Incomplete Packet Tracer - Implement Device Hardening

Objectives

In this activity, you will learn how to harden network devices to prevent common cyberattacks.

  • Part 1: Use Port Security to Harden Network Switches
  • Part 2: Mitigate Rogue DHCP Server Vulnerabilities
  • Part 3: Improve Password Security

Background / Scenario

A cyberattack has occurred at a substation that is operated by your company. A threat actor gained physical access to the substation by exploiting a gap in the perimeter fence caused by a fallen tree. The attacker was able to access the network with their own devices and installed a rogue access point in an equipment cabinet for persistent access. You need to help investigate and mitigate the attack and improve overall security of networking devices in use in the substation to harden the devices against further attacks.

Instructions

Part 1: Use Port Security to Harden Network Switches

Step 1: Verify attack process.

The threat actor physically plugged a device into the network by breaching an equipment cabinet to gain access to a substation switch. The threat actor then plugged a wireless access point into the switch, exited the substation perimeter enclosure, and connected to the substation network with a wireless laptop through the rogue AP. In this step, you will replicate the attack.

  1. Connect Port 0 of the Rogue Access Point to interface Gig1/10 of switch BaySwitch1 with a copper straight-through cable.
  2. On the Config tab of Rogue Laptop, click On for the Port Status to activate Wireless0. After a short delay, you should see Rogue Laptop attach to the Rogue AP.
  3. Verify that the Rogue Laptop has received an address on the substation network over DHCP. It may take a short time before the laptop receives an address.
  4. From the desktop of the Rogue Laptop, open the Supervisory Workstation application.
  5. Enter the following:
    • Data Historian IP address: 192.168.1.254
    • Username: admin
    • Password: admin
  6. When logged in, leave the date ranges as they are and click Add Chart. You should see a graph of data from Data Historian. The threat actor has been able to access proprietary data.
  7. Close the Rogue Laptop configuration window.
  8. Disconnect the link between BaySwitch1 and Rogue Access Point. Press the <Delete> key on your computer to change to the delete cursor or click the Delete tool on the toolbar to delete the cable. Press the <Esc> key to revert the back to the Select cursor.

Step 2: Shut down unused ports.

Now that you have demonstrated that you can access the network in the same way that the threat actor did, you will mitigate similar threats by hardening the switch.

  1. On BaySwitch1, enter the show ip interface brief command and make note of the GigabitEthernet interfaces that have a status of down.
  2. BaySwitch1> enable
    BaySwitch1# show ip interface brief
    Interface              IP-Address      OK? Method Status                Protocol 
    GigabitEthernet1/1     unassigned      YES unset  up                    up 
    GigabitEthernet1/2     unassigned      YES unset  down                  down
    GigabitEthernet1/3     unassigned      YES unset  up                    up 
    GigabitEthernet1/4     unassigned      YES unset  up                    up 
    GigabitEthernet1/5     unassigned      YES unset  up                    up 
    GigabitEthernet1/6     unassigned      YES unset  down                  down
    GigabitEthernet1/7     unassigned      YES unset  down                  down
    GigabitEthernet1/8     unassigned      YES unset  down                  down
    GigabitEthernet1/9     unassigned      YES unset  down                  down
    GigabitEthernet1/10    unassigned      YES unset  down                  down
    Vlan1                  unassigned      YES unset  administratively down down
  3. You can configure multiple switch interfaces at the same time by using the range option with the interface configuration command.
  4. BaySwitch1# configure terminal
    BaySwitch1(config)# interface range g1/2,g1/6-10
    BaySwitch1(config-if-range)# shutdown
    
    %LINK-5-CHANGED: Interface GigabitEthernet1/2, changed state to administratively down
    
    %LINK-5-CHANGED: Interface GigabitEthernet1/6, changed state to administratively down
    
    %LINK-5-CHANGED: Interface GigabitEthernet1/7, changed state to administratively down
    
    %LINK-5-CHANGED: Interface GigabitEthernet1/8, changed state to administratively down
    
    %LINK-5-CHANGED: Interface GigabitEthernet1/9, changed state to administratively down
    
