Incomplete Packet Tracer - Monitoring Network Security

Addressing Table

Device Interface IP Address Subnet Mask Default Gateway
PC NIC DHCP
Rogue_PC NIC DHCP
Inside_Server NIC 172.16.1.220 (inside)
192.168.10.220 (outside)
255.255.254.0 172.16.1.254
Inside_Router G0/0/0 192.168.10.1 255.255.255.0 192.168.10.254
G0/0/1 172.16.1.254 255.255.254.0 172.16.1.254
Switch VLAN 1 172.16.1.250 255.255.254.0 172.16.1.254
CyberObserver NIC 172.16.1.230 (inside)
192.168.10.230 (outside)
255.255.254.0 172.16.1.254
Engineering NIC DHCP
Enterprise_Server NIC 192.168.10.250 255.255.255.0 192.168.10.254
PLC1 NIC 172.16.1.251 255.255.254.0 172.16.1.254
PLC2 NIC 172.16.1.252 255.255.254.0 172.16.1.254
PLC3 NIC 172.16.1.253 255.255.254.0 172.16.1.254

Objectives

In this activity, you will complete the following objectives:

  • Part 1: Use a Sniffer to Monitor Network Traffic
  • Part 2: Use CyberObserver to Create a Device Inventory
  • Part 3: Mitigate a Vulnerability
  • Part 4: Implement Security Measures

Background / Scenario

In this activity, you will implement two different types of network monitoring using port-mirroring on a switch and a security and visibility security application designed to integrate IT and OT security practices.

Instructions

Part 1: Use A Sniffer to Monitor Network Traffic

In this part of the activity, you will implement network monitoring using port mirroring with the Switched Port Analyzer (SPAN) feature on a Cisco switch. SPAN enables you to capture and forward traffic entering or leaving designated switch ports. The traffic is mirrored to a network monitoring device for analysis. This enables real-time detection of problematic network traffic.

Step 1: Verify connectivity and configure the sniffer.

In this step, you will verify end-to-end connectivity and verify the configuration on the sniffer. The privileged EXEC password is class and the VTY password is cisco, for simplicity.

  1. From the PC, you should be able to ping the interfaces in the 172.16.0.0/23 network on Inside_Router, Switch, and Inside_Server.
  2. Access the Sniffer and click GUI.
  3. Verify Service is set to On. Select On to enable the Service.
  4. Click the Show All/None button to deselect all protocols. Click Edit Filters and select only ICMP.
  5. Click Clear to remove any existing events.
  6. Leave the Sniffer window open.

Step 2: Configure Local SPAN on Switch and capture copied traffic.

To configure Local SPAN you designate one or more source ports and a single destination port for copied or mirrored traffic to be sent out from. SPAN source ports can be configured to monitor traffic in either ingress or egress, or both directions (default). Both source and destination SPAN ports are called monitored ports.

The SPAN source port will need to be configured on the port that connects to the router on Switch switchport G1/0/24. All traffic entering or exiting the LAN, via the router, will be monitored. The SPAN destination port will be configured on Switch switchport G1/0/23 which is connected to a sniffer.

  1. Access Switch and configure a monitoring session by designating the source and destination monitor ports. Now all traffic entering or leaving G1/0/24 will be copied and forwarded out of G1/0/23.
  2. Switch(config)# monitor session 1 source interface g1/0/24
    Switch(config)# monitor session 1 destination interface g1/0/23
    Switch(config)# exit
  3. Verify SPAN configuration for session 1.
  4. Switch# show monitor session 1
    Session 1
    ---------
    Type                   : Local Session
    Description            : -
    Source Ports           : 
        Both               : Gig1/0/24
    Destination Ports      : Gig1/0/23
        Encapsulation      : Native
              Ingress      : Disabled

Step 3: Create ICMP traffic on the LAN.

  1. Connect Switch to Inside_Router with SSH using user account admin. The password is cisco. Note: In the ssh command, the option -l is letter l for login name, not -1 as a number.
  2. Switch# ssh -l admin 172.16.1.254
    
    Password: 
    
    
    
    Inside_Router#
  3. From privileged EXEC mode, ping Inside_Server and PC. The IP address assigned to PC via DHCP may be different than the example below.
  4. Inside_Router# ping 172.16.1.220
    
    Type escape sequence to abort.
    Sending 5, 100-byte ICMP Echos to 172.16.1.220, timeout is 2 seconds:
    .!!!!
    Success rate is 80 percent (4/5), round-trip min/avg/max = 0/6/32 ms
    
    Inside_Router# ping <DHCP assigned IP address for PC>
    
    Type escape sequence to abort.
    Sending 5, 100-byte ICMP Echos to 172.16.0.3, timeout is 2 seconds:
    .!!!!
    Success rate is 80 percent (4/5), round-trip min/avg/max = 0/7/14 ms

Step 4: Examine the ICMP packets.

