<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7514463516099385727</id><updated>2012-01-24T14:43:07.871+04:00</updated><category term='bgp'/><category term='гост'/><category term='континент'/><category term='ccna_sec'/><category term='security'/><category term='ipt'/><category term='uc'/><category term='iscw'/><category term='госструктуры'/><category term='qos'/><category term='ospf'/><category term='comptia'/><category term='перс данные'/><category term='pppoe'/><category term='cisco'/><category term='certification'/><category term='junos'/><category term='wireless'/><category term='juniper'/><category term='expo'/><category term='eigrp'/><category term='routing'/><category term='vpn'/><category term='quick notes'/><category term='bsci notes'/><category term='redistribution'/><category term='isis'/><category term='ont'/><category term='ipv6'/><category term='multicast'/><title type='text'>Security Notes</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>59</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-3796650642701124320</id><published>2012-01-24T12:06:00.000+04:00</published><updated>2012-01-24T12:06:54.154+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='quick notes'/><category scheme='http://www.blogger.com/atom/ns#' term='ccna_sec'/><title type='text'>IOS CLI VIEWS</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;#enable view&lt;br /&gt;(config)#parser view VIEW_1&lt;br /&gt;(config-view)#secret cisco&lt;br /&gt;(config-view)#commands exec include all show&lt;br /&gt;(config-view)#commands exec include ping&lt;br /&gt;&lt;br /&gt;(config)#username helpdesk view VIEW_1 secret cisco&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Superview&lt;/b&gt;&lt;br /&gt;(config)#parser view SV superview&lt;br /&gt;(config-view)#view VIEW_1 //add view to superview. Superview combines commands from several views&lt;br /&gt;(config-view)#view VIEW_2&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-3796650642701124320?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/3796650642701124320/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=3796650642701124320' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/3796650642701124320'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/3796650642701124320'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2012/01/ios-cli-views.html' title='IOS CLI VIEWS'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-8421290507166122646</id><published>2012-01-24T11:29:00.000+04:00</published><updated>2012-01-24T11:29:33.813+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='quick notes'/><category scheme='http://www.blogger.com/atom/ns#' term='ccna_sec'/><title type='text'>AAA</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;radius udp:1645 udp:1812&lt;br /&gt;tacacs+ tcp:49&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-8421290507166122646?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/8421290507166122646/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=8421290507166122646' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/8421290507166122646'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/8421290507166122646'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2012/01/aaa.html' title='AAA'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-3757105556149000643</id><published>2012-01-19T12:28:00.001+04:00</published><updated>2012-01-19T12:34:19.199+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='quick notes'/><category scheme='http://www.blogger.com/atom/ns#' term='ccna_sec'/><title type='text'>ssh config</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;(config)# ip domain-name xxx.com&lt;br /&gt;(config)#crypto key generate rsa&lt;br /&gt;(config-line)#transport input ssh&lt;br /&gt;(config)#ip s sh version 2&lt;br /&gt;(config)#ip ssh time-out &amp;lt;1-120secs&amp;gt; //default 120&lt;br /&gt;(config)#ip ssh authentication-retries &amp;lt;0-5&amp;gt; //default 3&lt;br /&gt;&lt;br /&gt;sh users&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-3757105556149000643?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/3757105556149000643/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=3757105556149000643' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/3757105556149000643'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/3757105556149000643'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2012/01/ssh.html' title='ssh config'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-8150411019643133223</id><published>2012-01-19T12:24:00.000+04:00</published><updated>2012-01-19T12:24:23.675+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='quick notes'/><category scheme='http://www.blogger.com/atom/ns#' term='ccna_sec'/><title type='text'>SNMP</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;b&gt;snmp 1/2c&lt;/b&gt;&lt;br /&gt;config)#snmp-server community &lt;name&gt; ro&amp;nbsp;&lt;/name&gt;&lt;br /&gt;&lt;br /&gt;snmp 3&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-8150411019643133223?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/8150411019643133223/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=8150411019643133223' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/8150411019643133223'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/8150411019643133223'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2012/01/snmp.html' title='SNMP'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-5022564161746138616</id><published>2012-01-19T12:21:00.000+04:00</published><updated>2012-01-19T12:21:01.269+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cisco'/><category scheme='http://www.blogger.com/atom/ns#' term='quick notes'/><category scheme='http://www.blogger.com/atom/ns#' term='ccna_sec'/><title type='text'>logging config</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;(config)#logging buffered 4096 //логировать на флеш (до 4096 байт)&lt;br /&gt;(config)#logging xxx.xxx.xxx.xxx&lt;br /&gt;(config)#logging trap &amp;nbsp;//уровень логгирования. Рекомендуется 5 (notice)&lt;br /&gt;(config)# line vty 0 4&lt;br /&gt;(config-line)#logging synchronous &amp;nbsp;// вывод логов на консоль не мешает вводить команды&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;syslog-servers:&lt;br /&gt;-Kiwi syslog&lt;br /&gt;-Splunk&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-5022564161746138616?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/5022564161746138616/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=5022564161746138616' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/5022564161746138616'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/5022564161746138616'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2012/01/logging-config.html' title='logging config'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-7622341697490905634</id><published>2011-02-25T16:58:00.000+03:00</published><updated>2011-02-25T16:58:14.821+03:00</updated><title type='text'></title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;CISA&lt;br /&gt;CISSP&lt;br /&gt;&lt;span class="Apple-style-span" style="font-family: Helvetica, sans-serif; font-size: 12px; font-weight: bold;"&gt;CCSK&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-7622341697490905634?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/7622341697490905634/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=7622341697490905634' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/7622341697490905634'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/7622341697490905634'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2011/02/cisa-cissp-ccsk.html' title=''/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-2926694743806791023</id><published>2011-02-25T15:53:00.001+03:00</published><updated>2011-02-25T15:54:33.251+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='comptia'/><category scheme='http://www.blogger.com/atom/ns#' term='certification'/><title type='text'>ComTIA Sec+   Basics</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-size: large;"&gt;Defenses against Attacks&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;Although multiple defenses may be necessary to withstand an attack, these defenses should be&lt;br /&gt;based on five fundamental security principles: protecting systems by layering, limiting, diversity,&lt;br /&gt;obscurity, and simplicity. This section examines each of these principles, which provide a&lt;br /&gt;foundation for building a secure system.&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Layering&lt;/b&gt;&lt;br /&gt;The Hope diamond is a massive (45-carat) stone that by some estimates is worth one-quarter&lt;br /&gt;of a billion dollars. How are precious stones like the Hope diamond protected from theft? They&lt;br /&gt;are not openly displayed in public with a single security guard standing at the door. Instead,&lt;br /&gt;they are enclosed in protective cases that are bullet-proof, smash-proof, and resistant to almost&lt;br /&gt;any outside force. The cases are located in special rooms with massive walls and sensors that&lt;br /&gt;can detect slight movements or vibrations. The doors to the rooms are monitored around theclock by remote security cameras, and the video images from each camera are recorded on tape.&lt;br /&gt;The rooms are in buildings surrounded by roaming guards and fences. In short, precious stones&lt;br /&gt;are protected by layers of security. If one layer is penetrated—such as the thief getting into the&lt;br /&gt;building—several more layers must still be breached, with each layer being more difficult or&lt;br /&gt;complicated than the previous layer. A layered approach has the advantage of creating a barrier&lt;br /&gt;of multiple defenses that can be coordinated to thwart a variety of attacks.&lt;br /&gt;The Hope diamond has not always had multiple layers of security. In&lt;br /&gt;1958, this priceless diamond was placed in a plain brown paper wrapper&lt;br /&gt;and sent by registered first-class U.S. mail to the Smithsonian&lt;br /&gt;Institution! The envelope in which it was sent is on display at the&lt;br /&gt;Smithsonian along with the diamond itself.&lt;br /&gt;Information security must likewise be created in layers, because one defense mechanism&lt;br /&gt;may be relatively easy for an attacker to circumvent. Instead, a security system must have&lt;br /&gt;layers, making it unlikely that an attacker has the tools and skills to break through all the&lt;br /&gt;layers of defenses. A layered approach can also be useful in resisting a variety of attacks.&lt;br /&gt;Layered security provides the most comprehensive protection.&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Limiting&lt;/b&gt;&lt;br /&gt;Consider again protecting a precious diamond. Although a diamond may be on display for&lt;br /&gt;the general public to view, permitting anyone to touch the stone increases the chances that it&lt;br /&gt;will be stolen. Only approved personnel should be authorized to handle the diamond.&lt;br /&gt;Limiting who can access the diamond reduces the threat against it.&lt;br /&gt;The same is true with information security. Limiting access to information reduces the threat&lt;br /&gt;against it. Only those who must use data should have access to it. In addition, the amount of&lt;br /&gt;access granted to someone should be limited to what that person needs to know. For example,&lt;br /&gt;access to the human resource database for an organization should be limited to approved&lt;br /&gt;employees, including department managers and vice presidents. An entry-level computer&lt;br /&gt;technician might back up the database every day, but he should not be able to view the data,&lt;br /&gt;such as the salaries of the vice presidents, because he has no job-related need to do so.&lt;br /&gt;What level of access should users have? The best answer is the least&lt;br /&gt;amount necessary to do their jobs, and no more.&lt;br /&gt;Some ways to limit access are technology-based (such as assigning file permissions so that&lt;br /&gt;a user can only read but not modify a file), while others are procedural (prohibiting an&lt;br /&gt;employee from removing a sensitive document from the premises). The key is that access&lt;br /&gt;must be restricted to the bare minimum.&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Diversity&lt;/b&gt;&lt;br /&gt;Diversity is closely related to layering. Just as it is important to protect data with layers of&lt;br /&gt;security, so too must the layers be different (diverse) so that if attackers penetrate one layer,&lt;br /&gt;they cannot use the same techniques to break through all other layers. A jewel thief, for&lt;br /&gt;instance, might be able to foil the security camera by dressing in black clothes but should not&lt;br /&gt;be able to use the same technique to trick the motion detection system.&lt;br /&gt;Using diverse layers of defense means that breaching one security layer does not compromise&lt;br /&gt;the whole system. Diversity may be achieved in several ways. For example, some&lt;br /&gt;&lt;br /&gt;organizations use security products provided by different vendors. An attacker who can circumvent&lt;br /&gt;a Brand A device would have more difficulty trying to break through both Brand A&lt;br /&gt;and Brand B devices because they are different.&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Obscurity&lt;/b&gt;&lt;br /&gt;Suppose a thief plans to steal a precious diamond during a shift change of the security guards.&lt;br /&gt;When the thief observes the guards, however, she finds that the guards do not change shifts&lt;br /&gt;at the same time each night. On Monday they rotate shifts at 7:15 PM, while on Tuesday they&lt;br /&gt;rotate at 6:50 PM, and the following Monday at 6:25 PM. The thief cannot find out the times&lt;br /&gt;of these changes because they are kept secret. The thief, not knowing when a change takes&lt;br /&gt;place, cannot detect a clear pattern of times. Because the shift changes are confusing and not&lt;br /&gt;well known, an attack becomes more difficult. This technique is sometimes called “security&lt;br /&gt;by obscurity.” Obscuring what goes on inside a system or organization and avoiding clear&lt;br /&gt;patterns of behavior make attacks from the outside much more difficult.&lt;br /&gt;An example of obscurity would be not revealing the type of computer, operating system,&lt;br /&gt;software, and network connection a computer uses. An attacker who knows that information&lt;br /&gt;can more easily determine the weaknesses of the system to attack it. However, if this&lt;br /&gt;information is hidden, it takes much more effort to acquire the information and, in many&lt;br /&gt;instances, an attacker will then move on to another computer in which the information is&lt;br /&gt;easily available. Obscuring information can be an important way to protect information.&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;Simplicity&lt;/b&gt;&lt;br /&gt;Because attacks can come from a variety of sources and in many ways, information security&lt;br /&gt;is by its very nature complex. The more complex something becomes, the more difficult it is&lt;br /&gt;to understand. A security guard who does not understand how motion detectors interact with&lt;br /&gt;infrared trip lights may not know what to do when one system alarm shows an intruder but&lt;br /&gt;the other does not. In addition, complex systems allow many opportunities for something to&lt;br /&gt;go wrong. In short, complex systems can be a thief’s ally.&lt;br /&gt;The same is true with information security. Complex security systems can be hard to&lt;br /&gt;understand, troubleshoot, and feel secure about. As much as possible, a secure system should&lt;br /&gt;be simple for those on the inside to understand and use. Complex security schemes are often&lt;br /&gt;compromised to make them easier for trusted users to work with—yet this can also make it&lt;br /&gt;easier for the attackers. In short, keeping a system simple from the inside but complex on the&lt;br /&gt;outside can sometimes be difficult but reaps a major benefit.&lt;br /&gt;&lt;br /&gt;(с) "COMPTIA&amp;nbsp;SECURITY+ 2008&amp;nbsp;IN DEPTH" by&amp;nbsp;Mark Ciampa&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-2926694743806791023?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/2926694743806791023/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=2926694743806791023' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2926694743806791023'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2926694743806791023'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2011/02/comtia-sec-basics.html' title='ComTIA Sec+   Basics'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-4140722299409170496</id><published>2010-08-12T12:05:00.002+04:00</published><updated>2010-08-12T13:45:18.982+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='континент'/><title type='text'>АПКШ "Континент" - Развертывание</title><content type='html'>Последовательность действий в общем&lt;br /&gt;(Согласно "Admin Guide Central")&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;1. Инициализация и подключение КШ с ЦУС. См. [ 2 ].&lt;br /&gt;2. Установка и запуск Программы управления (см. стр. 25).&lt;br /&gt;3. Установка и запуск Агента (см. стр. 35).&lt;br /&gt;4. Настройка Агента. См. [ 3 ].&lt;br /&gt;5. Регистрация КШ, входящих в комплекс (см. стр. 35).&lt;br /&gt;6. Запись конфигураций КШ на отчуждаемые носители (см. стр. 38).&lt;br /&gt;7. Инициализация и подключение зарегистрированных КШ. См. [ 2 ].&lt;br /&gt;8. Ввод в эксплуатацию инициализированных КШ (см. стр. 56).&lt;br /&gt;9. Настройка комплекса (см. стр. 39).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;ol&gt;&lt;li&gt;&lt;b&gt;Установка/обновление ПО&lt;/b&gt;&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;Для установки с usb-флешки, ее надо сначала подготовить с помощью утилиты Flash.exe&lt;/div&gt;&lt;div&gt;При этом все данные с нее удаляются !!! Имиджи установщиков:&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;i&gt;cgw_release.flash&lt;/i&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ПО для установки &lt;b&gt;КШ&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;cgw.aserv_release.flash &lt;/i&gt;&amp;nbsp; &amp;nbsp; ПО для установки &lt;b&gt;КШ с сервером доступа&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;ncc_release.flash&lt;/i&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ПО для установки &lt;b&gt;КШ с ЦУС&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;ncc.aserv_release.flash&lt;/i&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;ПО для установки &lt;b&gt;КШ с ЦУС и сервером доступа&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Также требуется идентификатор админа (таблетка ibutton) для того чтобы ПАК "Соболь" разрешил изменить программную среду. По F1 надо обязательно проверить, что Соболь - Версия 1.0&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;2. Инициализация ЦУС КШ&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Требуется ключевая информация для инициализации. Поставляется на дискете, можно просто переписать на флеш. После инициализации на флеш будет записан ключ для установки ПУ для этого ЦУС.&lt;/div&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-4140722299409170496?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/4140722299409170496/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=4140722299409170496' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/4140722299409170496'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/4140722299409170496'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2010/08/blog-post_12.html' title='АПКШ &quot;Континент&quot; - Развертывание'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-6605388158202870934</id><published>2010-08-10T15:11:00.002+04:00</published><updated>2010-08-10T15:18:20.599+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='континент'/><title type='text'>АПКШ "Континент" - Фильтрация IP-пакетов.