    %LINK-5-CHANGED: Interface GigabitEthernet1/10, changed state to administratively down
  5. It is also a good practice to assign unused switchports to an unused VLAN that has been created for that purpose. While still in the interface range config mode, enter the following command:
  6. BaySwitch1(config-if-range)# switchport access vlan 999
    % Access VLAN does not exist. Creating vlan 999
    BaySwitch1(config-if-range)# end
  7. Return to Privileged EXEC mode and use the show interfaces command to verify the switchport configuration.
  8. BaySwitch1# show interfaces | include Gig
    GigabitEthernet1/1 is up, line protocol is up (connected)
    GigabitEthernet1/2 is administratively down, line protocol is down (disabled)
    GigabitEthernet1/3 is up, line protocol is up (connected)
    GigabitEthernet1/4 is up, line protocol is up (connected)
    GigabitEthernet1/5 is up, line protocol is up (connected)
    GigabitEthernet1/6 is administratively down, line protocol is down (disabled)
    GigabitEthernet1/7 is administratively down, line protocol is down (disabled)
    GigabitEthernet1/8 is administratively down, line protocol is down (disabled)
    GigabitEthernet1/9 is administratively down, line protocol is down (disabled)
    GigabitEthernet1/10 is administratively down, line protocol is down (disabled)
    Interfaces with the administrative down status have been deactivated with the shutdown command.
  9. Enter the show vlan command to verify the VLAN membership of the ports.
  10. BaySwitch1# show vlan
    
    VLAN Name                             Status    Ports
    ---- -------------------------------- --------- -------------------------------
    1    default                          active    Gig1/3, Gig1/4, Gig1/5
    999  VLAN0999                         active    Gig1/2, Gig1/6, Gig1/7, Gig1/8
                                                    Gig1/9, Gig1/10
    1002 fddi-default                     active    
    1003 token-ring-default               active    
    1004 fddinet-default                  active    
    1005 trnet-default                    active
  11. Connect the Rogue Access Point to an available port on BaySwitch1 with a copper straight-through cable. Note that the red triangles at each end of the cable. This indicates that the link is down.
  12. Go to the IP Configuration application on the Desktop of the Rogue Laptop.
    1. Select the Wireless0 interface from the dropdown menu.
    2. Set the configuration mode to Static, and then back to DHCP.
    3. Wait for the laptop to receive an IP address.
Did the laptop receive an IP address over DHCP? Explain.
Answer Area
The DHCP request from the laptop failed because the laptop no longer has access to the network. The available unused ports are all shutdown.

Step 3: Connect the Rogue Access Point to a port that is in use.

Shutting down unused ports is a first step in protecting network access, but attackers can still unplug a device from the switch and substitute their own device. Port security offers several mechanisms designed to prevent this from occurring.

  1. Delete the cable that connects MU1 device to port Gig1/3 by pressing the <Delete> key or selecting the Delete tool from the menu bar and clicking on the cable. Choose the Select tool from the menu bar to stop deleting devices and cables or press <Esc>.
  2. Connect the Rogue Access Point cable to port Gig1/3 by dragging the red triangle that is near the switch to the newly empty port.
  3. After the orange circle on the end of the cable near the switch turns to a green triangle, repeat the process above to determine if Rogue Laptop has received an IP address over DHCP.
Did the laptop receive an IP address over DHCP? What is the significance of this?
Answer Area
The DHCP request from the laptop was successful. This means that Rogue Laptop can still access the Substation network.
  1. Reconnect MU1 to the network with the cable that is connected to Rogue Access Point.

Step 4: Use port security to designate which devices should be permitted to connect to the switch.

Because threat actors with physical access to networking devices can manipulate cable connections, another means of securing switchports has been developed. Port Security allows granular control of the number and identity of unique devices that are permitted to connect to switch ports. If the port security settings are violated, by an unknown device connecting to a port, for example, the port can be automatically shut down and notifications sent to network management workstations.

  1. Access the CLI of switch BaySwitch1. Use the show ip interface brief command to get a summary of the status of the interfaces. Identify the interfaces that have a status of up. These are the interfaces that are currently in use. Port Gig1/1 is a trunk port that connects to another switch. Although the port is in use, it is not an access port that requires port-security configuration Make note of the three access ports that are in use.
  2. BaySwitch1# show ip interface brief
    Interface              IP-Address      OK? Method Status                Protocol 
    GigabitEthernet1/1     unassigned      YES unset  up                    up 
    GigabitEthernet1/2     unassigned      YES unset  down                  down 
    GigabitEthernet1/3     unassigned      YES unset  up                    up
    GigabitEthernet1/4     unassigned      YES unset  up                    up
    GigabitEthernet1/5     unassigned      YES unset  up                    up
    GigabitEthernet1/6     unassigned      YES unset  down                  down 
    GigabitEthernet1/7     unassigned      YES unset  down                  down 
    GigabitEthernet1/8     unassigned      YES unset  down                  down 
    GigabitEthernet1/9     unassigned      YES unset  down                  down 
    GigabitEthernet1/10    unassigned      YES unset  down                  down 
    Vlan1                  unassigned      YES unset  administratively down down
    