  1. Return to Sniffer.
  2. Examine the captured ICMP packets. Click each ICMP packet in the scrolling window on the left and scroll down to the ICMP header in the protocol Window on the right. Note the source and destination IP addresses for the ICMP packets.
Were the pings from Inside_Router to PC and Inside_Server successfully copied and forwarded out G1/0/23 to Sniffer? Was the traffic monitored and copied in both directions?
Answer Area
The pings were successful, and the traffic was monitored and copied in both directions.

Part 2: Use CyberObserver to Create a Device Inventory

As one part of a network security approach, it is important to know what devices are authorized to be on your network and details about the devices such as the manufacturer and model, software in use, and the software versions that they run. Network visibility devices can automatically conduct a device inventory, gather information about each device, and detect unauthorized devices as they attach to the network. In this part of the activity, you will use a network visibility device known as CyberObserver. The CyberObserver in Packet Tracer is for demonstration purposes only.

Step 1: Verify connectivity to CyberObserver.

  1. Connect the G0 port on CyberObserver to any available port on Switch using a copper straight-through cable.
  2. From Engineering, verify connectivity to CyberObserver by pinging cyberobserver from the Command Prompt.
  3. C:/> ping cyberobserver
  4. Using a web browser on Engineering, enter cyberobserver as the URL to navigate to CyberObserver. Log into CyberObserver using the admin account with the password cisco.

Step 2: Create an inventory of devices.

  1. Click the menu and select Provisioning. Select the DISCOVERY tab and then the +DISCOVERY button.
  2. In the New Discovery dialog window, enter a name of your choice for the new discovery and 172.16.1.230 as the inside IP address for the CyberObserver device. Select the checkbox Use Sensor and click ADD to continue.
  3. The discovery process could take a few minutes. After the discovery process is done, click NETWORK DEVICE to view the inventory of devices. Review the inventory list.

Step 3: Remove false alarm.

Because this is the first time that the CyberObserver is connected to the network, you can assume all the devices detected are allowed on the network for this activity.
  1. From the CyberObserver webpage, click the menu and select Dashboard.
  2. In the Dashboard, two network vulnerabilities are reported for two PLC devices. You will resolve these issues later in this activity.
  3. Under Network Issues heading, click Delete to remove any detected rogue devices as necessary. The Network Issues portion of the Dashboard should be empty now.

Part 3: Mitigate a Vulnerability

In this part, you will use CyberObserver to address a critical security issue by locating and updating the vulnerable firmware in a PLC.

Step 1: Document CVE.

You have been tasked to update the firmware on some of the PLCs that are operating in your facility. You can use the capabilities of the CyberObserver to locate the vulnerable PLCs that are using the outdated firmware, which is version 1.0.0.

  1. Navigate to Dashboard on Cyberobserver as needed. Notice the vulnerability on the PLCs in Cell Zones 2 and 3.
What are the IP addresses of PLCs with vulnerabilities?
Answer Area
The IP addresses are 172.16.1.252 and 172.16.1.253.
  1. Click the menu and navigate to Provisioning > VULNERABILITY DATABASE. Note the information for a vulnerability that is already added to the Vulnerability Database.
  2. Navigate back to the Dashboard on Cyberobserver and leave the web page on CyberObserver open.

Step 2: Update firmware.

The IT department has already downloaded the latest firmware to Inside_Server and verified the authenticity of the file.
  1. On PC, use a web browser to navigate to Inside_Server (172.16.1.220 or insideserver).
  2. Click the latest firmware link to download the firmware.
Record the location of the downloaded firmware.
Answer Area
C:/Downloads/firmware2.2.3.dat
  1. Close the web browser and open the PT Industrial Automation App.
  2. Click Devices > Discover and Config. Under the Update Firmware heading, enter the IP address of the PLC with the vulnerability in the Device IP address field. Enter the location of the downloaded firmware that you recorded above. Click Upload to continue. You should receive the following message:
  3. Status: FIRMWARE_UPDATE_SUCCESSFUL
  4. Return to Engineering. After a brief delay, one of the listed network vulnerabilities will be removed from the list. In the Network Device list, notice the PLC firmware version has updated to 2.2.3.
  5. Repeat the previous steps for the other PLC to resolve the vulnerabilities.
  6. Leave the CyberObserver web page open on Engineering.

