Objectives
In this activity, you will learn how to harden network devices to prevent common cyberattacks.
- Part 1: Use Port Security to Harden Network Switches
- Part 2: Mitigate Rogue DHCP Server Vulnerabilities
- Part 3: Improve Password Security
Background / Scenario
A cyberattack has occurred at a substation that is operated by your company. A threat actor gained physical access to the substation by exploiting a gap in the perimeter fence caused by a fallen tree. The attacker was able to access the network with their own devices and installed a rogue access point in an equipment cabinet for persistent access. You need to help investigate and mitigate the attack and improve overall security of networking devices in use in the substation to harden the devices against further attacks.
Instructions
Part 1: Use Port Security to Harden Network Switches
Step 1: Verify attack process.
The threat actor physically plugged a device into the network by breaching an equipment cabinet to gain access to a substation switch. The threat actor then plugged a wireless access point into the switch, exited the substation perimeter enclosure, and connected to the substation network with a wireless laptop through the rogue AP. In this step, you will replicate the attack.
- Connect Port 0 of the Rogue Access Point to interface Gig1/10 of switch BaySwitch1 with a copper straight-through cable.
- On the Config tab of Rogue Laptop, click On for the Port Status to activate Wireless0. After a short delay, you should see Rogue Laptop attach to the Rogue AP.
- Verify that the Rogue Laptop has received an address on the substation network over DHCP. It may take a short time before the laptop receives an address.
- From the desktop of the Rogue Laptop, open the Supervisory Workstation application.
- Enter the following:
- Data Historian IP address: 192.168.1.254
- Username: admin
- Password: admin
- When logged in, leave the date ranges as they are and click Add Chart. You should see a graph of data from Data Historian. The threat actor has been able to access proprietary data.
- Close the Rogue Laptop configuration window.
- Disconnect the link between BaySwitch1 and Rogue Access Point. Press the <Delete> key on your computer to change to the delete cursor or click the Delete tool on the toolbar to delete the cable. Press the <Esc> key to revert the back to the Select cursor.
Step 2: Shut down unused ports.
Now that you have demonstrated that you can access the network in the same way that the threat actor did, you will mitigate similar threats by hardening the switch.
- On BaySwitch1, enter the show ip interface brief command and make note of the GigabitEthernet interfaces that have a status of down.
- You can configure multiple switch interfaces at the same time by using the range option with the interface configuration command.
- It is also a good practice to assign unused switchports to an unused VLAN that has been created for that purpose. While still in the interface range config mode, enter the following command:
- Return to Privileged EXEC mode and use the show interfaces command to verify the switchport configuration.
- Enter the show vlan command to verify the VLAN membership of the ports.
- Connect the Rogue Access Point to an available port on BaySwitch1 with a copper straight-through cable. Note that the red triangles at each end of the cable. This indicates that the link is down.
- Go to the IP Configuration application on the Desktop of the Rogue Laptop.
- Select the Wireless0 interface from the dropdown menu.
- Set the configuration mode to Static, and then back to DHCP.
- Wait for the laptop to receive an IP address.
