentication Server

· Implement a hardware firewall

· Implement IDS\IPS systems

· Use strong passwords

· Remove default login names and password from routers

· Implement latest firmware

· Do not use standard ip schemes on your network with defaults for the router login

There are many different methods that hackers use to compromise your network. Some of these methods are listed below:

· Trojan Horses

· Back Door Programs

· DoS (Denial of Service) Attacks

· Packet Sniffing

· Brute Force Password Attacks

· Fake Access Points

The purpose of this capstone project for router security is to bring a network up to date with protection from outside threats. I will be doing a detailed security audit to assess any potential areas that could be compromised. If such areas are found then I will fix them as needed, whether it be changing the router configuration or adding more secure passwords. Some of the issues that I might possibly run in to are:

· IOS Version out of date

· Weak or no passwords

· Found that someone has already hacked the network and changed login information

These problems can be remediated during this project. The IOS version can be updated to the newest version to add additional security. Passwords can be changed using the CLI. If someone has hacked into the network we can always go into the router using the console port and wipe the configuration and start from scratch.

Once the project is underway and the routers have been hardened to be more secure, it will need to be monitored. This is the most important step of the project so we can see if the changes we made were successful. The network monitoring tool Spiceworks will be installed to perform this action. Although we can hope for a smooth install of Spiceworks there could also be issues there. Making sure that we are using the 64-bit software and not the 32-bit is one of the things that could really mess up the plan.

The proposed hardware for this project is the Cisco 1941 ISR. This particular model has a built in 8-port Ethernet switch. This will make integration into the network much smoother. As with any electronic device there is a chance of hardware failure, but I believe that Cisco makes the best routers in the world. This is not only personal opinion seeing that 80% of the internet is using cisco routers according to Thomas Akin in Hardening Cisco Routers. (Akin, 2002)

·

Goals and Objectives

There are two main goals for this project. The first goal for this project is to redesign a current network with much more security than it has at the moment. The second goal is to meet the following objectives:

· Evaluate Current Network Security

· Choose Network Hardware

· Configure wireless router

· Set up encryption method

· Remove Default Username and Passwords

· Configure Cisco 1941

· Install and configure ACLs (Access lists)

· Enabling Port-Security

· Install network monitoring software (Spiceworks)

· Set up an Authentication Server (Radius)

· Perform Penetration Testing (Kali Linux)

· Complete all objectives within the project timeframe

The first thing that will need to be done is to evaluate the current network and see where it stands concerning security. We need to look for open ports, default passwords, and default ip schemes. I know many people that go out to the local electronics store and buy a wireless router. When they get home they just hook it up and let it auto-configure itself. The problem with that is that it uses a default ip scheme. The two most common schemes are 192.168.1.0/24 or 192.168.0.0/24. A hacker knows that if you are using one of these routers your ip address to access the routers web interface is 192.168.1.1 or 192.168.0.1. Now if they are sitting out in your street and you haven’t added any additional security they can have full access to your network. They can even use a network sniffer and decrypt your website passwords as you type them. Pretty scary thought, isn’t it? So with that being said, the biggest failure I see is not making a complete evaluation before starting a project. This can cause future problems after the security upgrade concerning access to many different applications. It can even block access to certain computers and/or websites.

Depending on the situation, you will need to evaluate which hardware to choose. In this project I will be using a Cisco 1941 ISM router which has an integrated 8 port switch and a Netgear Nighthawk X6 wireless router. Choosing the right equipment for the project is critical because you don’t want to use outdated or inferior products when it comes to security. Both of the routers I have chosen are able to handle all of today’s best security standards.

Now that we know what equipment will be used we need to make some configuration changes on the wireless router. The most important thing to do when you get any new router is to change the default username and password. Hackers prey on networks that use default names and passwords. Most people don’t know that when they buy a new wireless router that the username and password need to be changed. All a potential hacker would need to know is your SSID and they could potentially have free roam of your network. Choosing which wireless encryption is also very important. The most secure at the time of this project is WPA2 so that is what will be used in this project. The other encryptions that are available are WEP and WPA.

