You are on page 1of 15

Cisco Systems,

Systems, Inc.
Inc. All
All rights
rights reserved.
reserved.
2004,
2005 Cisco

Wide Area Network

WAN
2005 Cisco Systems, Inc. All rights reserved.

WAN Overview

DTE = Data Terminal Equipment.


DCE = Data Communications Equipment.
CPE = Customer Premises Equipment.
2005 Cisco Systems, Inc. All rights reserved.

WAN Connection Types


1- Leased Line :
The link is available all the time , with all the dedicated bandwidth.
No call setup procedures before transmitting data.
Only support point-to-point connection.
Expensive ( Fixed Cost ).

2- Circuit Switching :
The link is available but only for the duration of call.
Need call setup procedures before transmitting data.
Only support point-to-point connection.
Cheaper when connectivity is not needed all the time ( Variable Cost ).
Useful for backup connection.
Example : Analog Dial-up Connection ( MODEM )
Digital Dial-up Connection ( ISDN )

2005 Cisco Systems, Inc. All rights reserved.

WAN Connection Types


3- Packet Switching :
The Router is connected to a Telco ( Telephone Company ) using a single physical
line with the possibility of being able to forward traffic to all other sites.
Support point-to-multi-point connection ( Virtual Circuit ).
Example : Frame Relay ( FR )

2005 Cisco Systems, Inc. All rights reserved.

WAN Protocols
HDLC ( High level Data Link Control Protocol )
It is the default encapsulation on serial interfaces of Cisco routers.
Router (config-if) # encapsulation hdlc
- Per Vendor Protocol.

- Has no options.

PPP ( Point-to-Point Protocol )


It is a standard protocol.
Router (config-if) # encapsulation ppp
PPP options:
1- Compression.

2- Callback.

3- Multi-Link.

4- Authentication ( PAP & CHAP )

2005 Cisco Systems, Inc. All rights reserved.

PPP Authentication Protocols


PAP ( Password Authentication Protocol )
PAP is a 2-way handshake Process.
Username & Password are sent in a clear text to the destination.

CHAP ( Challenge Handshake Authentication Protocol )


CHAP is a 3-way handshake Process.
Using one-way hash function based on the Message Digest 5 (MD5).

2005 Cisco Systems, Inc. All rights reserved.

PPP Authentication Protocols Configuration


PAP
Server:
(config) # username remote hostname password password
(Config-if) # ppp authentication pap
Client :
(Config-if) # ppp pap sent-username my hostname password
matching password
CHAP
On both:
(config) # username remote hostname password matching password
(Config-if) # ppp authentication chap
# debug ppp authentication

2005 Cisco Systems, Inc. All rights reserved.

Frame Relay
Frame Relay is data link layer ( Layer 2 ).
FR is a packet switching technology.
FR support Multiple Access technology depending on the concept of
Virtual Circuit ( VC )
Virtual Circuit : is a logical connection between two devices.

2005 Cisco Systems, Inc. All rights reserved.

Frame Relay
Data Link Connection Identifier ( DLCI )
Each VC has a unique local address called DLCI.
DLCI is locally significant.
Local Management Interface ( LMI )
Signaling protocol between Router & FR Switch ( Keep alive & VC Status ).
LMI is locally significant.
LMI Types
1- Cisco ( Default on Cisco Devices )
2- Q933a ( Standard )
3- Ansi ( American )

2005 Cisco Systems, Inc. All rights reserved.

10

Wireless Communication
Ethernet LAN

IEEE 802.3

Electrical Signal
or Pulses of light

Wireless LAN

IEEE 802.11

Radio Waves

Wireless Standard
IEEE 802.11a 54 Mbps
IEEE 802.11b 11 Mbps ( Commonly Used )
IEEE 802.11g 54 Mbps
Wireless Access Point ( WAP ) communicate like a Hub.
2005 Cisco Systems, Inc. All rights reserved.

11

Wireless Communication

Wireless Modes
1- Ad-hoc Mode :
2 Devices communicate directly ( No AP is needed )
Independent Basic Service Set ( IBSS )
2- Infra Structure Mode:
One AP Basic Service Set ( BSS ) .
More than one AP Extended Service Set ( ESS )

2005 Cisco Systems, Inc. All rights reserved.

12

Types of Attacks

Types of Attacks:
1- Denial Of Service ( DOS ) Attack :
Break things , erase data ( Destroyers , crashers ).
Flood network with a packet ( Flooders ).
Active Attack.
2- Reconnaissance Attack :
Gather Information ( IP address ,..) .
Passive Attack.
2005 Cisco Systems, Inc. All rights reserved.

13

Security Tools

Security Tools:
1- IDS ( Intrusion Detection System ) :
receive a copy of data via monitoring port.
Detect only ( No action )
2- IPS (Intrusion Prevention System ) :
In the packet forwarding path but react & filter traffic.
Detect & Prevent ( action ).

2005 Cisco Systems, Inc. All rights reserved.

14


Cisco Systems,
Systems, Inc.
Inc. All
All rights
rights reserved.
reserved.
2005,
2005 Cisco

15

15

You might also like