</title><content type='html'>Фильтрация дважды - до и после (де-)криптования.&lt;br /&gt;&lt;br /&gt;Фильтрация по:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;dest&amp;amp;source IP, dest&amp;amp;source ports&lt;/li&gt;&lt;li&gt;source int&lt;/li&gt;&lt;li&gt;факт аутентификации для внутренних хостов.&lt;/li&gt;&lt;li&gt;содержимое пакетов для прикладных протоколов.&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;Правила фильтрации IP-пакетов подразделяются на два типа:&lt;br /&gt;• правила, сформированные комплексом автоматически;&lt;br /&gt;• правила, заданные администратором.&lt;br /&gt;&lt;br /&gt;Автоматическое формирование правил фильтрации для данного КШ осуществ-&lt;br /&gt;ляется &lt;b&gt;при инициализации&lt;/b&gt; ЦУС и КШ. Правила этого типа &lt;b&gt;не отображаются&lt;/b&gt; на&lt;br /&gt;экране и &lt;b&gt;не могут быть удалены&lt;/b&gt; &lt;b&gt;или изменены&lt;/b&gt; администратором&lt;br /&gt;&lt;br /&gt;Правила, сформированные комплексом автоматически, разрешают соединения:&lt;br /&gt;• ЦУС с Программой управления и Агентом;&lt;br /&gt;• ЦУС с зарегистрированными КШ;&lt;br /&gt;• основного и резервного КШ.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Режимы работы фильтра:&lt;/b&gt;&lt;br /&gt;1) Основной -&amp;nbsp;пакеты, прохождение которых запрещено, отбрасывают-&lt;br /&gt;&lt;div style="margin-bottom: 0px; margin-left: 0px; margin-right: 0px; margin-top: 0px;"&gt;ся с регистрацией этого события в журнале НСД.&lt;/div&gt;2) "Мягкий"-&amp;nbsp;пакеты только регистрируются в журнале НСД, но пропускаются фильтром.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-6605388158202870934?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/6605388158202870934/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=6605388158202870934' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/6605388158202870934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/6605388158202870934'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2010/08/ip.html' title='АПКШ &quot;Континент&quot; - Фильтрация IP-пакетов.'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-22528949034577187</id><published>2010-08-10T13:59:00.002+04:00</published><updated>2010-08-10T15:36:14.016+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='континент'/><title type='text'>АПКШ "Континент" - Общие сведения</title><content type='html'>Основа - урезанная FreeBSD&lt;br /&gt;Общий функционал:&lt;br /&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;NAT&lt;/li&gt;&lt;li&gt;QoS&lt;/li&gt;&lt;li&gt;PPPoE&lt;/li&gt;&lt;li&gt;VLAN&lt;/li&gt;&lt;li&gt;v.92 dial-up (через COM или USB модем) ! нельзя при установленном на КШ ЦУС или сервера доступа&lt;/li&gt;&lt;li&gt;hot standby (кроме КШ с установленным&amp;nbsp;ЦУС, а также КШ, подключаемых к телефонной линии с помощью модема)&lt;/li&gt;&lt;li&gt;Аутентификация хостов, подключенных к внутренним интерфейсам КШ&lt;/li&gt;&lt;li&gt;SPAN-порт&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;В стандартной поставке идет с ПАК "Соболь"&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Центральное управление КШ - через ЦУС и программу управления.&amp;nbsp;&lt;/div&gt;&lt;div&gt;ЦУС устанавливается на одном из КШ.&amp;nbsp;&lt;/div&gt;&lt;div&gt;Программа управления работает через &lt;i&gt;агент центра управления сетью.&amp;nbsp;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Основные ТТХ:&lt;/div&gt;&lt;div&gt;&lt;div&gt;• Алгоритм шифрования &lt;b&gt;ГОСТ 28147-89&lt;/b&gt;&amp;nbsp;режим гаммирования&amp;nbsp;с обратной связью&lt;/div&gt;&lt;div&gt;• Длина ключа, бит &lt;b&gt;256&lt;/b&gt;&lt;/div&gt;&lt;div&gt;• Защита передаваемых данных от искажения &lt;b&gt;ГОСТ 28147-89&lt;/b&gt;&amp;nbsp;режим имитовставки&lt;/div&gt;&lt;div&gt;• Фильтрация IP-пакетов в соответствии&amp;nbsp;с задаваемыми&amp;nbsp;правилами&amp;nbsp;фильтрации&lt;/div&gt;&lt;div&gt;• Увеличение размера пакета с учетом&amp;nbsp;дополнительного IP-заголовка, байт, не более&amp;nbsp;&lt;b&gt;48&lt;/b&gt;&lt;/div&gt;&lt;div&gt;• Количество КШ в сети с одним ЦУС до &lt;b&gt;500&lt;/b&gt;&lt;/div&gt;&lt;div&gt;• Максимальное количество сетевых интерфейсов&amp;nbsp;у одного КШ&amp;nbsp;&lt;b&gt;16&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;/b&gt;•&amp;nbsp;Аутентификация компьютеров при подключениик КШ&amp;nbsp;На основе расчета&amp;nbsp;хэш-функции по&lt;/div&gt;&lt;div&gt;алгоритму&amp;nbsp;ГОСТ Р 34.11-94&lt;/div&gt;&lt;div&gt;• Максимальное количество КШ в кластере горячего&amp;nbsp;резервирования&amp;nbsp;&lt;b&gt;2&lt;/b&gt;&lt;/div&gt;&lt;div&gt;• Комплекс обеспечивает непрерывную работу&amp;nbsp;в необслуживаемом режиме&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-22528949034577187?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/22528949034577187/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=22528949034577187' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/22528949034577187'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/22528949034577187'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2010/08/blog-post.html' title='АПКШ &quot;Континент&quot; - Общие сведения'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-2333778475687247971</id><published>2010-07-28T15:31:00.003+04:00</published><updated>2010-07-28T16:13:55.760+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='перс данные'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Законы регламентирующие защиту ПДн</title><content type='html'>&lt;b&gt;Общедоступные&lt;/b&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;&lt;span class="Apple-style-span"   style="  line-height: 19px; font-family:sans-serif;font-size:13px;"&gt;&lt;a href="http://ru.wikisource.org/wiki/%D0%A4%D0%B5%D0%B4%D0%B5%D1%80%D0%B0%D0%BB%D1%8C%D0%BD%D1%8B%D0%B9_%D0%B7%D0%B0%D0%BA%D0%BE%D0%BD_%D0%BE%D1%82_27.07.2006_%E2%84%96_152-%D0%A4%D0%97"&gt;ФЗ № 152 «О персональных данных» &lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span"   style="  line-height: 19px; font-family:sans-serif;font-size:13px;"&gt;&lt;a href="http://ru.wikisource.org/wiki/%D0%A4%D0%B5%D0%B4%D0%B5%D1%80%D0%B0%D0%BB%D1%8C%D0%BD%D1%8B%D0%B9_%D0%B7%D0%B0%D0%BA%D0%BE%D0%BD_%D0%BE%D1%82_27.07.2006_%E2%84%96_152-%D0%A4%D0%97"&gt;от 27 июля 2006 г.&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"   style="  line-height: 19px; font-family:sans-serif;font-size:13px;"&gt;&lt;a href="http://www.garant.ru/hotlaw/federal/218169/?subscribe_fed#review"&gt;ФЗ 363 "О внесении изменений в статьи 19 и 25 Федерального закона "О персональных данных" от 27 декабря 2009 г.&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span class="Apple-style-span"   style="  line-height: 19px; font-family:sans-serif;font-size:13px;"&gt;&lt;a href="http://www.fstec.ru/_docs/doc_781.htm"&gt;Приказ ФСТЭК  N 58 "Об утверждении положения о методах и способах защиты информации в информационных системах защиты персональных данных"&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span"   style="  line-height: 19px; font-family:sans-serif;font-size:13px;"&gt;&lt;a href="http://www.fstec.ru/_docs/doc_781.htm"&gt;от 5 февраля 2010 г.&lt;/a&gt;&lt;/span&gt;&lt;span class="Apple-style-span"   style="  line-height: 19px; font-family:sans-serif;font-size:13px;"&gt; &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"   style="  line-height: 19px; font-family:sans-serif;font-size:13px;"&gt;&lt;a href="http://www.garant.ru/hotlaw/federal/218169/?subscribe_fed" class="external text" rel="nofollow" style="text-decoration: none; color: rgb(51, 102, 187); background-image: url(http://bits.wikimedia.org/skins-1.5/vector/images/external-link-ltr-icon.png?2); background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; padding-top: 0px; padding-right: 13px; padding-bottom: 0px; padding-left: 0px; background-position: 100% 50%; background-repeat: no-repeat no-repeat; "&gt;&lt;/a&gt;&lt;/span&gt;&lt;b&gt;Закрытые&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span"   style=" font-weight: normal;  line-height: 19px; font-family:sans-serif;font-size:13px;"&gt;&lt;h3   style="color: black; background-image: none; background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; font-weight: bold; margin-top: 0px; margin-right: 0px; margin-bottom: 0.3em; margin-left: 0px; padding-top: 0.5em; padding-bottom: 0.17em; border-bottom-width: initial; border-bottom-style: none; border-bottom- width: auto;  background-position: initial initial; background-repeat: initial initial; font-size:17px;color:initial;"&gt;&lt;span class="mw-headline" id=".D0.9C.D0.B5.D1.82.D0.BE.D0.B4.D0.B8.D1.87.D0.B5.D1.81.D0.BA.D0.B8.D0.B5_.D0.BC.D0.B0.D1.82.D0.B5.D1.80.D0.B8.D0.B0.D0.BB.D1.8B_.D0.A4.D0.A1.D0.A2.D0.AD.D0.9A"&gt;Методические материалы ФСТЭК&lt;/span&gt;&lt;/h3&gt;&lt;ul style="line-height: 1.5em; list-style-type: square; margin-top: 0.3em; margin-right: 0px; margin-bottom: 0px; margin-left: 1.5em; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-image: url(http://bits.wikimedia.org/skins-1.5/vector/images/bullet-icon.png?1); "&gt;&lt;li style="margin-bottom: 0.1em; "&gt;Базовая модель угроз безопасности персональных данных при их обработке в информационных системах персональных данных" от 15 февраля 2008 года (&lt;a href="http://www.fstec.ru/_razd/_ispo.htm" class="external text" rel="nofollow" style="text-decoration: none; color: rgb(51, 102, 187); background-image: url(http://bits.wikimedia.org/skins-1.5/vector/images/external-link-ltr-icon.png?2); background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; padding-top: 0px; padding-right: 13px; padding-bottom: 0px; padding-left: 0px; background-position: 100% 50%; background-repeat: no-repeat no-repeat; "&gt;Базовая модель&lt;/a&gt;).&lt;/li&gt;&lt;/ul&gt;&lt;ul style="line-height: 1.5em; list-style-type: square; margin-top: 0.3em; margin-right: 0px; margin-bottom: 0px; margin-left: 1.5em; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-image: url(http://bits.wikimedia.org/skins-1.5/vector/images/bullet-icon.png?1); "&gt;&lt;li style="margin-bottom: 0.1em; "&gt;Методика определения актуальных угроз безопасности персональных данных при их обработке в информационных системах персональных данных" от 15 февраля 2008 года (&lt;a href="http://www.fstec.ru/_razd/_ispo.htm" class="external text" rel="nofollow" style="text-decoration: none; color: rgb(51, 102, 187); background-image: url(http://bits.wikimedia.org/skins-1.5/vector/images/external-link-ltr-icon.png?2); background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; padding-top: 0px; padding-right: 13px; padding-bottom: 0px; padding-left: 0px; background-position: 100% 50%; background-repeat: no-repeat no-repeat; "&gt;Методика&lt;/a&gt;).&lt;/li&gt;&lt;/ul&gt;&lt;p style="margin-top: 0.4em; margin-right: 0px; margin-bottom: 0.5em; margin-left: 0px; line-height: 1.5em; "&gt;Документы, которые не применяются с 15 марта 2010 г. &lt;a href="http://www.fstec.ru/_docs/doc_781_1.htm" class="external text" rel="nofollow" style="text-decoration: none; color: rgb(51, 102, 187); background-image: url(http://bits.wikimedia.org/skins-1.5/vector/images/external-link-ltr-icon.png?2); background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; padding-top: 0px; padding-right: 13px; padding-bottom: 0px; padding-left: 0px; background-position: 100% 50%; background-repeat: no-repeat no-repeat; "&gt;Решение ФСТЭК&lt;/a&gt;:&lt;/p&gt;&lt;ul style="line-height: 1.5em; list-style-type: square; margin-top: 0.3em; margin-right: 0px; margin-bottom: 0px; margin-left: 1.5em; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-image: url(http://bits.wikimedia.org/skins-1.5/vector/images/bullet-icon.png?1); "&gt;&lt;li style="margin-bottom: 0.1em; "&gt;&lt;i&gt;Основные мероприятия по организации и техническому обеспечению безопасности персональных данных, обрабатываемых в информационных системах персональных данных" от 15 февраля 2008 года (пометка «для служебного пользования» снята Решением ФСТЭК России от 11 ноября 2009 г.)&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul style="line-height: 1.5em; list-style-type: square; margin-top: 0.3em; margin-right: 0px; margin-bottom: 0px; margin-left: 1.5em; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-image: url(http://bits.wikimedia.org/skins-1.5/vector/images/bullet-icon.png?1); "&gt;&lt;li style="margin-bottom: 0.1em; "&gt;&lt;i&gt;Рекомендации по обеспечению безопасности персональных данных при их обработке в информационных системах персональных данных" от 15 февраля 2008 года (пометка «для служебного пользования» снята Решением ФСТЭК России от 11 ноября 2009 г.)&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-2333778475687247971?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/2333778475687247971/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=2333778475687247971' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2333778475687247971'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2333778475687247971'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2010/07/blog-post_28.html' title='Законы регламентирующие защиту ПДн'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-7408401564606948110</id><published>2010-07-28T15:13:00.002+04:00</published><updated>2010-07-28T15:24:04.832+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='гост'/><category scheme='http://www.blogger.com/atom/ns#' term='госструктуры'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>ГОСТ Р 51583-2000 Порядок создания автоматизированных систем в защищенном исполнении</title><content type='html'>&lt;span class="Apple-style-span" style="font-family: Tahoma, Arial, Georgia; font-size: 12px; color: rgb(51, 51, 51); "&gt;ПРИНЯТ И ВВЕДЕН В ДЕЙСТВИЕ Постановлением Госстандарта России от 6 апреля 2000 г. № 95-ст&lt;/span&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Tahoma, Arial, Georgia; font-size: 12px; color: rgb(51, 51, 51); "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Tahoma, Arial, Georgia; font-size: 12px; color: rgb(51, 51, 51); "&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;&lt;strong style="font-size: 11px; font-family: Tahoma, Verdana, sans-serif; "&gt;1 Область применения&lt;/strong&gt;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;Настоящий стандарт распространяется на автоматизированные системы в защищенном ис полнении, используемые в различных видах деятельности (исследование, управление, проектиро вание и т. п.), включая их сочетания, в процессе создания и применения, которых осуществляется обработка защищаемой информации, &lt;b&gt;содержащей сведения, отнесенные к государственной или служебной тайне&lt;/b&gt;.&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;Настоящий стандарт устанавливает дополнительные требования и положения стандартов класса 34 “Информационная технология. Комплекс стандартов на автоматизированные системы” в части порядка создания и применения автоматизированных систем в защищенном исполнении.&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;Настоящий стандарт применяется на территории Российской Федерации &lt;b&gt;органами государственной власти, местного самоуправления, организациями, предприятиями и учреждениями не зависимо от их организационно-правовой формы и формы собственности&lt;/b&gt;, которые заказывают, разрабатывают, изготавливают и используют (эксплуатируют) автоматизированные системы в за щищенном исполнении.&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt; настоящем стандарте приняты следующие сокращения:&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;AC — автоматизированная система;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;АСЗИ — автоматизированная система в защищенном исполнении;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;ЗИ — защита информации;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;НД — нормативный документ;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;ТЗ — техническое задание;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;ЧТЗ — частное техническое задание;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;ШС — шифровальное средство;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;ТС — технические средства;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;ПС — программные средства;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;СрЗИ — средство защиты информации;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;СиЗИ — система защиты информации;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;СВТ — средство вычислительной техники;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;ПЭМИН — побочные электромагнитные излучения и наводки;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;НСД — несанкционированный доступ;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;НИР — научно-исследовательская работа;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;ФАПСИ — Федеральное агентство правительственной связи и информации.&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;&lt;a href="http://iso27000.ru/standarty/gost-r-nacionalnye-standarty-rossiiskoi-federacii-v-oblasti-zaschity-informacii/gost-r-51583-2000-poryadok-sozdaniya-avtomatizirovannyh-sistem-v-zaschischennom-ispolnenii"&gt;http://iso27000.ru/standarty/gost-r-nacionalnye-standarty-rossiiskoi-federacii-v-oblasti-zaschity-informacii/gost-r-51583-2000-poryadok-sozdaniya-avtomatizirovannyh-sistem-v-zaschischennom-ispolnenii&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-7408401564606948110?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/7408401564606948110/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=7408401564606948110' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/7408401564606948110'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/7408401564606948110'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2010/07/51583-2000.html' title='ГОСТ Р 51583-2000 Порядок создания автоматизированных систем в защищенном исполнении'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-9038018557736454140</id><published>2010-07-16T12:16:00.002+04:00</published><updated>2010-07-16T12:20:31.201+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='перс данные'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Классификация ИСПДн</title><content type='html'>&lt;span class="Apple-style-span" style="font-family: Arial; font-size: 13px; color: rgb(68, 68, 68); "&gt;&lt;h1 style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 10px; padding-right: 0px; padding-bottom: 10px; padding-left: 0px; color: rgb(62, 155, 87); text-decoration: none; font-weight: normal; font-size: 20px; "&gt;Классификация ИСПДн&lt;/h1&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 5px; padding-right: 0px; padding-bottom: 5px; padding-left: 0px; "&gt;Классификация информационных систем персональных данных (ИСПДн) определяется Приказом ФСТЭК России, ФСБ России, Мининформсвязи России от 13 февраля 2008 г. № 55/86/20 «Об утверждении Порядка проведения классификации информационных систем персональных данных».&lt;/p&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 5px; padding-right: 0px; padding-bottom: 5px; padding-left: 0px; "&gt;Следующая информация приведена в соответствии с данным приказом.&lt;/p&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 5px; padding-right: 0px; padding-bottom: 5px; padding-left: 0px; "&gt;Классификация ИСПДн включает в себя следующие этапы:&lt;/p&gt;&lt;ul style="margin-top: 0px; margin-right: 0px; margin-bottom: 10px; margin-left: 20px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-type: none; list-style-position: initial; list-style-image: initial; "&gt;&lt;li style="margin-top: 10px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-image: url(http://www.itprotect.ru/res/img/design_page/leftmenu.gif); "&gt;сбор и анализ исходных данных по информационной системе;&lt;/li&gt;&lt;li style="margin-top: 10px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-image: url(http://www.itprotect.ru/res/img/design_page/leftmenu.gif); "&gt;присвоение информационной системе соответствующего класса и его документальное оформление.