On the Cisco 1941 we also have to add a password away from the default password of “cisco”. Hackers know what the defaults are and will look for them as an easy way in. After the password has been changed ACLs should be implemented. An ACL is sort of like a small firewall that is built into the router. You can specify different protocols and port numbers that allowed in and out of the network depending on the devices that the traffic is originated from. To further add security on the switch ports, port-security will be enabled, Port-Security allows for the configuration to be made so that only certain mac addresses are allowed to access the network through a certain port on the routers integrated switch. For example, if I configured port 8 with the mac address of my printer, only the printer could connect to the network using that port. All network devices in the world have a unique mac address, so this is a very good method to secure your network.

Once the network install and configuration changes have been made it is very important to set up a network monitoring server on the network to watch for potential attacks. For this project I have chosen Spiceworks. It is a full featured network monitor that will be installed on a local server within the network. A network monitor is very useful at detecting rogue computers on your network that are attempting to connect to outside networks. They can also monitor bandwidth usage to see what devices are using the most of your network connection. Once Spiceworks is installed we also need to install a Radius server. I will be using the same server that Spiceworks is on to install this. What Radius allows you to do is implement AAA on your routers. AAA stands for Authorization, Authentication and Accounting. This adds another level of protection to the logging in of your routers.

Once all of the routers have been configured and the authentication server has been setup it will be time to do some penetration testing to see if there are any weak areas in the network where a hacker could attempt to exploit. I have chosen Kali Linux to be the platform from which the penetration testing will occur. Kali Linux is the industry standard that security engineers use to test their networks. If any weaknesses are found then the appropriate actions will need to be taken.

All of these objectives will need to follow a small timeframe. To keep the project on schedule these objectives will need to be done in a specific order.

Project Deliverables

The key deliverables for this project are hardware, security, software, and a security audit report. The hardware deliverable will be the Cisco 1941 ISM router and a Netgear Nighthawk X6 wireless router. Security deliverables include new configurations on both network routers. The software deliverables are the Spiceworks network monitoring software and the radius server software. Along with the software a virtual server will be installed to run the applications. The security audit report will be a log of what the penetration test results find.

· The Cisco 1941 is a very powerful router when it comes to security. I chose this device based on its flexibility as a router with an integrated switch. Here are the specifications from the manufacturer:

Architectural Feature

Benefits

Modular Platform

●  The Cisco 1941 Series ISR are highly modular platforms with multiple module slots to provide connectivity and services for varied branch network requirements.

●  The ISRs offer an industry-leading breadth of LAN and WAN connectivity options through modules to accommodate field upgrades to future technologies without requiring replacement of the platform.

Processors

●  The Cisco 1941 Series is powered by high-performance multi-core processors that support growing demands of branch office networks by supporting high throughput WAN requirements.

MultiGigabit Fabric

●  The Cisco 1941 introduces an innovative MultiGigabit Fabric (MGF) which allows for efficient module to module communication, enabling direct services interactions across modules while reducing the overhead on the router processor.

Embedded IPSec VPN Hardware Acceleration

●  Embedded hardware encryption acceleration is enhanced to provide higher scalability, which, combined with an optional Cisco IOS Security license, enables WAN link security and VPN services (IPSec acceleration).

●  The onboard encryption hardware out-performs the Advanced Integration Modules of previous generations.

Integrated Gigabit Ethernet Ports

●  All onboard WAN ports are 10/100/1000 Gigabit Ethernet WAN routed ports .

Innovative universal-serial-bus (USB)-based console access

●  A new, innovative, mini-B USB console port supports management connectivity when traditional serial ports are not available.

●  The traditional console and auxiliary ports are also available. Either the USB-based console or the RJ-45-based console port can be used to configure the router.

Optional Integrated Power Supply for Distribution of Power Over Ethernet (PoE)

●  An optional upgrade to the internal power supply provides in-line power (802.3af-compliant Power-over-Ethernet [PoE] and Cisco standard inline power) to optional integrated switch modules.

· (Cisco, 2015)

The Netgear Nighthawk X6 router is also one of the most powerful wireless routers on the market today. Along with fast speeds and excellent connectivity it also has the highest standards when it comes to security.