Part 4: Implement Security Measures

In this part, you will use CyberObserver to monitor and prevent rogue devices from accessing the network. You will configure an ACL via CyberObserver and upload to Inside_Router.

Step 1: Set up for rogue device detection.

Inside_Router has been configured with the username admin and password cisco.
  1. Navigate to Inside_Router. Enter the command show access-lists to display all the currently configured access lists.
  2. Inside_Router> enable
    Inside_Router# show access-lists
    Standard IP access list 1
        10 permit 172.16.0.0 0.0.1.255
  3. In CyberObserver, click the menu and select Provisioning. Select the CREDENTIALS tab and click the +CREDENTIAL button to create new credentials for access to Inside_Router.
  4. Enter admin as the username and cisco as the password. Leave the enable password field empty. Enter the description of your choice. Click OKAY to continue.
  5. In the NETWORK DEVICE list, select the gear next to the Inside_Router entry. Under the CLI Configuration heading, select the newly created credentials.
  6. Copy and paste the following ACL into the CLI configuration gray text box. Click UPDATE to save the configuration, and you should receive the message Updated Successfully. The variable rogue_device in the ACL below will be replaced when the Cyber Observer detects a rogue device.
  7. interface GigabitEthernet0/0/0
     ip access-group Cyber_Observer_Mitigation_Acl in
    interface GigabitEthernet0/0/1
     ip access-group Cyber_Observer_Mitigation_Acl in
    ip access-list extended Cyber_Observer_Mitigation_Acl
     deny ip host <rogue_device> any
     permit ip any any

Step 2: Detect the rogue device.

In this step, you will connect a rogue device to the inside network to test the mitigation function of Cyber Observer.
  1. From the CyberObserver web site, navigate to the Dashboard (Menu > Dashboard). Verify that the Dashboard does not show any rogue devices. Delete any as necessary.
  2. Connect Rogue_PC to any available port on Switch using a copper straight-through cable.
  3. After adding Rogue_PC to the network, fast forward time and wait a few minutes until the network has updated.
  4. Return to the Dashboard (Menu > Dashboard) on CyberObserver. Review any network vulnerabilities or issues. Be patient it may take a few minutes for issues to display.
Record any network vulnerabilities or issues.
Answer Area
A rogue device, 172.16.0.100, is detected in the network. This is the Rogue_PC that you have just added to the network.

Step 3: Deny network access.

In a previous step, you configured an ACL on the CyberObserver that will be implemented by Inside_Router when a rogue device is detected. This ACL will prevent Rogue_PC from accessing Inside_Router and the networks attached to it.
  1. From Rogue_PC, ping Inside_Router (172.16.1.254), from the command prompt.
What was the ping results?
Answer Area
The ping was unsuccessful because it was blocked by the ACL on the Inside_Router that was uploaded from the CyberObserver.
  1. Navigate to Inside_Router. Issue the command to display the access list that denies network access to the rogue device. When you ping 172.16.1.254 from Rogue_PC, a match is made to the deny statement as shown in the show command results.
  2. Inside_Router# show access-lists Cyber_Observer_Mitigation_Acl
    Extended IP access list Cyber_Observer_Mitigation_Acl
         deny ip host 172.16.0.100 any (4 match(es))
         permit ip any any (267 match(es))
  3. Disconnect Rogue_PC from the network by deleting the cable that it connects it. Click Delete from the CyberObserver Dashboard to remove the rogue device network issue. Reload the router to remove the added access list, which has not been saved in the configuration.
  4. Inside_Router# reload
    Proceed with reload? [confirm]

Summary

In this activity, you have configured a simple network monitor using the port mirroring feature called SPAN that is available on Cisco switches. You have also used a network visibility and security device to create a device inventory, block a rogue device, and mitigate a software vulnerability present on two PLCs.

© 2024 - 2025 Cisco and/or its affiliates. All rights reserved. Cisco Public