&lt;/li&gt;&lt;/ul&gt;&lt;h2 style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 10px; padding-right: 0px; padding-bottom: 10px; padding-left: 0px; color: rgb(62, 155, 87); text-decoration: none; font-weight: bold; font-size: 15px; "&gt;Категории информации&lt;/h2&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 5px; padding-right: 0px; padding-bottom: 5px; padding-left: 0px; "&gt;Информация, обрабатываемая в ИСПДн может быть отнесена к одной из следующих  4 категорий:&lt;/p&gt;&lt;ul style="margin-top: 0px; margin-right: 0px; margin-bottom: 10px; margin-left: 20px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-type: none; list-style-position: initial; list-style-image: initial; "&gt;&lt;li style="margin-top: 10px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-image: url(http://www.itprotect.ru/res/img/design_page/leftmenu.gif); "&gt;&lt;strong&gt;категория 1&lt;/strong&gt; - персональные данные, касающиеся расовой, национальной принадлежности, политических взглядов, религиозных и философских убеждений, состояния здоровья, интимной жизни;&lt;/li&gt;&lt;li style="margin-top: 10px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-image: url(http://www.itprotect.ru/res/img/design_page/leftmenu.gif); "&gt;&lt;strong&gt;категория 2 &lt;/strong&gt;- персональные данные, позволяющие идентифицировать субъекта персональных данных и получить о нем дополнительную информацию, за исключением персональных данных, относящихся к категории 1;&lt;/li&gt;&lt;li style="margin-top: 10px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-image: url(http://www.itprotect.ru/res/img/design_page/leftmenu.gif); "&gt;&lt;strong&gt;категория 3&lt;/strong&gt; - персональные данные, позволяющие идентифицировать субъекта персональных данных;&lt;/li&gt;&lt;li style="margin-top: 10px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-image: url(http://www.itprotect.ru/res/img/design_page/leftmenu.gif); "&gt;&lt;strong&gt;категория 4&lt;/strong&gt; - обезличенные и (или) общедоступные персональные данные&lt;/li&gt;&lt;/ul&gt;&lt;h2 style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 10px; padding-right: 0px; padding-bottom: 10px; padding-left: 0px; color: rgb(62, 155, 87); text-decoration: none; font-weight: bold; font-size: 15px; "&gt;&lt;br /&gt;Классификация по масштабу ИСПДн&lt;/h2&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 5px; padding-right: 0px; padding-bottom: 5px; padding-left: 0px; "&gt;По объему обрабатываемых персональных данных (количество субъектов персональных данных, персональные данные которых обрабатываются в информационной системе), ИСПДн делятся на 3 подкласса (Хнпд):&lt;/p&gt;&lt;ol style="margin-top: 0px; margin-right: 0px; margin-bottom: 10px; margin-left: 20px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;&lt;li style="margin-top: 10px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;в информационной системе одновременно обрабатываются персональные данные более чем 100 000 субъектов персональных данных или персональные данные субъектов персональных данных в пределах субъекта Российской Федерации или Российской Федерации в целом;&lt;/li&gt;&lt;li style="margin-top: 10px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;в информационной системе одновременно обрабатываются персональные данные от 1000 до 100 000 субъектов персональных.данных или персональные данные субъектов персональных данных, работающих в отрасли экономики Российской Федерации, в органе государственной власти, проживающих в пределах муниципального образования;&lt;/li&gt;&lt;li style="margin-top: 10px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; "&gt;в информационной системе одновременно обрабатываются данные менее чем 1000 субъектов персональных данных или персональные данные субъектов персональных данных в пределах конкретной организации.&lt;/li&gt;&lt;/ol&gt;&lt;div&gt;&lt;h2 style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 10px; padding-right: 0px; padding-bottom: 10px; padding-left: 0px; color: rgb(62, 155, 87); text-decoration: none; font-weight: bold; font-size: 15px; "&gt;Типовые и специальные ИСПДн.&lt;/h2&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 5px; padding-right: 0px; padding-bottom: 5px; padding-left: 0px; "&gt;По заданным оператором ПДн характеристикам безопасности обрабатываемой информации ИСПДн подразделяются на типовые и специальные.&lt;/p&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 5px; padding-right: 0px; padding-bottom: 5px; padding-left: 0px; "&gt;«Типовые информационные системы - информационные системы, в которых требуется обеспечение только конфиденциальности персональных данных.&lt;br /&gt;Специальные информационные системы - информационные системы, в которых вне зависимости от необходимости обеспечения конфиденциальности персональных данных требуется обеспечить хотя бы одну из характеристик безопасности персональных данных, отличную от конфиденциальности (защищенность от уничтожения, изменения, блокирования, а также иных несанкционированных действий).&lt;/p&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 5px; padding-right: 0px; padding-bottom: 5px; padding-left: 0px; "&gt;К специальным информационным системам должны быть отнесены:&lt;/p&gt;&lt;ul style="margin-top: 0px; margin-right: 0px; margin-bottom: 10px; margin-left: 20px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-type: none; list-style-position: initial; list-style-image: initial; "&gt;&lt;li style="margin-top: 10px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-image: url(http://www.itprotect.ru/res/img/design_page/leftmenu.gif); "&gt;информационные системы, в которых обрабатываются персональные данные, касающиеся состояния здоровья субъектов персональных данных;&lt;/li&gt;&lt;li style="margin-top: 10px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-image: url(http://www.itprotect.ru/res/img/design_page/leftmenu.gif); "&gt;информационные системы, в которых предусмотрено принятие на основании исключительно автоматизированной обработки персональных данных решений, порождающих юридические последствия в отношении субъекта персональных данных или иным образом затрагивающих его права и законные интересы».&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;h2 style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 10px; padding-right: 0px; padding-bottom: 10px; padding-left: 0px; color: rgb(62, 155, 87); text-decoration: none; font-weight: bold; font-size: 15px; "&gt;Типовым ИСПДн могут быть присвоены следующие классы:&lt;/h2&gt;&lt;ul style="margin-top: 0px; margin-right: 0px; margin-bottom: 10px; margin-left: 20px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-type: none; list-style-position: initial; list-style-image: initial; "&gt;&lt;li style="margin-top: 10px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-image: url(http://www.itprotect.ru/res/img/design_page/leftmenu.gif); "&gt;&lt;strong&gt;класс 1 (К1) &lt;/strong&gt;- информационные системы, для которых нарушение заданной характеристики безопасности персональных данных, обрабатываемых в них, может привести к значительным негативным последствиям для субъектов персональных данных;&lt;/li&gt;&lt;li style="margin-top: 10px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-image: url(http://www.itprotect.ru/res/img/design_page/leftmenu.gif); "&gt;&lt;strong&gt;класс 2 (К2) &lt;/strong&gt;- информационные системы, для которых нарушение заданной характеристики безопасности персональных данных, обрабатываемых в них, может привести к негативным последствиям для субъектов персональных данных;&lt;/li&gt;&lt;li style="margin-top: 10px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-image: url(http://www.itprotect.ru/res/img/design_page/leftmenu.gif); "&gt;&lt;strong&gt;класс 3 (К3) &lt;/strong&gt;- информационные системы, для которых нарушение заданной характеристики безопасности персональных данных, обрабатываемых в них, может привести к незначительным негативным последствиям для субъектов персональных данных;&lt;/li&gt;&lt;li style="margin-top: 10px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 0px; padding-right: 0px; padding-bottom: 0px; padding-left: 0px; list-style-image: url(http://www.itprotect.ru/res/img/design_page/leftmenu.gif); "&gt;&lt;strong&gt;класс 4 (К4) &lt;/strong&gt;- информационные системы, для которых нарушение заданной характеристики безопасности персональных данных, обрабатываемых в них, не приводит к негативным последствиям для субъектов персональных данных.&lt;/li&gt;&lt;/ul&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 5px; padding-right: 0px; padding-bottom: 5px; padding-left: 0px; "&gt;Данные классы определяются, исходя из таблицы, в которой в качестве исходных данных присутствует масштаб системы ИСПДн (Хнпд) и категория обрабатываемой информации (Хпд):&lt;/p&gt;&lt;table id="table" width="300" style="border-collapse: collapse; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; margin-top: 10px; margin-right: 0px; margin-bottom: 10px; margin-left: 0px; "&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td colspan="2" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: normal; "&gt;&lt;/td&gt;&lt;td class="head" colspan="3" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: bold; background-image: url(http://www.itprotect.ru/res/img/design_page/table_td_bg.gif); background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; "&gt;X&lt;sub&gt;нпд&lt;/sub&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td colspan="2" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: normal; "&gt;&lt;/td&gt;&lt;td class="head" align="middle" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: bold; background-image: url(http://www.itprotect.ru/res/img/design_page/table_td_bg.gif); background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; "&gt;3&lt;/td&gt;&lt;td class="head" align="middle" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: bold; background-image: url(http://www.itprotect.ru/res/img/design_page/table_td_bg.gif); background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; "&gt;2&lt;/td&gt;&lt;td class="head" align="middle" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: bold; background-image: url(http://www.itprotect.ru/res/img/design_page/table_td_bg.gif); background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; "&gt;1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td rowspan="4" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: normal; "&gt;X&lt;sub&gt;пд&lt;/sub&gt;&lt;/td&gt;&lt;td class="head" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: bold; background-image: url(http://www.itprotect.ru/res/img/design_page/table_td_bg.gif); background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; "&gt;Категория 4&lt;/td&gt;&lt;td style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: normal; "&gt;К4&lt;/td&gt;&lt;td style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: normal; "&gt;К4&lt;/td&gt;&lt;td style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: normal; "&gt;К4&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="head" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: bold; background-image: url(http://www.itprotect.ru/res/img/design_page/table_td_bg.gif); background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; "&gt;Категория 3&lt;/td&gt;&lt;td style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: normal; "&gt;К3&lt;/td&gt;&lt;td style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: normal; "&gt;К3&lt;/td&gt;&lt;td style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: normal; "&gt;К2&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="head" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: bold; background-image: url(http://www.itprotect.ru/res/img/design_page/table_td_bg.gif); background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; "&gt;Категория 2&lt;/td&gt;&lt;td style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: normal; "&gt;К3&lt;/td&gt;&lt;td style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: normal; "&gt;К2&lt;/td&gt;&lt;td style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: normal; "&gt;К1&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="head" style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: bold; background-image: url(http://www.itprotect.ru/res/img/design_page/table_td_bg.gif); background-attachment: initial; background-origin: initial; background-clip: initial; background-color: initial; background-position: 50% 100%; background-repeat: repeat no-repeat; "&gt;Категория 1&lt;/td&gt;&lt;td style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: normal; "&gt;К1&lt;/td&gt;&lt;td style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: normal; "&gt;К1&lt;/td&gt;&lt;td style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 3px; padding-right: 15px; padding-bottom: 3px; padding-left: 15px; text-align: left; border-top-width: 1px; border-right-width: 1px; border-bottom-width: 1px; border-left-width: 1px; border-top-style: solid; border-right-style: solid; border-bottom-style: solid; border-left-style: solid; border-top-color: rgb(235, 235, 235); border-right-color: rgb(235, 235, 235); border-bottom-color: rgb(235, 235, 235); border-left-color: rgb(235, 235, 235); font-weight: normal; "&gt;К1&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 5px; padding-right: 0px; padding-bottom: 5px; padding-left: 0px; "&gt;&lt;br /&gt;Кроме того ИСПДн имеют еще несколько критериев классификации.&lt;/p&gt;&lt;p style="margin-top: 0px; margin-right: 0px; margin-bottom: 0px; margin-left: 0px; padding-top: 5px; padding-right: 0px; padding-bottom: 5px; padding-left: 0px; "&gt;&lt;br /&gt;В соответствии с п.2 Приказа «&lt;em&gt;классификация информационных систем проводится государственными органами, муниципальными органами, юридическими и физическими лицами, организующими и (или) осуществляющими обработку персональных данных, а также определяющими цели и содержание обработки персональных данных&lt;/em&gt;» - то есть операторами персональных данных.&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-9038018557736454140?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/9038018557736454140/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=9038018557736454140' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/9038018557736454140'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/9038018557736454140'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2010/07/blog-post_16.html' title='Классификация ИСПДн'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-4735921757004082407</id><published>2010-07-16T11:53:00.004+04:00</published><updated>2010-07-28T15:28:53.475+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>терминология ИБ</title><content type='html'>НСД -&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;несанкционированный доступ, защита от несанкционированного доступа&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;СКЗИ&lt;span class="Apple-tab-span" style="white-space:pre"&gt; -&lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;&lt;/span&gt;средства криптографической защиты информации&lt;/div&gt;&lt;div&gt;МСЭ&lt;span class="Apple-tab-span" style="white-space:pre"&gt; -&lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;&lt;/span&gt;межсетевой экран&lt;/div&gt;&lt;div&gt;СЗИ&lt;span class="Apple-tab-span" style="white-space:pre"&gt; -&lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;&lt;/span&gt;средства защиты информации (общее)&lt;/div&gt;&lt;div&gt;СЗПДн -&lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;система защиты персональных данных&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-family: Tahoma, Arial, Georgia; font-size: 12px; color: rgb(51, 51, 51); line-height: 20px; "&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;AC — &lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;автоматизированная система;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;АСЗИ — &lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;автоматизированная система в защищенном исполнении;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;ЗИ — &lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;защита информации;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;НД — &lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;нормативный документ;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;ЧТЗ —&lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;частное техническое задание;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;ШС — &lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;шифровальное средство;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;ТС —&lt;span class="Apple-tab-span" style="white-space:pre"&gt;   &lt;/span&gt;технические средства;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;ПС —&lt;span class="Apple-tab-span" style="white-space:pre"&gt;   &lt;/span&gt;программные средства;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;СрЗИ —&lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;средство защиты информации;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;СиЗИ —&lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;система защиты информации;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;СВТ —&lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;средство вычислительной техники;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;ПЭМИН —&lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;побочные электромагнитные излучения и наводки;&lt;/p&gt;&lt;p style="font-size: 12px; font-family: Tahoma, Arial, Georgia; font-style: normal; letter-spacing: 0px; color: rgb(51, 51, 51); "&gt;НИР —&lt;span class="Apple-tab-span" style="white-space:pre"&gt;  &lt;/span&gt;научно-исследовательская работа;&lt;/p&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-4735921757004082407?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/4735921757004082407/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=4735921757004082407' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/4735921757004082407'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/4735921757004082407'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2010/07/blog-post.html' title='терминология ИБ'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-8085987497684030506</id><published>2010-06-17T10:49:00.004+04:00</published><updated>2010-06-17T11:19:30.059+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='juniper'/><category scheme='http://www.blogger.com/atom/ns#' term='junos'/><title type='text'>JunOS interfaces</title><content type='html'>Наименование порта&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;fe, ge, xe&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;fe &lt;span class="Apple-style-span"  style="color:#3366FF;"&gt;0&lt;/span&gt;/&lt;span class="Apple-style-span"  style="color:#FF6600;"&gt;1&lt;/span&gt;/&lt;span class="Apple-style-span"  style="color:#33CC00;"&gt;1&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color:#33CC00;"&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 102, 255); "&gt;0  - номер шасси или слота, мембер ид в Virtual Chassis. Для standalone номер всегда = 0&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color:#FF6600;"&gt;1  - Pic number. Фиксированные интерфейсы - 0, аплинк модули - 1&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color:#33CC00;"&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 102, 255); "&gt;&lt;span class="Apple-style-span" style="color: rgb(255, 102, 0); "&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 204, 0); "&gt;1  - номер порта. Начинается с 0&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color:#33CC00;"&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 102, 255); "&gt;&lt;span class="Apple-style-span" style="color: rgb(255, 102, 0); "&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 204, 0); "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"  style="color:#33CC00;"&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 102, 255); "&gt;&lt;span class="Apple-style-span" style="color: rgb(255, 102, 0); "&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 204, 0); "&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span"&gt;&lt;span class="Apple-style-span"&gt;&lt;b&gt;lo0&lt;/b&gt;&lt;span class="Apple-style-span"&gt; - loopback интерфейс&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;me0&lt;/b&gt; - mgmt out-of-band int&lt;/div&gt;&lt;div&gt;&lt;b&gt;vme&lt;/b&gt; - логический mgmt интерфейс в Virtual Chassis, доступен через me0 на любом коммутаторе, входящим в VS&lt;/div&gt;&lt;div&gt;&lt;b&gt;vlan&lt;/b&gt; - логический L3 int привязанный к соотвествующему vlan&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Все &lt;/b&gt;физические интерфейсы имеют сабинтерфейсы, называемые &lt;b&gt;units&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;L3 конфигурация - на уровне unit&lt;/div&gt;&lt;div&gt;L2 конфигурация применяется на уровне физического интерфейса.