BaySwitch1> enable BaySwitch1# show ip interface brief Interface IP-Address OK? Method Status Protocol GigabitEthernet1/1 unassigned YES unset up up GigabitEthernet1/2 unassigned YES unset down down GigabitEthernet1/3 unassigned YES unset up up GigabitEthernet1/4 unassigned YES unset up up GigabitEthernet1/5 unassigned YES unset up up GigabitEthernet1/6 unassigned YES unset down down GigabitEthernet1/7 unassigned YES unset down down GigabitEthernet1/8 unassigned YES unset down down GigabitEthernet1/9 unassigned YES unset down down GigabitEthernet1/10 unassigned YES unset down down Vlan1 unassigned YES unset administratively down down
BaySwitch1# configure terminal BaySwitch1(config)# interface range g1/2,g1/6-10 BaySwitch1(config-if-range)# shutdown %LINK-5-CHANGED: Interface GigabitEthernet1/2, changed state to administratively down %LINK-5-CHANGED: Interface GigabitEthernet1/6, changed state to administratively down %LINK-5-CHANGED: Interface GigabitEthernet1/7, changed state to administratively down %LINK-5-CHANGED: Interface GigabitEthernet1/8, changed state to administratively down %LINK-5-CHANGED: Interface GigabitEthernet1/9, changed state to administratively down %LINK-5-CHANGED: Interface GigabitEthernet1/10, changed state to administratively down
BaySwitch1(config-if-range)# switchport access vlan 999 % Access VLAN does not exist. Creating vlan 999 BaySwitch1(config-if-range)# end
BaySwitch1# show interfaces | include Gig GigabitEthernet1/1 is up, line protocol is up (connected) GigabitEthernet1/2 is administratively down, line protocol is down (disabled) GigabitEthernet1/3 is up, line protocol is up (connected) GigabitEthernet1/4 is up, line protocol is up (connected) GigabitEthernet1/5 is up, line protocol is up (connected) GigabitEthernet1/6 is administratively down, line protocol is down (disabled) GigabitEthernet1/7 is administratively down, line protocol is down (disabled) GigabitEthernet1/8 is administratively down, line protocol is down (disabled) GigabitEthernet1/9 is administratively down, line protocol is down (disabled) GigabitEthernet1/10 is administratively down, line protocol is down (disabled)Interfaces with the administrative down status have been deactivated with the shutdown command.
BaySwitch1# show vlan
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Gig1/3, Gig1/4, Gig1/5
999 VLAN0999 active Gig1/2, Gig1/6, Gig1/7, Gig1/8
Gig1/9, Gig1/10
1002 fddi-default active
1003 token-ring-default active
1004 fddinet-default active
1005 trnet-default active
Step 3: Connect the Rogue Access Point to a port that is in use.
Shutting down unused ports is a first step in protecting network access, but attackers can still unplug a device from the switch and substitute their own device. Port security offers several mechanisms designed to prevent this from occurring.
- Delete the cable that connects MU1 device to port Gig1/3 by pressing the <Delete> key or selecting the Delete tool from the menu bar and clicking on the cable. Choose the Select tool from the menu bar to stop deleting devices and cables or press <Esc>.
- Connect the Rogue Access Point cable to port Gig1/3 by dragging the red triangle that is near the switch to the newly empty port.
- After the orange circle on the end of the cable near the switch turns to a green triangle, repeat the process above to determine if Rogue Laptop has received an IP address over DHCP.
- Reconnect MU1 to the network with the cable that is connected to Rogue Access Point.
Step 4: Use port security to designate which devices should be permitted to connect to the switch.
Because threat actors with physical access to networking devices can manipulate cable connections, another means of securing switchports has been developed. Port Security allows granular control of the number and identity of unique devices that are permitted to connect to switch ports. If the port security settings are violated, by an unknown device connecting to a port, for example, the port can be automatically shut down and notifications sent to network management workstations.
- Access the CLI of switch BaySwitch1. Use the show ip interface brief command to get a summary of the status of the interfaces. Identify the interfaces that have a status of up. These are the interfaces that are currently in use. Port Gig1/1 is a trunk port that connects to another switch. Although the port is in use, it is not an access port that requires port-security configuration Make note of the three access ports that are in use.
- In global configuration mode, use the interface range command to select the interfaces that are in use for configuration.
- The ports are currently in dynamic mode. They must be in access mode to be configured with port security.
- Set the maximum number of unique MAC addresses permitted to access the ports to one.
- Set the switch ports to automatically enter the MAC address of the first device to connect to the ports. These MAC addresses will be entered into the device configuration file after the configuration is saved. This is a convenient way to configure specific MAC addresses as the only device addresses permitted to access the ports. This is called sticky learning.
- Activate port security on the switchports with the switchport port-security command.