  3. In global configuration mode, use the interface range command to select the interfaces that are in use for configuration.
  4. BaySwitch1(config)# interface range Gig1/3-5
  5. The ports are currently in dynamic mode. They must be in access mode to be configured with port security.
  6. BaySwitch1(config-if-range)# switchport mode access
  7. Set the maximum number of unique MAC addresses permitted to access the ports to one.
  8. BaySwitch1(config-if-range)# switchport port-security maximum 1
  9. Set the switch ports to automatically enter the MAC address of the first device to connect to the ports. These MAC addresses will be entered into the device configuration file after the configuration is saved. This is a convenient way to configure specific MAC addresses as the only device addresses permitted to access the ports. This is called sticky learning.
  10. BaySwitch1(config-if-range)# switchport port-security mac-address sticky
  11. Activate port security on the switchports with the switchport port-security command.
  12. BaySwitch1(config-if-range)# switchport port-security
  13. Define an action to take if a device with an unknown MAC address attempts to connect to the switch. The options are:
    • Protect - Drops packets with unknown source addresses until you remove a sufficient number of secure MAC addresses to drop below the maximum value.
    • Restrict - Dops packets with unknown source addresses until you remove a sufficient number of secure MAC addresses to drop below the maximum value and causes the security violation counter to increment.
    • Shutdown - Puts the interface into the error-disabled state immediately and sends an SNMP trap notification.
    We will use the shutdown option in this activity.

    BaySwitch1(config-if-range)# switchport port-security violation shutdown
  14. Type end to return to Privileged EXEC mode.
  15. Navigate to the desktop of MU1 device. From the Command Prompt, ping 192.168.1.250.
  16. At the command prompt of MU1, determine and note the MAC address of MU1 by using the command ipconfig /all.
  17. root@Thing:/> ipconfig /all
    
    GigabitEthernet0 Connection:(default port)
    
       Connection-specific DNS Suffix..: 
       Physical Address................: 0060.5C75.BD52
       Link-local IPv6 Address.........: FE80::260:5CFF:FE75:BD52
       IPv6 Address....................: ::
       IPv4 Address....................: 192.168.0.7
       Subnet Mask.....................: 255.255.254.0
       Default Gateway.................: ::
                                         192.168.1.250
       DHCP Servers....................: 192.168.1.253
       DHCPv6 IAID.....................: 
       DHCPv6 Client DUID..............: 0003000100605C75BD52
       DNS Servers.....................: ::
                                         0.0.0.0
  18. Navigate back to BaySwitch1. Save your configuration with copy running-config startup-config command.
  19. BaySwitch1# copy running-config startup-config
    Destination filename [startup-config]?
    Building configuration...
    [OK]
  20. Enter the show port-security command to view the port-security configuration.
  21. BaySwitch1# show port-security
    Secure Port MaxSecureAddr CurrentAddr SecurityViolation Security Action
                   (Count)       (Count)        (Count)
    --------------------------------------------------------------------
           Gig1/3        1          1                 0         Shutdown
           Gig1/4        1          1                 0         Shutdown
           Gig1/5        1          1                 0         Shutdown
    ---------------------------------------------------------------------
  22. Enter the show port-security address command to view the port-security configuration. The sticky MAC address should be the same as the MAC address of MU1.
  23. BaySwitch1# show port-security address
                   Secure Mac Address Table
    -----------------------------------------------------------------------------
    Vlan    Mac Address       Type                          Ports   Remaining Age
                                                                       (mins)
    ----    -----------       ----                          -----   -------------
       1    0060.5C75.BD52    SecureSticky                  Gig1/3       -
       1    000C.85BD.3DB3    SecureSticky                  Gig1/4       -
       1    00D0.58EC.A51A    SecureSticky                  Gig1/5       -
    -----------------------------------------------------------------------------
    Total Addresses in System (excluding one mac per port)     : 0
    Max Addresses limit in System (excluding one mac per port) : 1024
  24. Test your configuration by moving the cable from MU1 to the Rogue Access Point. Click the fast-forward time button below the topology window and to the left, to accelerate network processes until the status of the port Gig1/3 changes. You should see the link lights turn red on that cable. You should see the following messages in BaySwitch1 CLI.
  25. BaySwitch1#
    %LINK-5-CHANGED: Interface GigabitEthernet1/3, changed state to up
    
    %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/3, changed state to up
    
    %LINK-3-UPDOWN: Interface GigabitEthernet1/3, changed state to down
    
    %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/3, changed state to down
    
    %LINK-5-CHANGED: Interface GigabitEthernet1/3, changed state to up
    
    %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/3, changed state to up
    
    %LINK-5-CHANGED: Interface GigabitEthernet1/3, changed state to administratively down
    