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;family inet  - ipv4 конфигурация&lt;/div&gt;&lt;div&gt;family ethernet-switching -  L2 конфигурация  ethernet&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Деактивация порта:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;deactivate - деактивирует конфигурацию порта логически&lt;/div&gt;&lt;div&gt;disable - деактивирует сам порт&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-8085987497684030506?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/8085987497684030506/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=8085987497684030506' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/8085987497684030506'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/8085987497684030506'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2010/06/junos-interfaces.html' title='JunOS interfaces'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-4126034854408211053</id><published>2010-06-09T11:05:00.006+04:00</published><updated>2010-06-10T13:31:47.291+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cisco'/><category scheme='http://www.blogger.com/atom/ns#' term='uc'/><title type='text'>Унифицированные коммуникации по версии Cisco</title><content type='html'>&lt;b&gt;Что из себя представляет:&lt;/b&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;1) Все каналы коммуникации: телефония, видеосвязь, е-мейл, мессенджеры, sms и т.д. - объединяются в единую систему UC&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Бенефиты от внедрения:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;1) Экономия на расходах на связь - традиционно&lt;/div&gt;&lt;div&gt;2) Быстрый поиск всех способов связи с контактом (один контакт - несколько каналов связи) + presence абонента&lt;/div&gt;&lt;div&gt;3) "Единый номер" для всех ваших телефонов.&lt;/div&gt;&lt;div&gt;4) Ваши настройки (номер телефона, персональные контакты итд.) переезжают за вами, где бы вы не были. (Extension Mobility)&lt;/div&gt;&lt;div&gt;5) можем поддерживать 2х-стандартные wifi/gsm телефоны (через моб.терминалы)&lt;/div&gt;&lt;div&gt;6) Централизованное управления всеми контактами, каналами связи, и т.д. и т.п&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Варианты совместной работы&lt;/div&gt;&lt;div&gt;1)Personal Communicator + UC Meeting Place.&lt;/div&gt;&lt;div&gt;Видео, desktop sharing, конференции через веб-камеру&lt;/div&gt;&lt;div&gt;2)Cisco Unified Video Conferincing Desktop&lt;/div&gt;&lt;div&gt;Облегченный вариант.&lt;/div&gt;&lt;div&gt;3) TelePresence&lt;/div&gt;&lt;div&gt;Вебконференции для "взрослых" - большие экраны, спецкамеры,  выделенное оборудование и т.д и т.п.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Что посмотреть, почитать&lt;/b&gt;&lt;/div&gt;&lt;div&gt;1) Вебинар циско "UC в офисе" + наглядная демонстрация&lt;/div&gt;&lt;div&gt;&lt;a href="http://cisco-apps.cisco.com/pcgi-bin/sreg2/register/regdetail.pl?SESSION_ID=127606627110586&amp;amp;LANGUAGE_ID=R&amp;amp;SEMINAR_ID=17197&amp;amp;SEMINAR_TYPE=O&amp;amp;USER_TYPE=R&amp;amp;BANNER_FLAG=1&amp;amp;METHOD=D&amp;amp;TOPIC_CODE=S12049"&gt;http://cisco-apps.cisco.com/pcgi-bin/sreg2/register/regdetail.pl?SESSION_ID=127606627110586&amp;amp;LANGUAGE_ID=R&amp;amp;SEMINAR_ID=17197&amp;amp;SEMINAR_TYPE=O&amp;amp;USER_TYPE=R&amp;amp;BANNER_FLAG=1&amp;amp;METHOD=D&amp;amp;TOPIC_CODE=S12049&lt;/a&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-4126034854408211053?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/4126034854408211053/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=4126034854408211053' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/4126034854408211053'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/4126034854408211053'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2010/06/cisco.html' title='Унифицированные коммуникации по версии Cisco'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-687011783594491981</id><published>2009-09-29T16:19:00.003+04:00</published><updated>2009-09-29T16:33:18.784+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='quick notes'/><category scheme='http://www.blogger.com/atom/ns#' term='qos'/><category scheme='http://www.blogger.com/atom/ns#' term='ont'/><title type='text'>Query</title><content type='html'>serial &lt;= 2.048 kb/s   - WFQ&lt;div&gt;other default -  FIFO&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-687011783594491981?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/687011783594491981/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=687011783594491981' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/687011783594491981'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/687011783594491981'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2009/09/serial-2.html' title='Query'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-8559222066193846553</id><published>2009-09-15T15:45:00.002+04:00</published><updated>2009-09-15T16:13:12.529+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='ont'/><title type='text'>EAP</title><content type='html'>&lt;div&gt;&lt;b&gt;WEP&lt;/b&gt;&lt;/div&gt;&lt;div&gt;■ A lack of mutual authentication makes WEP vulnerable to rogue access points.&lt;/div&gt;&lt;div&gt;■ Usage of static keys makes WEP vulnerable to dictionary attacks.&lt;/div&gt;&lt;div&gt;■ Even with use of initialization vector (IV), attackers can deduct WEP keys by capturing &lt;/div&gt;&lt;div&gt;enough data.&lt;/div&gt;&lt;div&gt;■ Conﬁguring clients with the static WEP keys is nonscalable.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;LEAP&lt;/b&gt;&lt;/div&gt;&lt;div&gt;■ Following are the beneﬁts of LEAP over the basic 802.11 (WEP):&lt;/div&gt;&lt;div&gt;■ Server-based authentication (leveraging 802.1x) using passwords, one-time tokens, &lt;/div&gt;&lt;div&gt;public key infrastructure (PKI) certiﬁcates, or machine IDs&lt;/div&gt;&lt;div&gt;&lt;div&gt;■ Usage of dynamic WEP keys (also called session keys) through reauthenticating the user &lt;/div&gt;&lt;div&gt;periodically and negotiating a new WEP key each time (Cisco Key Integrity Protocol or &lt;/div&gt;&lt;div&gt;CKIP)&lt;/div&gt;&lt;div&gt;■ Mutual authentication between the wireless client and the RADIUS server&lt;/div&gt;&lt;div&gt;■ Usage of Cisco Message Integrity Check (CMIC) to protect against inductive WEP &lt;/div&gt;&lt;div&gt;attacks and replays&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;b&gt;WPA&lt;/b&gt;&lt;/div&gt;&lt;div&gt;■ Authenticated key management—WPA performs authentication using either IEEE 802.1x &lt;/div&gt;&lt;div&gt;or preshared key (PSK) prior to the key management phase.&lt;/div&gt;&lt;div&gt;■ Unicast and broadcast key management—After successful user authentication, message &lt;/div&gt;&lt;div&gt;integrity and encryption keys are derived, distributed, validated, and stored on the client and &lt;/div&gt;&lt;div&gt;the AP&lt;/div&gt;&lt;div&gt;&lt;div&gt;■ Utilization of TKIP and MIC—Temporal Key Integrity Protocol (TKIP) and Message &lt;/div&gt;&lt;div&gt;Integrity Check (MIC) are both elements of the WPA standard and they secure a system &lt;/div&gt;&lt;div&gt;against WEP vulnerabilities such as intrusive attacks.&lt;/div&gt;&lt;div&gt;■ Initialization vector space expansion—WPA provides per-packet keying (PPK) via &lt;/div&gt;&lt;div&gt;initialization vector (IV) hashing and broadcast key rotation. The IV is expanded from 24 bits &lt;/div&gt;&lt;div&gt;(as in 802.11 WEP) to 48 bits.&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;WPA2&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal; "&gt;■ AES&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;■ more CPU-intensive than WPA mostly because of the usage of AES&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;div&gt;&lt;b&gt;EAP-FAST&lt;/b&gt;&lt;/div&gt;&lt;div&gt;■ Supports Windows single sign-on for Cisco Aironet clients and Cisco-compatible clients&lt;/div&gt;&lt;div&gt;■ Does not use certiﬁcates or require Public Key Infrastructure (PKI) support on client &lt;/div&gt;&lt;div&gt;devices&lt;/div&gt;&lt;div&gt;■ Provides for a seamless migration from Cisco LEAP&lt;/div&gt;&lt;div&gt;&lt;div&gt;■ Provides full support for 802.11i, 802.1x, TKIP, and AES&lt;/div&gt;&lt;div&gt;■ Supports password expiration or change (Microsoft password change)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;b&gt; &lt;/b&gt; &lt;/div&gt;&lt;div&gt;■ EAP-TLS uses the Transport Layer Security (TLS) protocol.&lt;/div&gt;&lt;div&gt;■ EAP-TLS uses Public Key Infrastructure (PKI).&lt;/div&gt;&lt;div&gt;■ EAP-TLS is one of the original EAP authentication methods, and it is used in many &lt;/div&gt;&lt;div&gt;environments. &lt;/div&gt;&lt;div&gt;■ The supported clients for EAP-TLS include Microsoft Windows 2000, XP, and CE, plus &lt;/div&gt;&lt;div&gt;non-Windows platforms with third-party supplicants, such as Meetinghouse. &lt;/div&gt;&lt;div&gt;■ One of the advantages of Cisco and Microsoft implementation of EAP-TLS is that it is &lt;/div&gt;&lt;div&gt;possible to tie the Microsoft credentials of the user to the certiﬁcate of that user in a &lt;/div&gt;&lt;div&gt;Microsoft database, which permits a single logon to a Microsoft domain.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;b&gt;PEAP&lt;/b&gt; &lt;/div&gt;&lt;div&gt;■ PEAP was developed by Cisco Systems, Microsoft, and RSA Security to the IETF.&lt;/div&gt;&lt;div&gt;■ With PEAP, only the server authentication is performed using PKI certiﬁcate. &lt;/div&gt;&lt;div&gt;■ PEAP works in two phases. In Phase 1, server-side authentication is performed and an &lt;/div&gt;&lt;div&gt;encrypted tunnel (TLS) is created. In Phase 2, the client is authenticated using either EAP-&lt;/div&gt;&lt;div&gt;GTC or EAP-MSCHAPv2 within the TLS tunnel. &lt;/div&gt;&lt;div&gt;■ PEAP-MSCHAPv2 supports single sign-on, but Cisco PEAP-GTC supplicant does not &lt;/div&gt;&lt;div&gt;support single logon&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-8559222066193846553?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/8559222066193846553/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=8559222066193846553' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/8559222066193846553'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/8559222066193846553'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2009/09/eap.html' title='EAP'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-1523290662411973659</id><published>2009-09-14T16:19:00.004+04:00</published><updated>2009-09-14T16:47:59.995+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='wireless'/><category scheme='http://www.blogger.com/atom/ns#' term='ont'/><title type='text'>Wireless</title><content type='html'>&lt;div&gt;&lt;b&gt;Autonomous APs&lt;/b&gt;—  WLSE + WDS&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;WLSE&lt;/i&gt; -  centralized conﬁguration, monitoring, and management&lt;/div&gt;&lt;div&gt;&lt;i&gt;WDS&lt;/i&gt; -radio monitoring and management communication between the autonomous APs and &lt;/div&gt;&lt;div&gt;CiscoWorks WLSE&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;LWAP  - &lt;/b&gt; WLC (controllers) + WCS &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;WLSE&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;■ &lt;b&gt;Conﬁguration&lt;/b&gt;—One CiscoWorks WLSE console supports &lt;i&gt;up to 2500 APs&lt;/i&gt;. Conﬁguration &lt;/div&gt;&lt;div&gt;changes can be performed in mass, individually, or in deﬁned groups as desired or on a &lt;/div&gt;&lt;div&gt;schedule time. All Cisco Aironet APs are supported.&lt;/div&gt;&lt;div&gt;■ &lt;b&gt;Fault and policy monitoring&lt;/b&gt;—WLSE monitors device faults and performance threshold &lt;/div&gt;&lt;div&gt;conditions &lt;/div&gt;&lt;div&gt;■ &lt;b&gt;Reporting&lt;/b&gt;—WLSE provides the capability to e-mail, print, and export reports. Client, &lt;/div&gt;&lt;div&gt;device, and security information can all be tracked and reported.&lt;/div&gt;&lt;div&gt;■ &lt;b&gt;Firmware&lt;/b&gt;—WLSE performs centralized ﬁrmware upgrades. Upgrades can be done in mass, &lt;/div&gt;&lt;div&gt;individually, or in deﬁned groups as desired or on a scheduled time.&lt;/div&gt;&lt;div&gt;■ &lt;b&gt;Radio management&lt;/b&gt;—WLSE assists in management of the WLAN radio environment. Radio &lt;/div&gt;&lt;div&gt;management features include parameter generation, network status, and reports.&lt;/div&gt;&lt;div&gt;■ &lt;b&gt;Deployment wizard&lt;/b&gt;—WLSE provides a deployment wizard that discovers, uploads &lt;/div&gt;&lt;div&gt;&lt;div&gt;conﬁgurations, and manages all deployed AP&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;b&gt;WCS&lt;/b&gt; has three versions:&lt;/div&gt;&lt;div&gt;■ WCS Base&lt;/div&gt;&lt;div&gt;■ WCS Location&lt;/div&gt;&lt;div&gt;■ WCS Location + 2700 Series Wireless Location Appliance&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;■ &lt;b&gt;Conﬁguration&lt;/b&gt; for controllers and managed APs using customer-deﬁned templates&lt;/div&gt;&lt;div&gt;■ &lt;b&gt;Status and alarm monitoring&lt;/b&gt; of all managed devices with automated and manual client &lt;/div&gt;&lt;div&gt;monitoring and control functions&lt;/div&gt;&lt;div&gt;■ &lt;b&gt;Automated monitoring of rogue APs&lt;/b&gt;, coverage holes, security violations, controllers, and APs&lt;/div&gt;&lt;div&gt;■ &lt;b&gt;Event log &lt;/b&gt;information for data clients, rogue APs, coverage holes, security violations, &lt;/div&gt;&lt;div&gt;controllers, and APs&lt;/div&gt;&lt;div&gt;■ Automatic channel and power level assignment using &lt;b&gt;radio resource managemen&lt;/b&gt;t (&lt;b&gt;RRM&lt;/b&gt;)&lt;/div&gt;&lt;div&gt;■ &lt;b&gt;User-deﬁned audit&lt;/b&gt; status, missed trap polling, conﬁguration backups, and policy cleanups&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-1523290662411973659?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/1523290662411973659/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=1523290662411973659' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/1523290662411973659'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/1523290662411973659'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2009/09/wireless.html' title='Wireless'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-6051595806973632894</id><published>2009-07-20T12:00:00.002+04:00</published><updated>2009-07-20T12:58:23.016+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cisco'/><category scheme='http://www.blogger.com/atom/ns#' term='ont'/><category scheme='http://www.blogger.com/atom/ns#' term='ipt'/><title type='text'>IPT basics</title><content type='html'>Signaling protocols&lt;div&gt;1) H.323  - ITU standart&lt;/div&gt;&lt;div&gt;2) MGCP - IETF st&lt;/div&gt;&lt;div&gt;3) SIP - IETF st&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;Regardless of the signaling &lt;/div&gt;&lt;div&gt;protocol used, a phone call has three main stages:&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;call setup&lt;/li&gt;&lt;li&gt;call maintenance&lt;/li&gt;&lt;li&gt;call teardown.&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;b&gt;1) Call setup&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;During call setup, the destination telephone number must be resolved to an IP address, where the &lt;/div&gt;&lt;div&gt;call request message must be sent; this is called call routing. Call admission control (CAC) is an &lt;/div&gt;&lt;div&gt;optional step that determines whether the network has sufﬁcient bandwidth for the call. If bandwidth &lt;/div&gt;&lt;div&gt;is inadequate, CAC sends a message to the initiator indicating that the call cannot get through &lt;/div&gt;&lt;div&gt;because of insufﬁcient resources. (The caller usually hears a fast busy tone.) &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If call routing and CAC succeed, a call request message is sent toward the destination. If the &lt;/div&gt;&lt;div&gt;destination is not busy and it accepts the call, some parameters for the call must be negotiated &lt;/div&gt;&lt;div&gt;before voice communication begins. Following are a few of the important parameters that must be &lt;/div&gt;&lt;div&gt;negotiated:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;■ The IP addresses to be used as the destination and source of the VoIP packets between the call &lt;/div&gt;&lt;div&gt;end points&lt;/div&gt;&lt;div&gt;■ The destination and source User Datagram Protocol (UDP) port numbers that the RTP uses at &lt;/div&gt;&lt;div&gt;each call end point &lt;/div&gt;&lt;div&gt;■ The compression algorithm (codec) to be used for the call; for example, whether G.729, &lt;/div&gt;&lt;div&gt;G.711, or another standard will be used&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;2) Call maintenance&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;Call maintenance collects statistics such as packets exchanged, packets lost, end-to-end delay, and &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;jitter during the VoIP call. The end points (devices such as IP phones) that collect this information &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;can locally analyze this data and display the call quality information upon request, or they can &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;submit the results to another device for centralized data analysis.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;/span&gt;3)Call teardown&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;is simply "hanging up"  and sending appropriate notiﬁcation to the other end point and any control devices so that the resources can be made free.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;div&gt;&lt;b&gt;Analog-to-digital conversion&lt;/b&gt; involves four major steps:&lt;/div&gt;&lt;div&gt;&lt;i&gt;1. Sampling&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;2. Quantization&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;3. Encoding&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;4. Compression (optional)&lt;/i&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/b&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-6051595806973632894?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/6051595806973632894/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=6051595806973632894' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/6051595806973632894'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/6051595806973632894'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2009/07/ipt-basics.html' title='IPT basics'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-3942064446842239417</id><published>2009-05-25T10:34:00.004+04:00</published><updated>2009-05-25T11:59:43.877+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iscw'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Cisco IPS/IDS</title><content type='html'>&lt;div style="text-align: center;"&gt;ISR Built-in NIPS config&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;b&gt;Step 1&lt;/b&gt; Specify the location of the SDF—Various SDFs can exist in the Cisco IOS &lt;/div&gt;&lt;div&gt;device, but only one can be referenced.