The security configurations on both devices will be changed tremendously. With the addition of AAA, port-security, WPA2, and changing away from default usernames and passwords the configurations will look totally different. One very important thing to do here is to make sure that the original configurations are backed up so that in case of an issue there is a fall back plan.

To monitor the network once all the above is completed, Spiceworks network monitoring software will be installed. This will be running on a virtual server located within the network. Spiceworks is not heavily dependant on processor speed so it will be a perfect fit for the project. A virtual server using Microsoft server 2012 will be created to run Spiceworks and also run the Radius server. The radius server software will add another level of security to the network.

Project Plan and Timelines

The timeframe for this project is detailed below:

Exhibit 1: Project Gantt chart

Start Date

End Date

Description

Duration (days)

 

 

 

 

9/7

9/8

Initial Security Audit

2

9/9

9/9

Configuration of Routers

1

9/10

9/10

Installation of Software

1

9/11

9/13

Penetration Testing

2

9/13

9/13

Second Security Audit

1

9/14

9/14

Project Completion

1

Works Cited Akin, T. (2002). Hardening Cisco Routers. Sebastapol: O'Reilly. CCNA Routing and Switching - IT Certifications and Career Paths. (2015, August 26). Retrieved from Cisco .com: http://www.cisco.com/web/learning/certifications/associate/ccna/index.html CCNA Voice - IT Certifications and Career Paths. (2015, August 26). Retrieved from Cisco.com: http://www.cisco.com/web/learning/certifications/associate/ccna_voice/index.html CCNP Routing and Switching - IT certifications and Career Paths. (2015, August 26). Retrieved from Cisco.com: http://www.cisco.com/web/learning/certifications/professional/ccnp/index.html Cioara, J. (2015, August 26). Cisco CCNP Routing. Retrieved from cbtnuggets.com: https://www.cbtnuggets.com/it-training/cisco-ccnp-routing-switching-300-101 Cisco. (2015, August 27). Cisco 1941 Series ISR Data Sheet. Retrieved from Cisco.com: http://www.cisco.com/c/en/us/products/collateral/routers/1900-series-integrated-services-routers-isr/data_sheet_c78_556319.html Security Certifications, Network+ certification. (2015, August 26). Retrieved from comptia.com: http://certification.comptia.org/getCertified/certifications.network.aspx Tafa, P. B. (2014). Cisco CCNA in 60 Days. Reality Press.

Appendix A: My Professional Certifications

These are certifications have I have obtained after passing the tests required by the sponsor organizations. This list is of certifications that pertain to this capstone project.

CCNA Voice: “The Cisco CCNA Voice certification confirms that the required skill set for specialized job roles in voice technologies such as voice technologies administrator, voice engineer, and voice manager. It validates skills in VoIP technologies such as IP PBX, IP telephony, handset, call control, and voicemail solutions.” (http://www.cisco.com/web/learning/certifications/associate/ccna_voice/index.html)

CCNA : “The CCNA Routing and Switching validates the ability to install, configure, operate, and troubleshoot medium-size routed and switched networks.” (http://www.cisco.com/web/learning/certifications/associate/ccna/index.html)

CCNP : “Cisco Certified Network Professional (CCNP) Routing and Switching certification validates the ability to plan, implement, verify and troubleshoot local and wide-area enterprise networks and work collaboratively with specialists on advanced security, voice, wireless and video solutions.” (http://www.cisco.com/web/learning/certifications/professional/ccnp/index.html)

CompTIA Security+: “CompTIA Security+ not only ensures that candidates will apply knowledge of security concepts, tools, and procedures to react to security incidents, it ensures that security personnel are anticipating security risks and guarding against them.” (http://certification.comptia.org/getCertified/certifications/security.aspx)

Start Date Initial Security Audit Confiuration of Routers Installation of Software Penetration Testing Second Security Audit Project Completion 42254 42256 42257 42258 42260 42261 Duration (days) Initial Security Audit Confiuration of Routers Installation of Software Penetration Testing Second Security Audit Project Completion 2 1 1 2 1 1