    %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/3, changed state to down
    %PM-4-ERR_DISABLE: psecure-violation error detected on Gig1/3, putting Gig1/3 in err-disable state.
    %PORT_SECURITY-2-PSECURE_VIOLATION: Security violation occurred, caused by MAC address 00D0.FF75.00E5 on port GigabitEthernet1/3.
    A port security violation has occurred and port Gig1/3 has been shut down.
    Note: If the interface does not shutdown, you may need to generate some traffic for the switch to see that a device with a new MAC address is connected to the port. To do this, ping any IP address on the network from the command prompt of the Rogue Laptop.
  26. Reactivate the port.
    1. Move the cable back to the G0 interface of MU1.
    2. In global configuration mode, enter the following commands.
    BaySwitch1# configure terminal
    BaySwitch1(config)# interface g1/3
    BaySwitch1(config-if)# shutdown
    
    %LINK-5-CHANGED: Interface GigabitEthernet1/3, changed state to administratively down
    BaySwitch1(config-if)# no shutdown
    
    BaySwitch1(config-if)#
    %LINK-5-CHANGED: Interface GigabitEthernet1/3, changed state to up
    
    %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet1/3, changed state to up
    You should see the port change state to up.

Part 2: Mitigate Rogue DHCP Server Vulnerabilities.

If a threat actor is able to physically access a network, they could run a rogue DHCP server on their device. This could cause multiple devices to eventually configure with addresses in IP networks that are not normally used. This could cause important devices in the network to become unreachable. This is called a DHCP spoofing attack. In addition, threat actors could set the default gateway configured in DHCP to their own IP address, thus causing hosts to direct traffic that is to be sent outside the substation network to the threat actors’ devices instead. Hacker tools can also be used to forward that traffic on to the actual default gateway, thus performing an on-path attack.

Because this type of attack is relatively easy to execute when physical access to the network is obtained, switches can be configured with a feature called DHCP snooping that prevents DHCP traffic from being forwarded through untrusted switchports. You will configure switch BaySwitch1 with DHCP snooping.

Step 1: Determine trusted and untrusted ports.

Look at the topology diagram.

Where does DHCP configuration information come from across the network? Through which port on BaySwitch1? This should be the trusted port.
Answer Area
The DHCP server is attached to StationBusSwitch. The link between StationBusSwitch and BaySwitch1 is through port Gig1/1.
Which ports should not receive traffic from a DHCP server? These will be untrusted ports.
Answer Area
The access ports that have connections to the MU1, IED1 and IED2 devices. These are ports Gig1/3, 4, and 5.

Step 2: Configure DHCP Snooping.

  1. In global configuration mode, activate DHCP snooping.
  2. BaySwitch1(config)# ip dhcp snooping
  3. Configure interface Gig1/1 as the trusted interface.
  4. BaySwitch1(config)# interface g1/1
    BaySwitch1(config-if)# ip dhcp snooping trust
  5. On the untrusted interfaces, rate limit DHCP discovery messages.
  6. BaySwitch1(config-if)# interface range g1/3-5
    BaySwitch1(config-if-range)# ip dhcp snooping limit rate 6
  7. Verify configuration using the show ip dhcp snooping command in Privileged EXEC mode.
  8. BaySwitch1# show ip dhcp snooping
    <output omitted>
    DHCP snooping trust/rate is configured on the following Interfaces:
    
    Interface                  Trusted    Allow option    Rate limit (pps)
    -----------------------    -------    ------------    ----------------
    GigabitEthernet1/1         yes        yes             unlimited       
      Custom circuit-ids:
    GigabitEthernet1/2         no         no              unlimited       
      Custom circuit-ids:
    GigabitEthernet1/3         no         no              6               
      Custom circuit-ids:
    GigabitEthernet1/6         no         no              unlimited       
      Custom circuit-ids:
    GigabitEthernet1/7         no         no              unlimited       
      Custom circuit-ids:
    GigabitEthernet1/10        no         no              unlimited       
      Custom circuit-ids:
    GigabitEthernet1/8         no         no              unlimited       
      Custom circuit-ids:
    GigabitEthernet1/5         no         no              6               
      Custom circuit-ids:
    GigabitEthernet1/4         no         no              6               
      Custom circuit-ids:
    GigabitEthernet1/9         no         no              unlimited  

Part 3: Improve Password Security

An important part of hardening network devices is securing access to the device management plane. In this part of the activity, you will increase security by encrypting all passwords in the device configuration file, set password requirements to ensure stronger password protection, and control the number of failed login attempts to mitigate brute force attacks. You will be configuring the SubstationCoreRouter in the Substation cloud.