&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;! step 1 – define the location of the SDF&lt;/div&gt;&lt;div&gt;Router(config)#ip ips sdf  ?&lt;/div&gt;&lt;div&gt;  builtin   Use the built in signature definition file&lt;/div&gt;&lt;div&gt;  location  Location of the signature definition file&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Step 2&lt;/b&gt; Conﬁgure the failure parameter—This tells the Cisco IOS device what &lt;/div&gt;&lt;div&gt;to do if the signature microengine (SME) is not available to scan the trafﬁc.&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;! step 2 – define the behavior if an SME fails&lt;/div&gt;&lt;div&gt;Router(config)#ip ips fail ?&lt;/div&gt;&lt;div&gt;  closed  Do not forward traffic of the failed module.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;Router(config)#ip ips fail closed&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;b&gt;Step 3&lt;/b&gt; Create an IPS rule—This creates a name that is later applied to an interface. &lt;/div&gt;&lt;div&gt;The rule uses the SDF previously deﬁned. Optionally, an access control list &lt;/div&gt;&lt;div&gt;(ACL) can be applied to restrict which trafﬁc is scanned.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;! step 3 – create an IPS rule, and optionally apply an ACL&lt;/div&gt;&lt;div&gt;Router(config)#ip ips name ?&lt;/div&gt;&lt;div&gt;  WORD  Name of IPS rule&lt;/div&gt;&lt;div&gt;Router(config)#ip ips  name   testips ?&lt;/div&gt;&lt;div&gt;  list  Specify an access list to match&lt;/div&gt;&lt;div&gt;  &lt;cr&gt;&lt;/cr&gt;&lt;/div&gt;&lt;div&gt;Router(config)#ip ips  name   testips list 123&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Step 4&lt;/b&gt; Apply the IPS rule to an interface—Once the rule has been created, it must &lt;/div&gt;&lt;/div&gt;&lt;div&gt;be applied to an interface to become operational.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;! step 4 – apply the IPS rule to&lt;/div&gt;&lt;div&gt;Router(config)#interface fastethernet 0/0&lt;/div&gt;&lt;div&gt;Router(config-if)#ip ips testips ?&lt;/div&gt;&lt;div&gt;  in   Inbound IPS&lt;/div&gt;&lt;div&gt;  out  Outbound IPS&lt;/div&gt;&lt;div&gt;Router(config-if)#ip ips  testips in&lt;/div&gt;&lt;div&gt;Router(config-if)#&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Additional config&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ieNEtWk3S4E/ShpFJRwj8HI/AAAAAAAAAMk/HHOt2GCPzK0/s1600-h/ips_conf.PNG"&gt;&lt;img src="http://1.bp.blogspot.com/_ieNEtWk3S4E/ShpFJRwj8HI/AAAAAAAAAMk/HHOt2GCPzK0/s400/ips_conf.PNG" border="0" alt="" id="BLOGGER_PHOTO_ID_5339656333889368178" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 400px; height: 296px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-3942064446842239417?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/3942064446842239417/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=3942064446842239417' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/3942064446842239417'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/3942064446842239417'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2009/05/cisco-ipsids.html' title='Cisco IPS/IDS'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_ieNEtWk3S4E/ShpFJRwj8HI/AAAAAAAAAMk/HHOt2GCPzK0/s72-c/ips_conf.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-1863046781415221567</id><published>2009-05-20T17:26:00.003+04:00</published><updated>2009-05-20T17:34:20.564+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iscw'/><category scheme='http://www.blogger.com/atom/ns#' term='vpn'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>VPN Statefull</title><content type='html'>&lt;div&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;IPsec stateful failover uses two protocols for proper and continual operation: &lt;/div&gt;&lt;div&gt;■ HSRP—Monitors both the inside and outside interfaces. If either goes down, the entire router &lt;/div&gt;&lt;div&gt;is deemed unworthy and ownership of the IKE and IPsec SA processes is passed to the &lt;/div&gt;&lt;div&gt;standby router. When this transition occurs, the standby router becomes the active HSRP &lt;/div&gt;&lt;div&gt;router.&lt;/div&gt;&lt;div&gt;■ Stateful Switchover (SSO)—Shares the IKE and IPsec SA information between the active &lt;/div&gt;&lt;div&gt;and backup routers. At any time, either router knows enough to be the active IPsec VPN &lt;/div&gt;&lt;div&gt;router.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;There are some limitations/restrictions:&lt;/span&gt; &lt;br /&gt;&lt;/div&gt;&lt;div&gt;■ Both the active and standby devices must run an identical Cisco IOS release.&lt;/div&gt;&lt;div&gt;■ The active and standby devices must be connected via LAN ports, either directly or through &lt;/div&gt;&lt;div&gt;a switch. WAN interfaces are not supported.&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;■ Both the inside and outside interfaces must be connected via LAN ports.&lt;/div&gt;&lt;div&gt;■ Only “box-to-box” failover is supported. Intrachassis (card-to-card) failover is not currently &lt;/div&gt;&lt;div&gt;supported.&lt;/div&gt;&lt;div&gt;■ Load balancing is not supported. Only one device in a redundancy group can be active at any &lt;/div&gt;&lt;div&gt;time.&lt;/div&gt;&lt;div&gt;■ IKE keepalive messages are not supported. DPD and periodic DPD are supported.&lt;/div&gt;&lt;div&gt;■ Stateful failover of Layer 2 Tunneling Protocol (L2TP) is not supported.&lt;/div&gt;&lt;div&gt;■ IPsec idle timers are not supported.&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ieNEtWk3S4E/ShQF9E-S-oI/AAAAAAAAAMc/i9OrARLgq_g/s1600-h/vpn_statefull.PNG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 115px;" src="http://1.bp.blogspot.com/_ieNEtWk3S4E/ShQF9E-S-oI/AAAAAAAAAMc/i9OrARLgq_g/s320/vpn_statefull.PNG" border="0" alt="" id="BLOGGER_PHOTO_ID_5337898005206071938" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;Router C:&lt;br /&gt;&lt;/div&gt;&lt;div&gt;crypto dynamic-map from-remote 10&lt;/div&gt;&lt;div&gt; set transform-set trans1&lt;/div&gt;&lt;div&gt; reverse-route&lt;/div&gt;&lt;div&gt;!&lt;/div&gt;&lt;div&gt;crypto map central-office 10 ipsec-isakmp dynamic from-remote&lt;/div&gt;&lt;div&gt;!&lt;/div&gt;&lt;div&gt;interface fastethernet 1/0&lt;/div&gt;&lt;div&gt; ip address 172.20.1.1 255.255.255.0&lt;/div&gt;&lt;div&gt; standby 1 ip 172.20.1.5&lt;/div&gt;&lt;div&gt; standby 1 priority 150&lt;/div&gt;&lt;div&gt; standby 1 preempt&lt;/div&gt;&lt;div&gt; standby 1 name vpn-remote&lt;/div&gt;&lt;div&gt; crypto map central-office redundancy vpn-remote stateful&lt;/div&gt;&lt;div&gt;!&lt;/div&gt;&lt;div&gt;redundancy inter-device&lt;/div&gt;&lt;div&gt; scheme standby vpn-remote&lt;/div&gt;&lt;div&gt;!&lt;/div&gt;&lt;div&gt;ipc zone default&lt;/div&gt;&lt;div&gt; association 1&lt;/div&gt;&lt;div&gt; protocol sctp&lt;/div&gt;&lt;div&gt;  local-port 12321&lt;/div&gt;&lt;div&gt; local-ip 10.20.1.1&lt;/div&gt;&lt;div&gt; retransmit-timeout 300 10000&lt;/div&gt;&lt;div&gt; path-retransmit 10&lt;/div&gt;&lt;div&gt; assoc-retransmit 20&lt;/div&gt;&lt;div&gt;  remote-port 12321&lt;/div&gt;&lt;div&gt; remote-ip 10.20.1.2&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-1863046781415221567?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/1863046781415221567/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=1863046781415221567' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/1863046781415221567'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/1863046781415221567'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2009/05/vpn-statefull.html' title='VPN Statefull'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_ieNEtWk3S4E/ShQF9E-S-oI/AAAAAAAAAMc/i9OrARLgq_g/s72-c/vpn_statefull.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-2879317861440241482</id><published>2009-05-12T15:11:00.005+04:00</published><updated>2009-05-12T15:36:24.475+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='iscw'/><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><title type='text'>MPLS VPN Overview</title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_ieNEtWk3S4E/SglZ0eZBGXI/AAAAAAAAAMM/CSvayNLaErM/s1600-h/mpls_vpn.PNG"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 238px;" src="http://2.bp.blogspot.com/_ieNEtWk3S4E/SglZ0eZBGXI/AAAAAAAAAMM/CSvayNLaErM/s320/mpls_vpn.PNG" border="0" alt="" id="BLOGGER_PHOTO_ID_5334893991643126130" /&gt;&lt;/a&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span"  style=" ;font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;RD - Route Distiguisher&lt;/span&gt; -&lt;span class="Apple-style-span" style="font-weight: bold;"&gt; &lt;/span&gt;определяет принадлежность роутов к vrf instatnce. 64-bit value&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;RT - Route Target - &lt;/span&gt;позволяет нескольким клиентам с разными RD взаимодействовать. Можно определить какие роуты будут импортироваться или экспортироваться в зону с другим RD&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: verdana;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-family: verdana;"&gt;&lt;span class="Apple-style-span" style="font-family: Georgia; "&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ieNEtWk3S4E/SglfBMkbfuI/AAAAAAAAAMU/dqsLCBCVj6c/s1600-h/mpls_vpn2.PNG"&gt;&lt;img src="http://3.bp.blogspot.com/_ieNEtWk3S4E/SglfBMkbfuI/AAAAAAAAAMU/dqsLCBCVj6c/s320/mpls_vpn2.PNG" border="0" alt="" id="BLOGGER_PHOTO_ID_5334899707755593442" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 320px; height: 238px; " /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span"  style="font-family:verdana;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-2879317861440241482?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/2879317861440241482/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=2879317861440241482' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2879317861440241482'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2879317861440241482'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2009/05/mpls-vpn-overview.html' title='MPLS VPN Overview'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/_ieNEtWk3S4E/SglZ0eZBGXI/AAAAAAAAAMM/CSvayNLaErM/s72-c/mpls_vpn.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-8221639558548927300</id><published>2009-04-20T11:33:00.001+04:00</published><updated>2009-04-20T11:35:01.854+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='iscw'/><category scheme='http://www.blogger.com/atom/ns#' term='quick notes'/><category scheme='http://www.blogger.com/atom/ns#' term='pppoe'/><title type='text'>PPPoE config</title><content type='html'>&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;int dialer 1&lt;/span&gt;&lt;/div&gt;&lt;div&gt;(config-if)#ip mtu 1492 --- PPPoE adds 8 bytes header&lt;/div&gt;&lt;div&gt;(config-if)#ip address negotiate&lt;/div&gt;&lt;div&gt;(config-if)#encapsulation ppp&lt;br /&gt;&lt;/div&gt;&lt;div&gt;(config-if)#ppp authentication pap (chap) callin -- callin - one-way auth. ISP wants us to sent our credentials&lt;br /&gt;&lt;/div&gt;&lt;div&gt;but don't want to auth itself&lt;/div&gt;&lt;div&gt;Теперь надо привязать виртуальный dialer 1 к физическому интерфейсу через dialer-pool&lt;br /&gt;&lt;/div&gt;&lt;div&gt;(config-if)#dialer-pool 1&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;int fa 4&lt;/span&gt;&lt;/div&gt;&lt;div&gt;(config-if)#pppoe enable&lt;/div&gt;&lt;div&gt;(config-if)#pppoe-client dial-pool-number 1&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-8221639558548927300?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/8221639558548927300/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=8221639558548927300' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/8221639558548927300'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/8221639558548927300'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2009/04/pppoe-config.html' title='PPPoE config'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-6598615464697510090</id><published>2009-01-19T11:47:00.003+03:00</published><updated>2009-01-19T12:18:26.975+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><category scheme='http://www.blogger.com/atom/ns#' term='ipv6'/><title type='text'>IPv6 Translation</title><content type='html'>Translation is a different type of solution, allowing IPv6 devices to communicate with IPv4&lt;br /&gt;devices, without requiring either to be dual stack.&lt;br /&gt;&lt;br /&gt;Stateless IP/ICMP Translation (SIIT) translates IP header ﬁelds, and NAT Protocol Translation (NAT-PT) maps IPv6 addresses to IPv4 addresses. If IPv6 is used on the inside of a network and IPv4 is used on the outside, a NAT-PT device receives IPv6 trafﬁc on its inside interface and replaces the IPv6 header with an IPv4 header before sending it to an outside interface. Reply trafﬁc follows the mapping backwards, enabling two-way communication.&lt;br /&gt;Good NAT implementations interpret application trafﬁc and understand when IP information is included in the application data; NAT-PT inherits this capability. For example, DNS packets&lt;br /&gt;include IP addresses; therefore, NAT-PT must recognize DNS trafﬁc and change the IPv4&lt;br /&gt;addresses into IPv6 addresses, and vice-versa.&lt;br /&gt;IPv4 and IPv6 routing domains can also be connected using application-level gateways (ALG) or proxies. A proxy intercepts trafﬁc and converts between the two protocols; it can increase the transmission speed by responding to some requests using information in its cache. A separate ALG is required to support each protocol, so this method only solves speciﬁc types of translation problems.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-6598615464697510090?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/6598615464697510090/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=6598615464697510090' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/6598615464697510090'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/6598615464697510090'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2009/01/ipv6-translation.html' title='IPv6 Translation'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-3585125177717141149</id><published>2009-01-19T10:45:00.007+03:00</published><updated>2009-01-19T12:21:05.692+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><category scheme='http://www.blogger.com/atom/ns#' term='ipv6'/><title type='text'>IPv6 tunneling</title><content type='html'>1) Manual&lt;br /&gt;2) 6to4&lt;br /&gt;3) Teredo&lt;br /&gt;4) ISATAP&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Manual&lt;/span&gt;&lt;br /&gt;&lt;p&gt;&lt;span style="font-size:78%;"&gt;Example configuration: &lt;/span&gt;&lt;/p&gt; &lt;pre&gt;&lt;code&gt;Router(config)# interface tunnel0&lt;br /&gt;Router(config-if)# ipv6 address 2001:0:1:5::1/64&lt;br /&gt;Router(config-if)# tunnel source 192.168.1.1&lt;br /&gt;Router(config-if)# tunnel destination 192.168.2.1&lt;br /&gt;Router(config-if)# tunnel mode ipv6ip&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;h5&gt;&lt;span style="font-size:100%;"&gt;6-to-4 Tunnels&lt;/span&gt;&lt;/h5&gt; &lt;p&gt;6-to-4 tunnels work similar to manual tunnels but are set up automatically.6-to-4 tunnels concatenate &lt;span style="font-family: webdings; font-weight: bold;font-size:100%;" &gt;&lt;code&gt;&lt;span style="font-family: verdana;"&gt;2002::/16&lt;/span&gt;&lt;/code&gt;&lt;/span&gt; with the 32-bit IPv4 address of the edge router, creating a 48-bit prefix.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Ex:&lt;/span&gt; The tunnel interface on Router A has&lt;br /&gt;an IPv6 preﬁx of 2002:C0A8:501::/48, where C0A8:501 is the hexadecimal equivalent of&lt;br /&gt;192.168.5.1, the IPv4 address of its interface in the IPv4 network.&lt;/p&gt;&lt;span style="font-weight: bold;"&gt;Teredo&lt;/span&gt;&lt;br /&gt;Another type of tunnel is called Teredo (also known as shipworm). Teredo encapsulates IPv6&lt;br /&gt;packets in IPv4/UDP segments and works similarly to other tunnels but with the added beneﬁt of&lt;br /&gt;being able to traverse network address translation (NAT) devices and ﬁrewalls. Teredo is described&lt;br /&gt;in RFC 4380, Teredo: Tunneling IPv6 over UDP through Network Address Translations (NAT).&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ISATAP&lt;/span&gt;&lt;br /&gt;ISATAP treats the IPv4 network as an NBMA network and allows an IPv4 private network to&lt;br /&gt;incrementally implement IPv6 without upgrading the network. ISATAP is documented in RFC&lt;br /&gt;4214, Intra-Site Automatic Tunnel Addressing Protocol (ISATAP).&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-3585125177717141149?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/3585125177717141149/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=3585125177717141149' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/3585125177717141149'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/3585125177717141149'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2009/01/ipv6-tunneling.html' title='IPv6 tunneling'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-7125082493690678809</id><published>2009-01-18T14:48:00.004+03:00</published><updated>2009-01-18T15:00:35.514+03:00</updated><title type='text'>Route Maps</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ieNEtWk3S4E/SXMZ3n39nmI/AAAAAAAAAKE/UhUU4oa-qH0/s1600-h/route_maps.png"&gt;&lt;img style="display:block; margin:0px auto 10px; text-align:center;cursor:pointer; cursor:hand;width: 320px; height: 222px;" src="http://1.bp.blogspot.com/_ieNEtWk3S4E/SXMZ3n39nmI/AAAAAAAAAKE/UhUU4oa-qH0/s320/route_maps.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5292602430477672034" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;div style="text-align: left;"&gt;■ Each route map statement has &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;permit&lt;/span&gt; or &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;deny&lt;/span&gt; permission. Trafﬁc that matches a permit is &lt;/div&gt;&lt;div style="text-align: left;"&gt;affected by the route map. Trafﬁc that matches a deny, or does not ﬁnd a match in the list, is &lt;/div&gt;&lt;div style="text-align: left;"&gt;not affected by the route map.&lt;/div&gt;&lt;div style="text-align: left;"&gt;■ Trafﬁc that is not explicitly permitted is implicitly denied.&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;div style="text-align: left;"&gt;■ Each route map statement has zero or more match conditions. A statement without a match &lt;/div&gt;&lt;div style="text-align: left;"&gt;applies to all trafﬁc (like the any option in an access list). &lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 0, 238); text-decoration: underline;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-7125082493690678809?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/7125082493690678809/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=7125082493690678809' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/7125082493690678809'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/7125082493690678809'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2009/01/route-maps_18.html' title='Route Maps'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_ieNEtWk3S4E/SXMZ3n39nmI/AAAAAAAAAKE/UhUU4oa-qH0/s72-c/route_maps.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-6357896409576615815</id><published>2009-01-16T12:06:00.003+03:00</published><updated>2009-01-17T20:09:57.341+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><category scheme='http://www.blogger.com/atom/ns#' term='redistribution'/><title type='text'>Route Redistribution</title><content type='html'>It is important to consider the following rules when redistributing between IP routing protocols:&lt;br /&gt;&lt;br /&gt;■ If more than one routing protocol is running on a router, the routing table process will place&lt;br /&gt;the route with the best administrative distance into the routing table.