Wednesday, March 29, 2017

Packet capture samples

Some times I want to quickly look at a sample packet capture of some protocol but its not readily available somewhere in internet to download. So I thought of making a list.


1) BGP packet capture - https://drive.google.com/open?id=0B3ctVg8ubiwUa0FBZm5OM3dndE0

2) RADIUS packet capture - https://drive.google.com/open?id=0B3ctVg8ubiwUQlA5R0tEQWtTdmc

3) IPsec - isakmp - ESP  capture  - https://drive.google.com/open?id=0B3ctVg8ubiwUYWxkWTNJMER2dEk

4) Wifi 4-way handshake - https://drive.google.com/file/d/0B3ctVg8ubiwUMDYwWXJ2c2taMlE/view?usp=sharing

5) RSTP synchronization proposal and root election - https://drive.google.com/open?id=0B3ctVg8ubiwUMlQ4dHBPM1dGSEk

6) OSPF-with-LSA-types-1, 3, 4 and 5 -  https://drive.google.com/open?id=0B3ctVg8ubiwUVGNXeEQwNUdOd1k

7) Multiple spanning tree (MST) - https://drive.google.com/open?id=0B3ctVg8ubiwUeTVHLW0wQmZLeEU

8) RADIUS CoA, captured from Cisco ISE - https://drive.google.com/open?id=0B3ctVg8ubiwUYkE2ZEFVTGFBcTQ

9) EAP-FAST authentication RADIUS pkt capture from Cisco ISE - https://drive.google.com/open?id=0B3ctVg8ubiwUX3A3dVJrdU55MXc

10) WIFI CoA with RADIUS pkts - https://drive.google.com/open?id=0B3ctVg8ubiwUWG1nWHBfRmVoTDQ

11) AWS Greengrass IoT MQTT - https://drive.google.com/open?id=1W8n23dJAxhcrgwnMbFAcEaO6cEQQL2Ga

Monday, January 30, 2017

Aerohive HMNG API "Refreshing a Token"

based on :  https://developer.aerohive.com


1)  Using endpoint https://cloud.aerohive.com/services/oauth2/token

POST : https://cloud.aerohive.com/services/oauth2/token?grant_type=refresh_token&refresh_token=VephPaRwBhTR60Zg14cCIbWsB7SCqPnV


Content-Type : application/x-www-form-urlencoded
Authorization : Basic OTU4NzY4NDE6ODY0OTM4MA4YTU3NzlkNzEwY2QwNDdjNmIxMTlkZTg=
























2) [NOT recommended] Using endpoint : https://cloud.aerohive.com/services/acct/thirdparty/refreshtoken 

POST : https://cloud.aerohive.com/services/acct/thirdparty/refreshtoken?refreshToken=0-GI5UcUKqi9foTrE_-k6z6OMLDDnJtK

X-AH-API-CLIENT-ID : 9587841
X-AH-API-CLIENT-SECRET : 86493008a5779d710cd047c6b119de8
X-AH-API-CLIENT-REDIRECT-URI : https://apache.testneta.local



Friday, December 9, 2016

SNMPv3 with Aerohive APs and Net-SNMP

In this blog post I am going to explain how to configure SNMPv3 in Aerohive APs and test using Net-SNMP,














SNMPv3 introduce 3 different types of authentication/security methods,

1) NoauthNoPriv - only username is used, NO encryption
2) authNoPriv      - username and password is used but NO encryption
3) authPriv           - username, password and encryption




Give below are few thing that need to be configured to allow SNMP access to the Aerohive AP,













1) This is how to configure NoauthNoPriv in Aerohive AP (using HiveManager)





Use this command in Net-SNMP to do a snmpwalk,



snmpwalk -v 3 -u user1 -l NoauthNoPriv 172.16.1.75







2) This is how to configure authNoPriv in Aerohive AP (using HiveManager)




Use this command in Net-SNMP to do a snmpwalk,


snmpwalk -v 3 -u user1 -l authNoPriv 172.16.1.75 -a MD5 -A aerohive123 







3) This is how to configure authPriv in Aerohive AP (using HiveManager)




Use this command in Net-SNMP to do a snmpwalk,


snmpwalk -v 3 -u user1 -l authNPriv 172.16.1.75 -a MD5 -A aerohive123 -x AES -X 123aerohive






Monday, October 17, 2016

Enable https management interface in Aerohive SR2208P, SR2224P, SR2324P and SR2348P

1) SSH in to the switch,

username : admin
password  is under device management settings

















2) (AH-Switch) (Config)#crypto certificate generate


3) (AH-Switch) #ip http secure-server


4) (AH-Switch) #show ip http

HTTP Mode (Unsecure)........................... Disabled
Java Mode.................................................. Enabled
HTTP Port........................................................... 80
Maximum Allowable HTTP Sessions................... 3
HTTP Session Hard Timeout...................... 24 hours
HTTP Session Soft Timeout...................... 5 minutes

HTTP Mode (Secure)............................. Enabled
Secure Port..................................................... 443
Secure Protocol Level(s)................... TLS1 SSL3
Maximum Allowable HTTPS Sessions............. 4
HTTPS session hard timeout................. 24 hours
HTTPS session soft timeout................ 5 minutes
Certificate Present........................................ True
Certificate Generation In Progress............. False



5) Access the web interface using the management IP address



Monday, October 10, 2016

Aerohive SR2224P port routing configuration example

With this configuration one physical port need to be allocated per subnet





---  in configure ----



ip routing         %enable routing globally 


interface 1/0/1
routing
ip address 192.168.1.1 255.255.255.0
exit
                  

interface 1/0/2
routing
ip address 192.168.2.1 255.255.255.0
exit





Sunday, October 9, 2016

Aerohive 2324P , 2348P SFP not working, how to fix ?

If you run in to the issue that in SR2348P and SR2324 SFPs doesn’t link up (LED not turning on when the SFP and cables are connected from one switch to another),

probably its a speed mismatch issue , SFP doesn’t work in auto mode. Set the speed according to the SFP module you are using, 

(AH-Switch)# show port all 

1/0/49           Enable    Auto                  Down   Enable  Enable long
1/0/50           Enable    Auto                  Down   Enable  Enable long
1/0/51           Enable    Auto                  Down   Enable  Enable long
1/0/52           Enable    10G Full   10G Full   Up     Enable  Enable long



Check the SFP ports to see whether they are set to auto or a specific speed. Set the speed in the switch port in both sides of the switch ,

(AH-Switch) (Interface 1/0/49)#speed 10G full-duplex
(AH-Switch) (Interface 1/0/50)#speed 10G full-duplex
(AH-Switch) (Interface 1/0/51)#speed 10G full-duplex

(AH-Switch) (Interface 1/0/52)#speed 10G full-duplex