Step 1: Configure passwords.

  1. Enter the Substation cloud and open the CLI of SubstationCoreRouter.
  2. Configure the following passwords:
    • Enable password (not enable secret password): cisco
    • Line password: class
    • Console password: class
    SubstationCoreRouter(config)# enable password cisco
    SubstationCoreRouter(config)# line vty 0 4
    SubstationCoreRouter(config-line)# password class
    SubstationCoreRouter(config-line)# line console 0
    SubstationCoreRouter(config-line)# password class
    Note: These passwords do not meet standards for strong passwords. The passwords in use here simplify the process of configuring and logging into devices for the purpose of this learning activity only. In addition, we are using the unencrypted enable password as an example. It is a best practice to always use the enable secret password, which is encrypted.
  3. Enter the show running-config command. Look for the enable and line passwords that you just entered.
  4. Network administrators often back up their configuration files to servers. The configuration files are stored in clear text.
How does this pose a security risk?
Answer Area
Unauthorized users could access the configuration files on the file server to learn the passwords of various networking devices.

Step 2: Encrypt clear text passwords.

  1. Go to global configuration mode on the SubstationCoreRouter.
  2. Enter the command to encrypt all clear text passwords in the configuration file.
  3. SubstationCoreRouter(config)# service password-encryption
  4. Display the running configuration again and look for the three passwords that configured in the previous step.
What do you observe regarding the passwords?
Answer Area
The passwords are now encrypted.

Step 3: Set password requirements

Organizations establish security policies regarding the features of passwords that are acceptable for use. These policies specify the password length and the required mix of characters (alpha, numeric, and special) that should be used. You can configure the required minimum length of user and enable passwords in IOS.

  1. Enter global configuration mode on the SubstationCoreRouter router.
  2. Enter the following to view the help for the command.
  3. SubstationCoreRouter(config)# security passwords min-length ?
      <0-16>  Minimum length of all user/enable passwords
What are the possible password lengths that are available?
Answer Area
From 0 to 16 characters.
  1. We will use a minimum length of 10 characters. Enter the command and specify the length.
  2. SubstationCoreRouter(config)# security password min-length 10
  3. Enter a username and password with username admin and password cisco.
  4. SubstationCoreRouter(config)# username admin password cisco
How did the CLI respond?
Answer Area
% Password too short - must be at least 10 characters. Password not configured.
  1. Now reenter the command with password Cisco1234!
  2. SubstationCoreRouter(config)# username admin password Cisco1234!
  3. Reconfigure the enable password 5678Cisco!.
  4. Now view the user and enable passwords in the configuration file.
  5. SubstationCoreRouter# show running-config | section user
    username admin password 7 0802455D0A165445415F4D
    
    SubstationCoreRouter# show run | section enable
    enable password 7 08741A19513A0C0411044D

Step 4: Control login attempts.

Cisco IOS permits specifying a consequence for repeated failed login attempts over a specified period of time. This will block repeated logins if a threat actor is trying to brute force the password or a DoS attack on a virtual terminal line is under way.

  1. Go to global configuration mode on SubstationCoreRouter.
  2. Enter the following command.
  3. SubstationCoreRouter(config)# login block-for 120 attempts 5 within 60
    This command specifies that logins should be blocked for 120 seconds if 5 failed attempts are made over a period of 60 seconds.

Summary

In this activity, you have taken steps to enhance the security of a network and network devices. There are a number of other best practices for device hardening that were omitted from this activity for the sake of brevity. While there are many ways to secure a network, in a defense in depth approach, securing networking devices has an important role in overall network security.

Answer Scripts

Switch BaySwitch1

enable
configure terminal
ip dhcp snooping
interface range g1/3-5
 ip dhcp snooping limit rate 6
 switchport mode access
 switchport port-security max 1
 switchport port-security violation shutdown
 switchport port-security mac-address sticky
 switchport port-security
interface range g1/2, g1/6-10
 shutdown
 switchport access vlan 999
interface gigabitEthernet1/1
 ip dhcp snooping trust
end

Router SubstationCoreRouter

enable
configure terminal
service password-encryption
security password min-length 10
username admin password Cisco1234!
enable password 5678Cisco!
line vty 0 4
 password class
line console 0
 password class
login block-for 120 attempts 5 within 60
end

© 2024 - 2025 Cisco and/or its affiliates. All rights reserved. Cisco Public