&lt;br /&gt;■ Routing protocols can only redistribute routes they know. Thus, if RIP is being redistributed&lt;br /&gt;into EIGRP, the routing table must have an entry for the RIP network.&lt;br /&gt;■ When a route is redistributed, it inherits the default administrative distance of the new routing&lt;br /&gt;protocol.&lt;br /&gt;■ Redistributed routes are called external. External routes in EIGRP are given a different&lt;br /&gt;(higher) AD, while OSPF tracks the route as external and prefers internal routes.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Potential problems:&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;■ Routing loops because routers send routing information received from one autonomous &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;system back into the same autonomous system.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;■ Suboptimal routing decisions are made because of the difference in routing metrics. &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;■ The convergence time increases because of the different technologies involved. If the routing &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;protocols converge at different rates, this might result in timeouts and the temporary loss of &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;networks.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;■ The decision-making process and the information sent within the protocols might be &lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;incompatible and not easily exchanged, leading to errors and complex conﬁguration.&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;Control Methods:&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal; "&gt;■ Passive interfaces&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;&lt;div&gt;■ Static routes&lt;/div&gt;&lt;div&gt;■ Default routes&lt;/div&gt;&lt;div&gt;■ The null interface&lt;/div&gt;&lt;div&gt;■ Distribute lists&lt;/div&gt;&lt;div&gt;■ Route maps&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-6357896409576615815?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/6357896409576615815/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=6357896409576615815' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/6357896409576615815'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/6357896409576615815'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2009/01/route-redistribution.html' title='Route Redistribution'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-7835626969799874527</id><published>2009-01-14T10:44:00.002+03:00</published><updated>2009-01-14T12:23:30.974+03:00</updated><title type='text'>Route-maps</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ieNEtWk3S4E/SW2YIXS4uMI/AAAAAAAAAJ0/33ltmW9f2ss/s1600-h/route_maps.png"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 222px;" src="http://1.bp.blogspot.com/_ieNEtWk3S4E/SW2YIXS4uMI/AAAAAAAAAJ0/33ltmW9f2ss/s320/route_maps.png" alt="" id="BLOGGER_PHOTO_ID_5291052406689806530" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-7835626969799874527?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/7835626969799874527/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=7835626969799874527' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/7835626969799874527'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/7835626969799874527'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2009/01/route-maps.html' title='Route-maps'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_ieNEtWk3S4E/SW2YIXS4uMI/AAAAAAAAAJ0/33ltmW9f2ss/s72-c/route_maps.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-323091457313782464</id><published>2009-01-11T13:58:00.022+03:00</published><updated>2009-01-20T12:00:27.889+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><category scheme='http://www.blogger.com/atom/ns#' term='ipv6'/><title type='text'>IPv6 basics</title><content type='html'>&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;IPv6 address format&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;-&lt;span style="font-style: italic;font-family:verdana;" &gt;8&lt;/span&gt;&lt;span style="font-family:verdana;"&gt; groups,&lt;/span&gt;&lt;span style="font-style: italic;font-family:verdana;" &gt; 4&lt;/span&gt;&lt;span style="font-family:verdana;"&gt; hex (16  each&lt;/span&gt;:  &lt;span style="font-style: italic;"&gt;2001:0db8:0000:0000:0000:0000:1428:57ab&lt;br /&gt;&lt;span style="font-style: italic;"&gt;-::1/128 - loopback address&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Address types&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1)Link-local scope&lt;/span&gt; &lt;/span&gt;&lt;/span&gt;&lt;span&gt;- адреса для коннективити внутри L2-домена только. Аналог 169.254.x.x в Windows. Позволяет обмен трафика без настроек внутри сабнета по IP.&lt;br /&gt;-Генерится автоматом при включении хоста.&lt;br /&gt;-Всегда начинается с FE80 (1111 1110 1000), потом 54 bit нулей и последние 64 bit - MAC address c внедренным внутри  "FFFE" (Ex: 0019.D122.DCF3  ---&gt;  &lt;/span&gt;&lt;span&gt;0019.D1FF.FE22.DCF3 ).&lt;br /&gt;MAC адрес преобразованный таким образом называется &lt;/span&gt;&lt;span style="font-weight: bold;"&gt;EUI-64&lt;/span&gt; (Extended Universal Identifier 64-bit) и служит &lt;span style="font-weight: bold;"&gt;Interface ID&lt;/span&gt;&lt;br /&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;2) Unique/ Site-local scope&lt;/span&gt; - аналог private subnets. Внутренние адреса организации. &lt;span style="font-style: italic;"&gt;Depricated ?&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;3) &lt;span style="font-weight: bold;"&gt;Global&lt;/span&gt;&lt;/span&gt; - глобальные адреса.&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ieNEtWk3S4E/SXWRHPk3w6I/AAAAAAAAAKk/kHXTpAmpv9A/s1600-h/ipv6_address_structure.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 81px;" src="http://3.bp.blogspot.com/_ieNEtWk3S4E/SXWRHPk3w6I/AAAAAAAAAKk/kHXTpAmpv9A/s320/ipv6_address_structure.PNG" alt="" id="BLOGGER_PHOTO_ID_5293296490670179234" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;Address optimization rules:&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;1) Можно убирать нули идущие подряд&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;2001:0db8:0000:0000:0000:0000:1428:57ab&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;2001:0db8:0:0:0:0:1428:57ab&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;2001:0db8::1428:57ab&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;NOTE!&lt;/span&gt;&lt;span style="font-style: italic;"&gt;  &lt;/span&gt;&lt;span&gt;Символ :: нормально интерпретируется только один раз. Тоесть нельзя полностью убрать нули в двух разделенных другими символами  октетах&lt;/span&gt;&lt;span style="font-style: italic;"&gt; !NOTE&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;2) Можно убирать ведущие нули&lt;br /&gt;&lt;span style="font-style: italic;"&gt;2001:0db8::1428:57ab&lt;br /&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt;2001:db8::1428:57ab&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Communication types&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;1) Unicast&lt;/span&gt;  - one-to-one, same as IPv4&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;2) Multicast&lt;/span&gt; - same as IPv4, but broadcast now is a kind of multicast group "to all"&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3) Anycast&lt;/span&gt; - one-to-closest. Фактически встроенный load-balancing. Можно назначить один адрес многим устройствам аля "виртуальный ip в hsrp " и  отвечать будет ближайший к клиенту.&lt;br /&gt;&lt;br /&gt;IPv6 configuration&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;code&gt;(config)#ipv6 unicast-routing&lt;br /&gt;(config)#ipv6 cef&lt;br /&gt;(config-if)# ipv6 address [address]/[prefix] [eui-64]&lt;/code&gt;&lt;/pre&gt;The &lt;span style="font-weight: bold;"&gt;eui-64&lt;/span&gt; parameter causes the router to complete the lower order 64 bits of the address using an extended universal identiﬁer 64-bit (EUI-64) format interface ID&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-323091457313782464?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/323091457313782464/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=323091457313782464' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/323091457313782464'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/323091457313782464'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2009/01/ipv6-basics.html' title='IPv6 basics'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_ieNEtWk3S4E/SXWRHPk3w6I/AAAAAAAAAKk/kHXTpAmpv9A/s72-c/ipv6_address_structure.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-2694652493291317570</id><published>2009-01-09T15:02:00.004+03:00</published><updated>2009-01-09T15:21:43.191+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cisco'/><category scheme='http://www.blogger.com/atom/ns#' term='multicast'/><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><title type='text'>Multicast basics</title><content type='html'>&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;quick facts&lt;/span&gt;&lt;div&gt;-udp only&lt;/div&gt;&lt;div&gt;-224.0.0.0 - 239.255.255.255&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;|Client| -------|Switch|----------|Router|------|Internet|------|multicast server|&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;IGMP используется  для организации подписки клиента к мультикаст группе. Служит своего рода source based routing protocol, для нахождения лучшего пути к источнику "вещания" ( например серверу видео stream)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Существует IGMPv3, наиболее используемым является IGMPv2&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Если свитч не сконфигурирован для multicast, то по умолчанию он обрабатывает multicast traffic как броадкаст, тоесть рассылает всем.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Есть два метода поддержки multicast свитчом&lt;/div&gt;&lt;div&gt;1) Cisco Group Managment Protocol (CGMP) - cisco proprietary. Роутер по протоколу CGMP сообщает L2-свитчу, для каких маков пересылать трафик&lt;/div&gt;&lt;div&gt;2)IGMP snooping - Стандарт.Фактически весь функционал поддержки multicast переносится на свитч. Необходим L3 свитч. Если клиентов много, может создать сильную нагрузку на свитч.&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-2694652493291317570?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/2694652493291317570/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=2694652493291317570' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2694652493291317570'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2694652493291317570'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2009/01/multicast-basics.html' title='Multicast basics'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-1232775860132684567</id><published>2008-12-23T16:30:00.005+03:00</published><updated>2008-12-23T17:50:08.313+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='quick notes'/><category scheme='http://www.blogger.com/atom/ns#' term='vpn'/><title type='text'>VPN GRE tunnel with IPSEC</title><content type='html'>&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;quick checklist&lt;/span&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;1)&lt;/span&gt; crypto isakmp policy 10&lt;/div&gt;&lt;div&gt; encr aes 256&lt;/div&gt;&lt;div&gt; authentication pre-share&lt;/div&gt;&lt;div&gt; group 2&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;2)&lt;/span&gt; crypto isakmp key cisco address 192.168.3.2 no-xauth&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;3)&lt;/span&gt; crypto ipsec transform-set DEMO esp-aes 256 esp-sha-hmac&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;4)&lt;/span&gt; crypto ipsec profile VPN_PROFILE&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt;set transform-set DEMO &lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;5)&lt;/span&gt;  tunnel int&lt;/div&gt;&lt;div&gt;   &lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt; ip address 192.168.3.1 255.255.255.0&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt; tunnel source FastEthernet0/0&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt; tunnel destination 10.0.0.2&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt; tunnel mode ipsec ipv4&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-tab-span" style="white-space:pre"&gt; &lt;/span&gt; tunnel protection ipsec profile VPN_PROFILE&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-1232775860132684567?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/1232775860132684567/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=1232775860132684567' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/1232775860132684567'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/1232775860132684567'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/12/vpn-gre-tunnel-with-ipsec.html' title='VPN GRE tunnel with IPSEC'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-2332382309786035</id><published>2008-12-17T12:33:00.004+03:00</published><updated>2009-01-05T20:21:18.198+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><category scheme='http://www.blogger.com/atom/ns#' term='bgp'/><title type='text'>Controlling Route Selection</title><content type='html'>&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;Weight Attribute&lt;/span&gt;&lt;br /&gt;The weight attribute is Cisco proprietary, and is considered before any other attribute.&lt;br /&gt;Weight is local to the router and not propagated to other routers.&lt;br /&gt;Weight is a 16-bit value; higher is preferable. Default is 0 if the route is learned from a peer, or 32,768 if sourced locally.&lt;br /&gt;&lt;br /&gt;Router(config-router)# neighbor {&amp;lt;IP address&amp;gt; | &amp;lt;group name&amp;gt;} weight &amp;lt;weight&amp;gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Local-Preference Attribute&lt;/span&gt;&lt;br /&gt;Local preference is a 32-bit value; higher values are preferred. Default value is 100.&lt;br /&gt;Распространяется только в пределах одной AS ! Не переходит в другие !&lt;br /&gt;Общий стандарт.&lt;br /&gt;&lt;br /&gt;Configured as a default:&lt;br /&gt;Router(config-router)# bgp default local-preference &amp;lt;value&amp;gt;&lt;br /&gt;&lt;br /&gt;Configured per prefix (via a route-map):&lt;br /&gt;Router(config-router)# neighbor {&amp;lt;IP address&amp;gt; | &amp;lt;group name&amp;gt;} route-map &amp;lt;map name&amp;gt; in&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;MED Attribute&lt;/span&gt;&lt;br /&gt;The multi-exit discriminator is used to influence path selection by external neighbors routing into the AS.&lt;br /&gt;Default MED value is 0; lower is preferred.&lt;br /&gt;&lt;br /&gt;Configured as a default:&lt;br /&gt;Router(config-router)# default-metric &amp;lt;value&amp;gt;&lt;br /&gt;MED can also be configured per prefix via route-maps.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-2332382309786035?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/2332382309786035/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=2332382309786035' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2332382309786035'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2332382309786035'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/12/controlling-route-selection.html' title='Controlling Route Selection'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-4250370611006674568</id><published>2008-12-10T14:20:00.004+03:00</published><updated>2008-12-10T16:55:01.537+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><category scheme='http://www.blogger.com/atom/ns#' term='bgp'/><title type='text'>BGP Attributes</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Categories&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;1) Well-known  - every vendor, who claimed to support BGP, must support this&lt;br /&gt;2) Optional&lt;br /&gt;&lt;br /&gt;3) Mandatory  - must be in every route update ( Ex: "next hop address" )&lt;br /&gt;4) Discretionary - optional&lt;br /&gt;&lt;br /&gt;5) Transative - travel from router to router (from AS to AS) without change&lt;br /&gt;6) Non-transative&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Some of  "&lt;span style="font-weight: bold;"&gt;Well-known&lt;/span&gt;" route attr:&lt;br /&gt;&lt;br /&gt;1) &lt;span style="font-style: italic;"&gt;AS-PATH&lt;/span&gt; (Mandatory) -  путь прохождение через AS&lt;br /&gt;2) &lt;span style="font-style: italic;"&gt;Next-hop address&lt;/span&gt; (Mandatory)&lt;br /&gt;3) &lt;span style="font-style: italic;"&gt;Origin&lt;/span&gt; (Mandatory)  - происхождение маршрута, т.е. откуда он пришел, откуда о нем стало известно.&lt;br /&gt;4) Local preference (Discretionary)&lt;br /&gt;5) Atomic aggregate (Discretionary)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Route decision process&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_ieNEtWk3S4E/ST-tnaRZ2TI/AAAAAAAAAJs/ZYVxbVsbnzs/s1600-h/bgp_attr%231.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 239px;" src="http://4.bp.blogspot.com/_ieNEtWk3S4E/ST-tnaRZ2TI/AAAAAAAAAJs/ZYVxbVsbnzs/s320/bgp_attr%231.PNG" alt="" id="BLOGGER_PHOTO_ID_5278128180880333106" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Сравнение идет &lt;span style="font-style: italic;"&gt;до первого совпадения&lt;/span&gt; ( как в ACL)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Weight&lt;/span&gt; - проприетарный атрибут циски. Имеет локальное значение. Можно указать weight для определенного neighbor ( точнее для всех  приходящих от него маршрутов). Выигрывают маршруты с большим weight .&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-4250370611006674568?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/4250370611006674568/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=4250370611006674568' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/4250370611006674568'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/4250370611006674568'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/12/bgp-attributes.html' title='BGP Attributes'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_ieNEtWk3S4E/ST-tnaRZ2TI/AAAAAAAAAJs/ZYVxbVsbnzs/s72-c/bgp_attr%231.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-5988147108996677732</id><published>2008-12-10T12:14:00.002+03:00</published><updated>2008-12-10T12:18:12.608+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cisco'/><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><category scheme='http://www.blogger.com/atom/ns#' term='bgp'/><title type='text'>BGP troubleshooting</title><content type='html'>show ip bgp sum&lt;br /&gt;show ip bgp&lt;br /&gt;show ip bgp rib-failure - может показать причину осутствия роута в роутинг таблице, несмотря на наличие этого роута в bgp table&lt;br /&gt;etc&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;deb ip bgp events&lt;br /&gt;deb ip bgp ?&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-5988147108996677732?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/5988147108996677732/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=5988147108996677732' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/5988147108996677732'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/5988147108996677732'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/12/bgp-troubleshooting.html' title='BGP troubleshooting'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-2139264195247446964</id><published>2008-12-10T11:54:00.002+03:00</published><updated>2008-12-10T12:07:54.843+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cisco'/><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><category scheme='http://www.blogger.com/atom/ns#' term='bgp'/><title type='text'>BGP neighbor relationship</title><content type='html'>* Idle (active) - Searching for neighbors&lt;br /&gt;    * Connect (active) - TCP connection established&lt;br /&gt;    * Open Sent (active) - Open message sent&lt;br /&gt;    * Open Confirm (active) - Response received. Если сконфигуренные параметры не совпадают, возвращается к состоянию Active. SIA.