Addressing Table
Objectives
In this activity, you will complete the following objectives:
- Part 1: Use a Sniffer to Monitor Network Traffic
- Part 2: Use CyberObserver to Create a Device Inventory
- Part 3: Mitigate a Vulnerability
- Part 4: Implement Security Measures
Background / Scenario
In this activity, you will implement two different types of network monitoring using port-mirroring on a switch and a security and visibility security application designed to integrate IT and OT security practices.
Instructions
Part 1: Use A Sniffer to Monitor Network Traffic
In this part of the activity, you will implement network monitoring using port mirroring with the Switched Port Analyzer (SPAN) feature on a Cisco switch. SPAN enables you to capture and forward traffic entering or leaving designated switch ports. The traffic is mirrored to a network monitoring device for analysis. This enables real-time detection of problematic network traffic.
Step 1: Verify connectivity and configure the sniffer.
In this step, you will verify end-to-end connectivity and verify the configuration on the sniffer. The privileged EXEC password is class and the VTY password is cisco, for simplicity.
- From the PC, you should be able to ping the interfaces in the 172.16.0.0/23 network on Inside_Router, Switch, and Inside_Server.
- Access the Sniffer and click GUI.
- Verify Service is set to On. Select On to enable the Service.
- Click the Show All/None button to deselect all protocols. Click Edit Filters and select only ICMP.
- Click Clear to remove any existing events.
- Leave the Sniffer window open.
Step 2: Configure Local SPAN on Switch and capture copied traffic.
To configure Local SPAN you designate one or more source ports and a single destination port for copied or mirrored traffic to be sent out from. SPAN source ports can be configured to monitor traffic in either ingress or egress, or both directions (default). Both source and destination SPAN ports are called monitored ports.
The SPAN source port will need to be configured on the port that connects to the router on Switch switchport G1/0/24. All traffic entering or exiting the LAN, via the router, will be monitored. The SPAN destination port will be configured on Switch switchport G1/0/23 which is connected to a sniffer.
- Access Switch and configure a monitoring session by designating the source and destination monitor ports. Now all traffic entering or leaving G1/0/24 will be copied and forwarded out of G1/0/23.
- Verify SPAN configuration for session 1.
Switch(config)# monitor session 1 source interface g1/0/24 Switch(config)# monitor session 1 destination interface g1/0/23 Switch(config)# exit
Switch# show monitor session 1
Session 1
---------
Type : Local Session
Description : -
Source Ports :
Both : Gig1/0/24
Destination Ports : Gig1/0/23
Encapsulation : Native
Ingress : DisabledStep 3: Create ICMP traffic on the LAN.
- Connect Switch to Inside_Router with SSH using user account admin. The password is cisco. Note: In the ssh command, the option -l is letter l for login name, not -1 as a number.
- From privileged EXEC mode, ping Inside_Server and PC. The IP address assigned to PC via DHCP may be different than the example below.
Switch# ssh -l admin 172.16.1.254 Password: Inside_Router#
Inside_Router# ping 172.16.1.220 Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 172.16.1.220, timeout is 2 seconds: .!!!! Success rate is 80 percent (4/5), round-trip min/avg/max = 0/6/32 ms Inside_Router# ping <DHCP assigned IP address for PC> Type escape sequence to abort. Sending 5, 100-byte ICMP Echos to 172.16.0.3, timeout is 2 seconds: .!!!! Success rate is 80 percent (4/5), round-trip min/avg/max = 0/7/14 ms
Step 4: Examine the ICMP packets.
- Return to Sniffer.
- Examine the captured ICMP packets. Click each ICMP packet in the scrolling window on the left and scroll down to the ICMP header in the protocol Window on the right. Note the source and destination IP addresses for the ICMP packets.
Part 2: Use CyberObserver to Create a Device Inventory
As one part of a network security approach, it is important to know what devices are authorized to be on your network and details about the devices such as the manufacturer and model, software in use, and the software versions that they run. Network visibility devices can automatically conduct a device inventory, gather information about each device, and detect unauthorized devices as they attach to the network. In this part of the activity, you will use a network visibility device known as CyberObserver. The CyberObserver in Packet Tracer is for demonstration purposes only.
Step 1: Verify connectivity to CyberObserver.
- Connect the G0 port on CyberObserver to any available port on Switch using a copper straight-through cable.
- From Engineering, verify connectivity to CyberObserver by pinging cyberobserver from the Command Prompt.
- Using a web browser on Engineering, enter cyberobserver as the URL to navigate to CyberObserver. Log into CyberObserver using the admin account with the password cisco.
C:/> ping cyberobserver
Step 2: Create an inventory of devices.
- Click the menu and select Provisioning. Select the DISCOVERY tab and then the +DISCOVERY button.
- In the New Discovery dialog window, enter a name of your choice for the new discovery and 172.16.1.230 as the inside IP address for the CyberObserver device. Select the checkbox Use Sensor and click ADD to continue.
- The discovery process could take a few minutes. After the discovery process is done, click NETWORK DEVICE to view the inventory of devices. Review the inventory list.
Step 3: Remove false alarm.