- Define an action to take if a device with an unknown MAC address attempts to connect to the switch. The options are:
- Protect - Drops packets with unknown source addresses until you remove a sufficient number of secure MAC addresses to drop below the maximum value.
- Restrict - Dops packets with unknown source addresses until you remove a sufficient number of secure MAC addresses to drop below the maximum value and causes the security violation counter to increment.
- Shutdown - Puts the interface into the error-disabled state immediately and sends an SNMP trap notification.
- Type end to return to Privileged EXEC mode.
- Navigate to the desktop of MU1 device. From the Command Prompt, ping 192.168.1.250.
- At the command prompt of MU1, determine and note the MAC address of MU1 by using the command ipconfig /all.
- Navigate back to BaySwitch1. Save your configuration with copy running-config startup-config command.
- Enter the show port-security command to view the port-security configuration.
- Enter the show port-security address command to view the port-security configuration. The sticky MAC address should be the same as the MAC address of MU1.
- Test your configuration by moving the cable from MU1 to the Rogue Access Point. Click the fast-forward time button below the topology window and to the left, to accelerate network processes until the status of the port Gig1/3 changes. You should see the link lights turn red on that cable. You should see the following messages in BaySwitch1 CLI.
- Reactivate the port.
- Move the cable back to the G0 interface of MU1.
- In global configuration mode, enter the following commands.
BaySwitch1# show ip interface brief Interface IP-Address OK? Method Status Protocol GigabitEthernet1/1 unassigned YES unset up up GigabitEthernet1/2 unassigned YES unset down down GigabitEthernet1/3 unassigned YES unset up up GigabitEthernet1/4 unassigned YES unset up up GigabitEthernet1/5 unassigned YES unset up up GigabitEthernet1/6 unassigned YES unset down down GigabitEthernet1/7 unassigned YES unset down down GigabitEthernet1/8 unassigned YES unset down down GigabitEthernet1/9 unassigned YES unset down down GigabitEthernet1/10 unassigned YES unset down down Vlan1 unassigned YES unset administratively down down
BaySwitch1(config)# interface range Gig1/3-5
BaySwitch1(config-if-range)# switchport mode access
BaySwitch1(config-if-range)# switchport port-security maximum 1
BaySwitch1(config-if-range)# switchport port-security mac-address sticky
BaySwitch1(config-if-range)# switchport port-security
BaySwitch1(config-if-range)# switchport port-security violation shutdown
root@Thing:/> ipconfig /all
GigabitEthernet0 Connection:(default port)
Connection-specific DNS Suffix..:
Physical Address................: 0060.5C75.BD52
Link-local IPv6 Address.........: FE80::260:5CFF:FE75:BD52
IPv6 Address....................: ::
IPv4 Address....................: 192.168.0.7
Subnet Mask.....................: 255.255.254.0
Default Gateway.................: ::
192.168.1.250
DHCP Servers....................: 192.168.1.253
DHCPv6 IAID.....................:
DHCPv6 Client DUID..............: 0003000100605C75BD52
DNS Servers.....................: ::
0.0.0.0
BaySwitch1# copy running-config startup-config Destination filename [startup-config]? Building configuration...