&lt;br /&gt;    * Established - BGP neighborship established&lt;br /&gt;&lt;br /&gt;BGP neighborships can be confirmed with show ip bgp neighbors.&lt;br /&gt;&lt;br /&gt;Neighbors still displayed as "active" after some time has passed have not correctly peered.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-2139264195247446964?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/2139264195247446964/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=2139264195247446964' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2139264195247446964'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2139264195247446964'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/12/bgp-neighbor-relationship.html' title='BGP neighbor relationship'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-6503877680151628772</id><published>2008-12-10T11:01:00.004+03:00</published><updated>2008-12-10T11:54:27.679+03:00</updated><title type='text'>BGP peer groups</title><content type='html'>Peer groups - позволяет создать шаблон атрибутов и применить его к нескольким neighbors сразу.&lt;br /&gt;&lt;br /&gt;neighbor [name] peer-group &lt;br /&gt;neighbor [name] remote-as [num]&lt;br /&gt;neighbor [name] update-source [int_name]&lt;br /&gt;&lt;br /&gt;применить к neighbor:&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;neighbor [ip] peer-group [group_name]&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-6503877680151628772?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/6503877680151628772/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=6503877680151628772' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/6503877680151628772'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/6503877680151628772'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/12/bgp-peer-groups.html' title='BGP peer groups'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-693894596748362942</id><published>2008-12-03T16:47:00.004+03:00</published><updated>2008-12-04T13:29:53.958+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bgp'/><title type='text'>BGP notes</title><content type='html'>&lt;span style="font-weight: bold;"&gt;Packets&lt;/span&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Open&lt;/span&gt; - starts the session&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;Keepalive&lt;/li&gt;&lt;li style="font-weight: bold;"&gt;Update&lt;/li&gt;&lt;li&gt;&lt;span style="font-weight: bold;"&gt;Notification&lt;/span&gt; - smth &lt;span style="font-style: italic;"&gt;bad&lt;/span&gt; has happened; close session&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;EBGP requires direct connection, но можно обойти с помощью команды ebgp-multihop&lt;br /&gt;&lt;br /&gt;router bgp as &lt;num&gt;&lt;br /&gt;neighbor &lt;ip&gt; remote-as &lt;num&gt;&lt;br /&gt;update-source &lt;ip&gt; - если в качестве неибора указан адрес loopback&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;BGP Sync&lt;/span&gt;  (выключено после 12.2(8)T )&lt;br /&gt;Если маршрут пришел по iBGP,  но при этом не пришел по внутреннему протоколу - такой маршрут не попадет в routing table.&lt;br /&gt;&lt;br /&gt;BGP Next-hop&lt;br /&gt;&lt;br /&gt;eBGP peers - меняет next-hop на себя&lt;br /&gt;iBGP peers - не меняет next-hop на себя, оставляет как есть ( поменять поведение командой &lt;span style="font-style: italic;"&gt;next-hop-self &lt;/span&gt;)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/ip&gt;&lt;/num&gt;&lt;/ip&gt;&lt;/num&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-693894596748362942?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/693894596748362942/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=693894596748362942' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/693894596748362942'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/693894596748362942'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/12/bgp-notes.html' title='BGP notes'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-3863707537838849383</id><published>2008-11-25T10:39:00.002+03:00</published><updated>2008-11-25T10:58:46.150+03:00</updated><title type='text'>IS-IS Network Types</title><content type='html'>&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;1)&lt;/span&gt; &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;Broadcast&lt;/span&gt;&lt;/div&gt;&lt;div&gt;    -assumes full conectivity (all IS can reach each other)&lt;/div&gt;&lt;div&gt;    - elects Designated IS (DIS) - same as DR/BDR&lt;/div&gt;&lt;div&gt;    - multicast&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;2) Point-to-point&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;    &lt;/span&gt;-p2p connectivity&lt;/div&gt;&lt;div&gt;    -no DIS&lt;/div&gt;&lt;div&gt;    -unicast&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;When dealing with NBMA, p2p mode with sub-if is preferred design&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-3863707537838849383?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/3863707537838849383/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=3863707537838849383' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/3863707537838849383'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/3863707537838849383'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/11/is-is-network-types.html' title='IS-IS Network Types'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-6848043887944947272</id><published>2008-11-25T10:15:00.004+03:00</published><updated>2008-11-25T17:28:34.916+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='isis'/><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><title type='text'>IS-IS packet types</title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;packet = Protocol Data Unit (PDU)&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;network-layer packet = Network PDU&lt;/div&gt;&lt;div&gt;Data-link frame = Data-link PDU&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;PDU types:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;1) Hello&lt;/div&gt;&lt;div&gt;2) Link-state packet (&lt;span class="Apple-style-span" style="font-style: italic;"&gt;LSP&lt;/span&gt;) - аналог LSA в OSPF. Network advertisement&lt;/div&gt;&lt;div&gt;3) Partial sequence number PDU (&lt;span class="Apple-style-span" style="font-style: italic;"&gt;PSNP&lt;/span&gt;) - выполняет роль &lt;span class="Apple-style-span" style="font-style: italic;"&gt;ACK&lt;/span&gt; или &lt;span class="Apple-style-span" style="font-style: italic;"&gt;request for missing network&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-style: italic;"&gt;4) &lt;/span&gt;Complete&lt;span class="Apple-style-span" style="font-style: italic;"&gt; &lt;span class="Apple-style-span" style="font-style: normal; "&gt;sequence number PDU (CSNP) - аналог DBD в OSPF, краткий summary DB. It is rather small, it sent once in 10 s in broadcast network; only once in p2p networks.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ieNEtWk3S4E/SSup54M8ekI/AAAAAAAAAJg/h6OFbevDFvk/s1600-h/is_is_packets.PNG"&gt;&lt;img src="http://1.bp.blogspot.com/_ieNEtWk3S4E/SSup54M8ekI/AAAAAAAAAJg/h6OFbevDFvk/s320/is_is_packets.PNG" border="0" alt="" id="BLOGGER_PHOTO_ID_5272494600571615810" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 320px; height: 239px; " /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div&gt;LSP header - тип пакета и служебная инфа&lt;/div&gt;&lt;div&gt;TLV - стандартный контейнер, может содержать различную инфу. Вся инфа об IP также передается в TLV. Таким образом можно сопоставить NSAP и соответствующих ему IP subnets.&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-6848043887944947272?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/6848043887944947272/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=6848043887944947272' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/6848043887944947272'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/6848043887944947272'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/11/is-is-packet-types.html' title='IS-IS packet types'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_ieNEtWk3S4E/SSup54M8ekI/AAAAAAAAAJg/h6OFbevDFvk/s72-c/is_is_packets.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-1017376823259072317</id><published>2008-11-24T10:29:00.003+03:00</published><updated>2008-11-25T10:15:02.051+03:00</updated><title type='text'>IS-IS addressing</title><content type='html'>OSI uses connectionless network protocol addresses (CNLP)&lt;br /&gt;&lt;br /&gt;When CLNP assigned to a router it becomes a Network Service Access Point address (NSAP)&lt;br /&gt;or Net address&lt;br /&gt;&lt;br /&gt;NSAP address can be up to 20 bytes&lt;br /&gt;&lt;br /&gt;Original OSI implementation defines 5 fields in NSAP&lt;br /&gt;&lt;br /&gt;Cisco implementation defines 3 fields:&lt;br /&gt;1) The &lt;span style="font-weight: bold;"&gt;Area address&lt;/span&gt;&lt;br /&gt;2)The &lt;span style="font-weight: bold;"&gt;system ID&lt;/span&gt;&lt;br /&gt;3)The NSAP selector (&lt;span style="font-weight: bold;"&gt;NSEL&lt;/span&gt;)&lt;br /&gt;&lt;br /&gt;NSEL - всегда 00, просто определяет, что это IS система.&lt;br /&gt;&lt;span style="font-style: italic;"&gt;System ID&lt;/span&gt; - всегда 6 байт. Идентификатор роутера. Должен быть уникален&lt;br /&gt;Остальное - &lt;span style="font-style: italic;"&gt;Area address&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;EX:&lt;/span&gt; &lt;span style="color: rgb(255, 0, 0);"&gt;49.0003&lt;/span&gt;.&lt;span style="color: rgb(51, 102, 255);"&gt;4444.4444.4444&lt;/span&gt;.00&lt;br /&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="color: rgb(255, 0, 0); "&gt;49.0003 - &lt;/span&gt;Area id&lt;br /&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="color: rgb(51, 102, 255); "&gt;4444.4444.4444 -&lt;/span&gt; System ID&lt;br /&gt;  &lt;br /&gt;Best practice: System ID = Router MAC&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-1017376823259072317?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/1017376823259072317/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=1017376823259072317' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/1017376823259072317'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/1017376823259072317'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/11/is-is-addressing.html' title='IS-IS addressing'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-5622127635975873848</id><published>2008-11-18T11:46:00.006+03:00</published><updated>2009-01-25T17:03:25.970+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='isis'/><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><title type='text'>IS-IS routing</title><content type='html'>&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;IS-IS routing domains&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ieNEtWk3S4E/SSKBxB5eYvI/AAAAAAAAAJY/ja3hiRR6oQI/s1600-h/is_is_routing_domains.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 238px;" src="http://3.bp.blogspot.com/_ieNEtWk3S4E/SSKBxB5eYvI/AAAAAAAAAJY/ja3hiRR6oQI/s320/is_is_routing_domains.PNG" alt="" id="BLOGGER_PHOTO_ID_5269917193299976946" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;routing&lt;br /&gt;level 0 - взаимодействие End-System - IS&lt;br /&gt;level 1 - взаимодействие IS-IS внутри area&lt;br /&gt;level 2 - внутри AS&lt;br /&gt;level 3 - с другой AS&lt;br /&gt;&lt;img src="file:///C:/DOCUME~1/PTARAT~1.INF/LOCALS~1/Temp/moz-screenshot.jpg" alt="" /&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;IS-IS routing process&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;&lt;span class="Apple-style-span" style="font-weight: normal; "&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ieNEtWk3S4E/SXw5QGtyD2I/AAAAAAAAAK0/OfHYx3WWbsI/s1600-h/is_is_routing_process.png"&gt;&lt;img src="http://1.bp.blogspot.com/_ieNEtWk3S4E/SXw5QGtyD2I/AAAAAAAAAK0/OfHYx3WWbsI/s320/is_is_routing_process.png" border="0" alt="" id="BLOGGER_PHOTO_ID_5295170210724188002" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 320px; height: 239px; " /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;The Decision Process&lt;/div&gt;&lt;div&gt;After the link-state databases have been synchronized, it is necessary to decide which path to take &lt;/div&gt;&lt;div&gt;to reach the destination. Because the routers and hosts may have multiple connections to each &lt;/div&gt;&lt;div&gt;other, there may be many paths from which to choose.&lt;/div&gt;&lt;div&gt;To make the best path decision, link-state protocols employ the algorithm deﬁned by Dijkstra. This &lt;/div&gt;&lt;div&gt;algorithm creates a tree that shows the shortest paths to all destinations. The tree is used in turn &lt;/div&gt;&lt;div&gt;to create the routing table.&lt;/div&gt;&lt;div&gt;If there is more than one path to a remote destination, the criteria by which the lowest cost paths &lt;/div&gt;&lt;div&gt;are selected and placed in the forwarding database are as follows:&lt;/div&gt;&lt;div&gt;1. If there is more than one path with the lowest value metric, Cisco equipment places some or &lt;/div&gt;&lt;div&gt;all paths into the table. Older versions of IOS support as many as six load-sharing paths, &lt;/div&gt;&lt;div&gt;newer versions support more.&lt;/div&gt;&lt;div&gt;2. Internal paths are chosen before external paths. &lt;/div&gt;&lt;div&gt;3. Level 1 paths within the area are more attractive than Level 2 paths.&lt;/div&gt;&lt;div&gt;4. The address with the most speciﬁc address in IP is the address with the longest IP subnet &lt;/div&gt;&lt;div&gt;mask.&lt;/div&gt;&lt;div&gt;5. If there is no path, the forwarding database sends the packet to the nearest Level 2 router, &lt;/div&gt;&lt;div&gt;which is the default router. &lt;/div&gt;&lt;div&gt;The metric deﬁnes the cost of the path. Integrated IS-IS has four metrics, only one of which is &lt;/div&gt;&lt;div&gt;required and supported. The metrics deﬁned in ISO 10589 are as follows:&lt;/div&gt;&lt;div&gt;■ Default—Every Integrated IS-IS router must support this metric. Cisco set the default for all &lt;/div&gt;&lt;div&gt;interfaces to 10.&lt;/div&gt;&lt;div&gt;■ Delay—Cisco does not support the transit delay metric.&lt;/div&gt;&lt;div&gt;■ Expense—Cisco does not support the expense metric.&lt;/div&gt;&lt;div&gt;■ Error—Cisco does not support the error metric.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;By default, six-bit metrics are conﬁgured on the outgoing interface. A 10-bit ﬁeld describes the &lt;/div&gt;&lt;div&gt;total path cost. These default metrics are referred to as narrow. &lt;/div&gt;&lt;div&gt;Because it considered these inadequate, Cisco increased the metric size to 24 bits. This larger &lt;/div&gt;&lt;div&gt;metric ﬁeld provides more granularity to distinguish between paths and is referred to as wide.&lt;/div&gt;&lt;div&gt;To determine shortest path, the lowest metric is chosen, internal paths are chosen over external &lt;/div&gt;&lt;div&gt;paths, and Level 1 routes have precedence over Level 2 routes.&lt;/div&gt;&lt;div&gt;The default metric is the only metric supported by Cisco, because each metric used in Integrated &lt;/div&gt;&lt;div&gt;IS-IS requires a different link-state database calculation for both the Level 1 and Level 2 routes.&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-5622127635975873848?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/5622127635975873848/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=5622127635975873848' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/5622127635975873848'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/5622127635975873848'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/11/routing-level-0-end-system-is-level-1.html' title='IS-IS routing'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_ieNEtWk3S4E/SSKBxB5eYvI/AAAAAAAAAJY/ja3hiRR6oQI/s72-c/is_is_routing_domains.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-7966947300357550204</id><published>2008-11-18T11:35:00.003+03:00</published><updated>2008-11-18T11:41:37.264+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='isis'/><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><title type='text'>IS-IS design</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ieNEtWk3S4E/SSJ_f-hPSJI/AAAAAAAAAJQ/B7lofoS3Owc/s1600-h/is_is_design.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 239px;" src="http://3.bp.blogspot.com/_ieNEtWk3S4E/SSJ_f-hPSJI/AAAAAAAAAJQ/B7lofoS3Owc/s320/is_is_design.PNG" alt="" id="BLOGGER_PHOTO_ID_5269914701311985810" border="0" /&gt;&lt;/a&gt;Нужно предусматривать резервные линки на случай падения одного из роутеров ядра.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-7966947300357550204?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/7966947300357550204/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=7966947300357550204' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/7966947300357550204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/7966947300357550204'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/11/is-is-design.html' title='IS-IS design'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_ieNEtWk3S4E/SSJ_f-hPSJI/AAAAAAAAAJQ/B7lofoS3Owc/s72-c/is_is_design.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-9205493580418293979</id><published>2008-11-18T10:41:00.007+03:00</published><updated>2009-01-25T14:57:33.414+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='isis'/><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><title type='text'>IS-IS basics</title><content type='html'>&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;Originally designed for OSI&lt;br /&gt;Tuned for TCP/IP but still requires an OSI &lt;span style="font-style: italic;"&gt;connectionless network services address&lt;/span&gt; (CLNS)&lt;br /&gt;&lt;br /&gt;-Link-state - more tunable than OSPF&lt;br /&gt;-Uses SPF  - more efficient than OSPF&lt;br /&gt;-Hello msg&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ieNEtWk3S4E/SSJ1KyR5l9I/AAAAAAAAAJI/4Nd6H9s8Wn8/s1600-h/is_is_basics%231.PNG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 240px;" src="http://1.bp.blogspot.com/_ieNEtWk3S4E/SSJ1KyR5l9I/AAAAAAAAAJI/4Nd6H9s8Wn8/s320/is_is_basics%231.PNG" alt="" id="BLOGGER_PHOTO_ID_5269903342132893650" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;L1 routers - internal routers, only knows about routes inside the area&lt;br /&gt;L2 routers - backbone routers, only knows about backbone routes&lt;br /&gt;L1/L2 routers - что-то вроде граничных роутеров. Поддерживают как базу internal area routes, так и backbone routes.&lt;br /&gt;&lt;br /&gt;L1 - аналог клиента - внутри area он знает маршруты, но если надо попасть в другую area он обращается за помощью к L1/L2 ( аналог default gw)&lt;br /&gt;&lt;br /&gt;Для IS-IS необязательно наличие area 0 - главное чтоб backbone был неразрывен.