Because this is the first time that the CyberObserver is connected to the network, you can assume all the devices detected are allowed on the network for this activity.- From the CyberObserver webpage, click the menu and select Dashboard.
- In the Dashboard, two network vulnerabilities are reported for two PLC devices. You will resolve these issues later in this activity.
- Under Network Issues heading, click Delete to remove any detected rogue devices as necessary. The Network Issues portion of the Dashboard should be empty now.
Part 3: Mitigate a Vulnerability
In this part, you will use CyberObserver to address a critical security issue by locating and updating the vulnerable firmware in a PLC.
Step 1: Document CVE.
You have been tasked to update the firmware on some of the PLCs that are operating in your facility. You can use the capabilities of the CyberObserver to locate the vulnerable PLCs that are using the outdated firmware, which is version 1.0.0.
- Navigate to Dashboard on Cyberobserver as needed. Notice the vulnerability on the PLCs in Cell Zones 2 and 3.
- Click the menu and navigate to Provisioning > VULNERABILITY DATABASE. Note the information for a vulnerability that is already added to the Vulnerability Database.
- Navigate back to the Dashboard on Cyberobserver and leave the web page on CyberObserver open.
Step 2: Update firmware.
The IT department has already downloaded the latest firmware to Inside_Server and verified the authenticity of the file.- On PC, use a web browser to navigate to Inside_Server (172.16.1.220 or insideserver).
- Click the latest firmware link to download the firmware.
- Close the web browser and open the PT Industrial Automation App.
- Click Devices > Discover and Config. Under the Update Firmware heading, enter the IP address of the PLC with the vulnerability in the Device IP address field. Enter the location of the downloaded firmware that you recorded above. Click Upload to continue. You should receive the following message:
- Return to Engineering. After a brief delay, one of the listed network vulnerabilities will be removed from the list. In the Network Device list, notice the PLC firmware version has updated to 2.2.3.
- Repeat the previous steps for the other PLC to resolve the vulnerabilities.
- Leave the CyberObserver web page open on Engineering.
Status: FIRMWARE_UPDATE_SUCCESSFUL
Part 4: Implement Security Measures
In this part, you will use CyberObserver to monitor and prevent rogue devices from accessing the network. You will configure an ACL via CyberObserver and upload to Inside_Router.Step 1: Set up for rogue device detection.
Inside_Router has been configured with the username admin and password cisco.- Navigate to Inside_Router. Enter the command show access-lists to display all the currently configured access lists.
- In CyberObserver, click the menu and select Provisioning. Select the CREDENTIALS tab and click the +CREDENTIAL button to create new credentials for access to Inside_Router.
- Enter admin as the username and cisco as the password. Leave the enable password field empty. Enter the description of your choice. Click OKAY to continue.
- In the NETWORK DEVICE list, select the gear next to the Inside_Router entry. Under the CLI Configuration heading, select the newly created credentials.
- Copy and paste the following ACL into the CLI configuration gray text box. Click UPDATE to save the configuration, and you should receive the message Updated Successfully. The variable rogue_device in the ACL below will be replaced when the Cyber Observer detects a rogue device.
Inside_Router> enable
Inside_Router# show access-lists
Standard IP access list 1
10 permit 172.16.0.0 0.0.1.255
interface GigabitEthernet0/0/0 ip access-group Cyber_Observer_Mitigation_Acl in interface GigabitEthernet0/0/1 ip access-group Cyber_Observer_Mitigation_Acl in ip access-list extended Cyber_Observer_Mitigation_Acl deny ip host <rogue_device> any permit ip any any
Step 2: Detect the rogue device.
In this step, you will connect a rogue device to the inside network to test the mitigation function of Cyber Observer.- From the CyberObserver web site, navigate to the Dashboard (Menu > Dashboard). Verify that the Dashboard does not show any rogue devices. Delete any as necessary.
- Connect Rogue_PC to any available port on Switch using a copper straight-through cable.
- After adding Rogue_PC to the network, fast forward time and wait a few minutes until the network has updated.
- Return to the Dashboard (Menu > Dashboard) on CyberObserver. Review any network vulnerabilities or issues. Be patient it may take a few minutes for issues to display.
Step 3: Deny network access.
In a previous step, you configured an ACL on the CyberObserver that will be implemented by Inside_Router when a rogue device is detected. This ACL will prevent Rogue_PC from accessing Inside_Router and the networks attached to it.- From Rogue_PC, ping Inside_Router (172.16.1.254), from the command prompt.
- Navigate to Inside_Router. Issue the command to display the access list that denies network access to the rogue device. When you ping 172.16.1.254 from Rogue_PC, a match is made to the deny statement as shown in the show command results.
- Disconnect Rogue_PC from the network by deleting the cable that it connects it. Click Delete from the CyberObserver Dashboard to remove the rogue device network issue. Reload the router to remove the added access list, which has not been saved in the configuration.
Inside_Router# show access-lists Cyber_Observer_Mitigation_Acl
Extended IP access list Cyber_Observer_Mitigation_Acl
deny ip host 172.16.0.100 any (4 match(es))
permit ip any any (267 match(es))
Inside_Router# reload Proceed with reload? [confirm]