Académique Documents
Professionnel Documents
Culture Documents
configuration mistakes
2
/
andis[at]router.lv
www.linkedin.com/in/andisarins
MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv
10
MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv
Lack of monitoring
9
MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv
Lack of monitoring
Lack of monitoring
Lack of monitoring
9
IP - SNMP
/snmp> send-trap
for proactive
action
Lack of monitoring
The Dude
you can monitor and
manage your devices
10
Lack of monitoring
11
toolsnetwatch
Lack of monitoring
12
toolsTraffic monitor
Lack of monitoring
IP- Traffic Flow
13
Lack of monitoring
Also HA solutions without monitoring may fail one day
VRRP for 99.9%+
availability
0.365 days or
8.76 hours
down in year
14
DNS issues
15
8
MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv
DNS issues
16
Many requests from
spoofed IPs
VICTIM
MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv
DNS issues
17
10.0.0.0/24
Firewall inefficiency
18
7
MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv
Firewall inefficiency
internet
19
123.123.123.123
webserver
NAT issues
20
6
MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv
NAT issues
21
10.0.0.0/24
123.123.123.123
159.148.147.196
src-ip: 10.0.0.10
dst-ip: 159.148.147.196
NAT
masquarade
src-ip: 10.0.0.10
src-ip: 123.123.123.123
dst-ip: 159.148.147.196
NAT issues
22
10.1.1.0/24
10.0.0.0/24
10.1.1.0/24
123.123.123.0/24
bad
ok
ok
NAT issues
23
192.168.0.0/24
10.0.0.0/24
IPSec
Allowed IP Spoofing
5
MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv
24
Allowed IP Spoofing
10.0.0.0/24
src-ip: 13.13.13.13
dst-ip: 159.148.147.196
25
123.123.123.123
1. routing decision
2. firewall decision
Allowed IP Spoofing
Tools- Traffic Generator
26
Allowed IP Spoofing
Test your network
https://spoofer.caida.org/
http://ieeexplore.ieee.org/
27
Allowed IP Spoofing
28
10.0.0.0/24
src-ip: 13.13.13.13
dst-ip: 159.148.147.196
routing
decision
Bridge issues
29
4
MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv
Bridge issues
30
Bridge issues
wan
31
master slave
slave
slave
lan
bridge
Bridge issues
32
bridge-lan
PoE issues
33
3
MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv
PoE issues
34
Mikrotik PoE standart
(4,5pin +) (7,8pin -)
PoE issues
35
DC adaper
DC power 1
eth1
PoE in
data,power 2
2
MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv
36
37
38
39
Try to Guess
40
1
MUM USA, Dallas 2016.04.28 Andis Arins / WISP TRACON | router.lv
admin / no password
41
admin / no password
42
Thats it!