[OK]
BaySwitch1# show port-security
Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action
(Count) (Count) (Count)
--------------------------------------------------------------------
Gig1/3 1 1 0 Shutdown
Gig1/4 1 1 0 Shutdown
Gig1/5 1 1 0 Shutdown
---------------------------------------------------------------------
BaySwitch1# show port-security address
Secure Mac Address Table
-----------------------------------------------------------------------------
Vlan Mac Address Type Ports Remaining Age
(mins)
---- ----------- ---- ----- -------------
1 0060.5C75.BD52 SecureSticky Gig1/3 -
1 000C.85BD.3DB3 SecureSticky Gig1/4 -
1 00D0.58EC.A51A SecureSticky Gig1/5 -
-----------------------------------------------------------------------------
Total Addresses in System (excluding one mac per port) : 0
Max Addresses limit in System (excluding one mac per port) : 1024
BaySwitch1# %LINK-5-CHANGED: Interface GigabitEthernet1/3, changed state to up %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/3, changed state to up %LINK-3-UPDOWN: Interface GigabitEthernet1/3, changed state to down %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/3, changed state to down %LINK-5-CHANGED: Interface GigabitEthernet1/3, changed state to up %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/3, changed state to up %LINK-5-CHANGED: Interface GigabitEthernet1/3, changed state to administratively down %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/3, changed state to down %PM-4-ERR_DISABLE: psecure-violation error detected on Gig1/3, putting Gig1/3 in err-disable state. %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occurred, caused by MAC address 00D0.FF75.00E5 on port GigabitEthernet1/3.A port security violation has occurred and port Gig1/3 has been shut down.
Note: If the interface does not shutdown, you may need to generate some traffic for the switch to see that a device with a new MAC address is connected to the port. To do this, ping any IP address on the network from the command prompt of the Rogue Laptop.
BaySwitch1# configure terminal BaySwitch1(config)# interface g1/3 BaySwitch1(config-if)# shutdown %LINK-5-CHANGED: Interface GigabitEthernet1/3, changed state to administratively down BaySwitch1(config-if)# no shutdown BaySwitch1(config-if)# %LINK-5-CHANGED: Interface GigabitEthernet1/3, changed state to up %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/3, changed state to upYou should see the port change state to up.
Part 2: Mitigate Rogue DHCP Server Vulnerabilities.
If a threat actor is able to physically access a network, they could run a rogue DHCP server on their device. This could cause multiple devices to eventually configure with addresses in IP networks that are not normally used. This could cause important devices in the network to become unreachable. This is called a DHCP spoofing attack. In addition, threat actors could set the default gateway configured in DHCP to their own IP address, thus causing hosts to direct traffic that is to be sent outside the substation network to the threat actors’ devices instead. Hacker tools can also be used to forward that traffic on to the actual default gateway, thus performing an on-path attack.
Because this type of attack is relatively easy to execute when physical access to the network is obtained, switches can be configured with a feature called DHCP snooping that prevents DHCP traffic from being forwarded through untrusted switchports. You will configure switch BaySwitch1 with DHCP snooping.
Step 1: Determine trusted and untrusted ports.
Look at the topology diagram.
Step 2: Configure DHCP Snooping.
- In global configuration mode, activate DHCP snooping.
- Configure interface Gig1/1 as the trusted interface.
- On the untrusted interfaces, rate limit DHCP discovery messages.
- Verify configuration using the show ip dhcp snooping command in Privileged EXEC mode.
BaySwitch1(config)# ip dhcp snooping
BaySwitch1(config)# interface g1/1 BaySwitch1(config-if)# ip dhcp snooping trust
BaySwitch1(config-if)# interface range g1/3-5 BaySwitch1(config-if-range)# ip dhcp snooping limit rate 6
BaySwitch1# show ip dhcp snooping <output omitted> DHCP snooping trust/rate is configured on the following Interfaces: Interface Trusted Allow option Rate limit (pps) ----------------------- ------- ------------ ---------------- GigabitEthernet1/1 yes yes unlimited Custom circuit-ids: GigabitEthernet1/2 no no unlimited Custom circuit-ids: GigabitEthernet1/3 no no 6 Custom circuit-ids: GigabitEthernet1/6 no no unlimited Custom circuit-ids: GigabitEthernet1/7 no no unlimited Custom circuit-ids: GigabitEthernet1/10 no no unlimited Custom circuit-ids: GigabitEthernet1/8 no no unlimited Custom circuit-ids: GigabitEthernet1/5 no no 6 Custom circuit-ids: GigabitEthernet1/4 no no 6 Custom circuit-ids: GigabitEthernet1/9 no no unlimited
Part 3: Improve Password Security
An important part of hardening network devices is securing access to the device management plane. In this part of the activity, you will increase security by encrypting all passwords in the device configuration file, set password requirements to ensure stronger password protection, and control the number of failed login attempts to mitigate brute force attacks. You will be configuring the SubstationCoreRouter in the Substation cloud.
Step 1: Configure passwords.
- Enter the Substation cloud and open the CLI of SubstationCoreRouter.
- Configure the following passwords:
- Enable password (not enable secret password): cisco
- Line password: class
- Console password: class
- Enter the show running-config command. Look for the enable and line passwords that you just entered. Network administrators often back up their configuration files to servers. The configuration files are stored in clear text.
SubstationCoreRouter(config)# enable password cisco SubstationCoreRouter(config)# line vty 0 4 SubstationCoreRouter(config-line)# password class SubstationCoreRouter(config-line)# line console 0 SubstationCoreRouter(config-line)# password classNote: These passwords do not meet standards for strong passwords. The passwords in use here simplify the process of configuring and logging into devices for the purpose of this learning activity only. In addition, we are using the unencrypted enable password as an example. It is a best practice to always use the enable secret password, which is encrypted.
Step 2: Encrypt clear text passwords.
- Go to global configuration mode on the SubstationCoreRouter.
- Enter the command to encrypt all clear text passwords in the configuration file.
- Display the running configuration again and look for the three passwords that configured in the previous step.
SubstationCoreRouter(config)# service password-encryption
Step 3: Set password requirements
Organizations establish security policies regarding the features of passwords that are acceptable for use. These policies specify the password length and the required mix of characters (alpha, numeric, and special) that should be used. You can configure the required minimum length of user and enable passwords in IOS.
- Enter global configuration mode on the SubstationCoreRouter router.
- Enter the following to view the help for the command.
SubstationCoreRouter(config)# security passwords min-length ? <0-16> Minimum length of all user/enable passwords
- We will use a minimum length of 10 characters. Enter the command and specify the length.
- Enter a username and password with username admin and password cisco.
SubstationCoreRouter(config)# security password min-length 10
SubstationCoreRouter(config)# username admin password cisco
- Now reenter the command with password Cisco1234!
- Reconfigure the enable password 5678Cisco!.
- Now view the user and enable passwords in the configuration file.
SubstationCoreRouter(config)# username admin password Cisco1234!
SubstationCoreRouter# show running-config | section user username admin password 7 0802455D0A165445415F4D SubstationCoreRouter# show run | section enable enable password 7 08741A19513A0C0411044D
Step 4: Control login attempts.
Cisco IOS permits specifying a consequence for repeated failed login attempts over a specified period of time. This will block repeated logins if a threat actor is trying to brute force the password or a DoS attack on a virtual terminal line is under way.
- Go to global configuration mode on SubstationCoreRouter.
- Enter the following command.
SubstationCoreRouter(config)# login block-for 120 attempts 5 within 60This command specifies that logins should be blocked for 120 seconds if 5 failed attempts are made over a period of 60 seconds.
Summary
In this activity, you have taken steps to enhance the security of a network and network devices. There are a number of other best practices for device hardening that were omitted from this activity for the sake of brevity. While there are many ways to secure a network, in a defense in depth approach, securing networking devices has an important role in overall network security.
Answer Scripts
Switch BaySwitch1
enable configure terminal ip dhcp snooping interface range g1/3-5 ip dhcp snooping limit rate 6 switchport mode access switchport port-security max 1 switchport port-security violation shutdown switchport port-security mac-address sticky switchport port-security interface range g1/2, g1/6-10 shutdown switchport access vlan 999 interface gigabitEthernet1/1 ip dhcp snooping trust end
Router SubstationCoreRouter
enable configure terminal service password-encryption security password min-length 10 username admin password Cisco1234! enable password 5678Cisco! line vty 0 4 password class line console 0 password class login block-for 120 attempts 5 within 60 end