&lt;br /&gt;&lt;br /&gt;По умолчанию, все линки имеют cost = 10. Необходимо вручную настроить все линки cost ( 0 - 63 )&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Формирование relationship&lt;/span&gt;&lt;br /&gt;L1 &lt;-----&gt;L1&lt;br /&gt;L2 &lt;------&gt;L2&lt;br /&gt;L1  ////----///  L2  - не сформируются&lt;br /&gt;&lt;br /&gt;L1/L2  &lt;--------&gt; L1/L2  - relationship формируется независимо для L1-to-L1 и для L2-to-L2 и формируются независимые DB&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;IS-IS NSAP addressing&lt;/span&gt;&lt;/div&gt;&lt;div&gt;- ISIS uses CLNP ( Connectionless Network Protocol) - аналог IP в стеке TCP/IP&lt;/div&gt;&lt;div&gt;- когда CLNP адрес назначается роутеру, он называется NSAP address (Network Service Access Point)&lt;/div&gt;&lt;div&gt;- 1 адрес на ноду, не на интерфейс&lt;/div&gt;&lt;div&gt;- NSAP address up to 20 bytes length&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 0, 238); text-decoration: underline;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 0, 238); text-decoration: underline;"&gt;&lt;span class="Apple-style-span" style="color: rgb(0, 0, 0); "&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ieNEtWk3S4E/SXxReXedxRI/AAAAAAAAALE/WScMSh0sRIU/s1600-h/is_is_address.PNG"&gt;&lt;img src="http://1.bp.blogspot.com/_ieNEtWk3S4E/SXxReXedxRI/AAAAAAAAALE/WScMSh0sRIU/s320/is_is_address.PNG" border="0" alt="" id="BLOGGER_PHOTO_ID_5295196844020581650" style="display: block; margin-top: 0px; margin-right: auto; margin-bottom: 10px; margin-left: auto; text-align: center; cursor: pointer; width: 320px; height: 238px; " /&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="text-align: center;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="text-align: left;"&gt;Адрес в hex и его лучше читать справа налево:&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;1)&lt;/span&gt; &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;NSEL&lt;/span&gt; (1 байт справа - два символа в hex) - определяет тип системы. Для Inermediate System (IS) - роутера - всегда 00&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;2)&lt;/span&gt; &lt;span class="Apple-style-span" style="font-weight: bold;"&gt;System ID&lt;/span&gt; - 3 октета по 2 байта каждый. Всегда фиксировано 6 байт. Определяет ID роутера. Должен быть глобально уникальным.&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;span class="Apple-style-span" style="font-weight: bold;"&gt;3) Area address&lt;/span&gt; - Все остальное слева обозначает Area address. Должен быть одинаковым для роутеров в одной area&lt;/div&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-9205493580418293979?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/9205493580418293979/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=9205493580418293979' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/9205493580418293979'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/9205493580418293979'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/11/is-is-basics.html' title='IS-IS basics'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_ieNEtWk3S4E/SSJ1KyR5l9I/AAAAAAAAAJI/4Nd6H9s8Wn8/s72-c/is_is_basics%231.PNG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-8036377134656115716</id><published>2008-10-31T10:58:00.002+03:00</published><updated>2008-10-31T11:12:39.424+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><title type='text'>OSPF Authentication</title><content type='html'>&lt;ul&gt;&lt;li&gt;per-interface basis&lt;/li&gt;&lt;li&gt;every ospf packet keyed with password&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;Authentication types: &lt;/p&gt; &lt;ul&gt;&lt;li&gt;      null (no authentication)&lt;span style="font-family: verdana;"&gt;(type 0)&lt;/span&gt;&lt;br /&gt;&lt;/li&gt;&lt;li&gt;      plaintext  &lt;/li&gt;&lt;li&gt;      MD5  &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Authentication is enabled per interface. &lt;/p&gt;  &lt;h4&gt;Plaintext&lt;/h4&gt; &lt;pre&gt;&lt;code&gt;Router(config-if)# ip ospf authentication-key &lt;password&gt;&lt;br /&gt;Router(config-if)# ip ospf authentication&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt; &lt;h4&gt;MD5&lt;/h4&gt; &lt;pre&gt;&lt;code&gt;Router(config-if)# ip ospf message-digest-key &lt;key&gt; md5 &lt;password&gt;&lt;br /&gt;Router(config-if)# ip ospf authentication message-digest&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-8036377134656115716?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/8036377134656115716/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=8036377134656115716' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/8036377134656115716'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/8036377134656115716'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/10/ospf-authentication.html' title='OSPF Authentication'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-5721161344307873200</id><published>2008-10-28T11:19:00.010+03:00</published><updated>2008-10-28T12:38:08.309+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><title type='text'>OSPF Area types</title><content type='html'>&lt;h4&gt;Area Types&lt;/h4&gt; &lt;ul&gt;&lt;li&gt;      &lt;span style="font-weight: bold;"&gt;Standard&lt;/span&gt; &lt;span style="font-weight: bold;"&gt;area&lt;/span&gt;  &lt;/li&gt;&lt;li&gt;      &lt;span style="font-weight: bold;"&gt;Stub area&lt;/span&gt; - Will not accept external routes (type 5 LSAs); type 5 LSAs are replaced by a default route  &lt;/li&gt;&lt;li&gt; &lt;span style="font-weight: bold;"&gt;Totally stubby area&lt;/span&gt; - Will not accept LSAs of type 3, 4, or 5; routes are replaced by the ABR with a default route; &lt;span style="font-weight: bold;"&gt;Cisco proprietary&lt;/span&gt;. Полный аналог &lt;span style="font-style: italic;"&gt;static default route &lt;/span&gt;&lt;/li&gt;&lt;li&gt; &lt;span style="font-weight: bold;"&gt;Not-so-stubby area&lt;/span&gt; (NSSA) - Stub areas which contain one or more ASBRs; ASBRs in a NSSA generate type 7 LSAs which are then converted to type 5 by the ABR &lt;/li&gt;&lt;/ul&gt; &lt;p&gt;The greatest advantage of designating stub areas is decreased convergence time.&lt;/p&gt;&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Stub &amp;amp; Totally stub areas&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ieNEtWk3S4E/SQbLyyuL0-I/AAAAAAAAAIY/IK6brffe6ws/s1600-h/ospf_areas%231.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 240px;" src="http://3.bp.blogspot.com/_ieNEtWk3S4E/SQbLyyuL0-I/AAAAAAAAAIY/IK6brffe6ws/s320/ospf_areas%231.JPG" alt="" id="BLOGGER_PHOTO_ID_5262117288098386914" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-weight: bold;"&gt;Not-So-Stubby-Area&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_ieNEtWk3S4E/SQbad3OieXI/AAAAAAAAAIg/5V0TFM2cTEk/s1600-h/ospf_areas%232.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 238px;" src="http://2.bp.blogspot.com/_ieNEtWk3S4E/SQbad3OieXI/AAAAAAAAAIg/5V0TFM2cTEk/s320/ospf_areas%232.JPG" alt="" id="BLOGGER_PHOTO_ID_5262133421204994418" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;h4&gt;&lt;code&gt;area stub&lt;/code&gt;&lt;/h4&gt; &lt;p&gt;Areas are designated as stubs when the chosen exit ABR is unimportant (or there is only one). &lt;/p&gt; &lt;pre&gt;&lt;code&gt;Router(config-router)# area [id]  stub&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;All routers within a stub area must be configured as such. A stub router will not form an adjacency with a non-stub router in the same area. &lt;/p&gt;  &lt;h4&gt;&lt;code&gt;area stub no-summary&lt;/code&gt;&lt;/h4&gt; &lt;p&gt;no-summary further limits a stub area by creating a totally subby area. Totally stubby areas do not receive type 3 or 5 LSAs from other areas. &lt;/p&gt; &lt;pre&gt;&lt;code&gt;Router(config-router)# area [id]  stub no-summary&lt;br /&gt;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Only ABRs need to be configured with no-summary appended to the stub command. Остальные роутеры в area могут быть просто с флагом stub.&lt;br /&gt;&lt;/p&gt; &lt;p&gt;To direct packets outside the stub area, routers rely on a default route advertised by the ABR(s). &lt;/p&gt; &lt;p&gt;The concept of totally stubby areas is Cisco proprietary. &lt;/p&gt;  &lt;h4&gt;&lt;code&gt;area default-cost&lt;/code&gt;&lt;/h4&gt;Not-So-Stubby area configuration:&lt;br /&gt;&lt;code&gt;Router(config-router)# area [id] nssa &lt;/code&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;Used to define the cost of the default route injected by an ABR into a stub area. The default is (cost to the ABR + 1). &lt;/p&gt; &lt;p&gt;This can be used to prefer one stub exit over others. &lt;/p&gt; &lt;pre&gt;&lt;code&gt;Router(config-router)# area  default-cost &lt;cost&gt;&lt;br /&gt;&lt;/cost&gt;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Configuration is done only on the ABR. &lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-5721161344307873200?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/5721161344307873200/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=5721161344307873200' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/5721161344307873200'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/5721161344307873200'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/10/ospf-area-types.html' title='OSPF Area types'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_ieNEtWk3S4E/SQbLyyuL0-I/AAAAAAAAAIY/IK6brffe6ws/s72-c/ospf_areas%231.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-4009096561533611260</id><published>2008-10-28T10:39:00.016+03:00</published><updated>2008-10-28T12:13:35.302+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><title type='text'>OSPF Virtual links</title><content type='html'>Virtual links - позволяют обойти правило дизайна OSPF area, которое гласит что все area должны быть напрямую соединены с area 0&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_ieNEtWk3S4E/SQbDI78k9aI/AAAAAAAAAIQ/-Yx5wybs7_g/s1600-h/ospf_virtlinks%231.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 238px;" src="http://4.bp.blogspot.com/_ieNEtWk3S4E/SQbDI78k9aI/AAAAAAAAAIQ/-Yx5wybs7_g/s320/ospf_virtlinks%231.JPG" alt="" id="BLOGGER_PHOTO_ID_5262107772927145378" border="0" /&gt;&lt;/a&gt;Такой дизайн - не самая лучшая идея. Рекомендуется применять virtual links только в крайнем случае, как временное решение.&lt;br /&gt;Virtual links - фактически туннелирование в area 0. Может быть реализовано  с помощью туннельных интерфейсов.&lt;br /&gt;Virtual links cannot use a stub area for transit.&lt;br /&gt;&lt;br /&gt;&lt;pre&gt;&lt;code&gt;Router(config-router)#area [id] virtual-link [router id] &lt;/code&gt;&lt;/pre&gt;&lt;br /&gt;В нашем случае :&lt;br /&gt;&lt;code&gt;R3(config-router)#area 1 virtual-link 2.2.2.2&lt;/code&gt;&lt;br /&gt;Virtual link должен быть сконфигурен с обоих сторон&lt;br /&gt;&lt;code&gt;R2(config-router)#area 1 virtual-link 3.3.3.3&lt;/code&gt;&lt;br /&gt;При этом не важно, сколько роутеров между двумя конечными ABR.&lt;br /&gt;&lt;span style="font-style: italic;"&gt;sh ip ospf neighbors&lt;/span&gt; при этом выглядят также как и без использования VL.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;sh ip ospf virtual-links&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-4009096561533611260?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/4009096561533611260/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=4009096561533611260' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/4009096561533611260'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/4009096561533611260'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/10/ospf-virtual-links.html' title='OSPF Virtual links'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/_ieNEtWk3S4E/SQbDI78k9aI/AAAAAAAAAIQ/-Yx5wybs7_g/s72-c/ospf_virtlinks%231.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-5479563225159619173</id><published>2008-10-27T12:47:00.003+03:00</published><updated>2008-10-27T12:54:39.476+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><title type='text'>OSPF LSA types</title><content type='html'>&lt;h4&gt;Link-State Advertisements&lt;/h4&gt; &lt;ul&gt;&lt;li&gt;      &lt;span style="font-style: italic;"&gt;Router link&lt;/span&gt; (&lt;span style="font-weight: bold;"&gt;type 1&lt;/span&gt;) - Lists a router's neighbors and its cost to each; flooded throughout the area. Используется в пределах area  &lt;/li&gt;&lt;li&gt; &lt;span style="font-style: italic;"&gt;Network link&lt;/span&gt; (&lt;span style="font-weight: bold;"&gt;type 2&lt;/span&gt;) - Advertisement by the DR containing all routers on the segment it is adjacent to; flooded throughout the area &lt;/li&gt;&lt;li&gt; &lt;span style="font-style: italic;"&gt;Network summary link&lt;/span&gt; (&lt;span style="font-weight: bold;"&gt;type 3&lt;/span&gt;) - ABRs generate this type of LSA to send between areas; it lists all prefixes available in an are.Используется для анонсов из одной area в другую.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;      &lt;span style="font-style: italic;"&gt;AS external ASBR summary link&lt;/span&gt; (&lt;span style="font-weight: bold;"&gt;type 4&lt;/span&gt;) - Router link LSA for ASBRs. Анонс IP ASBR.   &lt;/li&gt;&lt;li&gt;      &lt;span style="font-style: italic;"&gt;External link&lt;/span&gt; (&lt;span style="font-weight: bold;"&gt;type 5&lt;/span&gt;) - Originated by an ASBR, contains a route external to OSPF  &lt;/li&gt;&lt;li&gt; &lt;span style="font-style: italic;"&gt;NSSA&lt;/span&gt; &lt;span style="font-style: italic;"&gt;external&lt;/span&gt; (&lt;span style="font-weight: bold;"&gt;type 7&lt;/span&gt;) - Equivalent to a type 5 LSA, but generated by an ASBR in a not-so-stubby area (NSSA); converted to a type 5 by the ABR &lt;/li&gt;&lt;/ul&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ieNEtWk3S4E/SQWPbaEGbLI/AAAAAAAAAII/5-FFV5vn-fI/s1600-h/ospf_lsa%231.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 239px;" src="http://3.bp.blogspot.com/_ieNEtWk3S4E/SQWPbaEGbLI/AAAAAAAAAII/5-FFV5vn-fI/s320/ospf_lsa%231.JPG" alt="" id="BLOGGER_PHOTO_ID_5261769440668052658" border="0" /&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-5479563225159619173?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/5479563225159619173/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=5479563225159619173' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/5479563225159619173'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/5479563225159619173'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/10/ospf-lsa-types.html' title='OSPF LSA types'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_ieNEtWk3S4E/SQWPbaEGbLI/AAAAAAAAAII/5-FFV5vn-fI/s72-c/ospf_lsa%231.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-2757620820600979999</id><published>2008-10-27T11:19:00.012+03:00</published><updated>2008-10-27T12:12:53.739+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><title type='text'>OSPF summarization</title><content type='html'>&lt;h4&gt;&lt;span style="font-size:85%;"&gt;Summarization&lt;/span&gt;&lt;/h4&gt; &lt;ul&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;      Inter-area summarization - Performed at the ABR; creates type 3 LSAs. Type 4 LSAs advertise ASBRs.  &lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-size:85%;"&gt;      External summarization - Performed at the ASBR; creates type 5 LSAs.  &lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ieNEtWk3S4E/SQV5zujnwyI/AAAAAAAAAH4/VRjsGQJShXM/s1600-h/ospf_summarization%231.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 298px;" src="http://1.bp.blogspot.com/_ieNEtWk3S4E/SQV5zujnwyI/AAAAAAAAAH4/VRjsGQJShXM/s400/ospf_summarization%231.JPG" alt="" id="BLOGGER_PHOTO_ID_5261745669230019362" border="0" /&gt;&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;"&gt;1)ABR summarization&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;Used on an ABR to summarize multiple networks into a single type 3 LSA. &lt;/p&gt; &lt;pre&gt;&lt;code&gt;Router(config-router)# area  range &lt;network&gt; &lt;mask&gt;&lt;br /&gt;&lt;br /&gt;В нашем случае (см. картинку)&lt;br /&gt;(config-router)# area 1 range 192.168.0.0 255.255.0.0 - указываем area &lt;span style="font-weight: bold;"&gt;ИЗ&lt;/span&gt; которой будет анонсироваться  summary route !&lt;br /&gt;&lt;br /&gt;&lt;/mask&gt;&lt;/network&gt;&lt;/code&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_ieNEtWk3S4E/SQV7xTBV3-I/AAAAAAAAAIA/9Hqkb-QoEVo/s1600-h/ospf_summarization%232.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 320px; height: 132px;" src="http://2.bp.blogspot.com/_ieNEtWk3S4E/SQV7xTBV3-I/AAAAAAAAAIA/9Hqkb-QoEVo/s320/ospf_summarization%232.JPG" alt="" id="BLOGGER_PHOTO_ID_5261747826502000610" border="0" /&gt;&lt;/a&gt;Summary address указывает на Null0 интерфейс - loop prevention mechanism.&lt;br /&gt;В случае, если трафик придет на summary address, но не предназначен ни одной из сетей, входящих в summary,&lt;br /&gt;он дропается на Null0 интерфейсе.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;network&gt;&lt;mask&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold;font-family:verdana;" &gt;2)ASBR summarization&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-family:verdana;"&gt;При суммировании маршрутов приходящих из другой AS используется другая команда.&lt;br /&gt;Так как в другой AS может не использоваться area (например redistribution из RIP),то используется просто summary-address&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/mask&gt;&lt;/network&gt;&lt;/code&gt;&lt;br /&gt;Router(config-router)# summary-address &lt;span style="font-style: italic;"&gt;address&lt;/span&gt; &lt;span style="font-style: italic;"&gt;mask&lt;/span&gt; [no-advertise] [tag]&lt;br /&gt;&lt;br /&gt;В нашем случае&lt;br /&gt;&lt;code&gt;&lt;br /&gt;Router(config-router)# summary-address&lt;/code&gt; 172.16.0.0 255.255.0.0&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;img src="file:///C:/DOCUME%7E1/PTARAT%7E1.INF/LOCALS%7E1/Temp/moz-screenshot.jpg" alt="" /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-2757620820600979999?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/2757620820600979999/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=2757620820600979999' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2757620820600979999'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2757620820600979999'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/10/ospf-summarization.html' title='OSPF summarization'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_ieNEtWk3S4E/SQV5zujnwyI/AAAAAAAAAH4/VRjsGQJShXM/s72-c/ospf_summarization%231.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-3288779005587355873</id><published>2008-10-27T10:27:00.003+03:00</published><updated>2008-10-27T11:19:37.760+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><title type='text'>OSPF Areas</title><content type='html'>&lt;span style="font-size:130%;"&gt;&lt;span style="font-weight: bold;"&gt;Router Types&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ieNEtWk3S4E/SQVz1cvSCwI/AAAAAAAAAHw/jdyhzXclLVk/s1600-h/ospf_routers%231.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 298px;" src="http://3.bp.blogspot.com/_ieNEtWk3S4E/SQVz1cvSCwI/AAAAAAAAAHw/jdyhzXclLVk/s400/ospf_routers%231.JPG" alt="" id="BLOGGER_PHOTO_ID_5261739101737061122" border="0" /&gt;&lt;/a&gt;&lt;span style="font-weight: bold;"&gt;Internal router&lt;/span&gt; - all ints in the same area&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Backbone&lt;/span&gt; - at least one int in area 0&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ABR&lt;/span&gt; - at least 2 int in different area&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ABRS&lt;/span&gt; - AS boundary&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-3288779005587355873?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/3288779005587355873/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=3288779005587355873' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/3288779005587355873'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/3288779005587355873'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/10/ospf-areas.html' title='OSPF Areas'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_ieNEtWk3S4E/SQVz1cvSCwI/AAAAAAAAAHw/jdyhzXclLVk/s72-c/ospf_routers%231.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-3331486196639628666</id><published>2008-10-23T15:23:00.006+04:00</published><updated>2008-10-24T10:57:04.784+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><title type='text'>OSPF network types</title><content type='html'>&lt;span style="font-weight: bold;"&gt;I. &lt;span style="font-size:130%;"&gt;Broadcast networks&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;-single operation mode&lt;br /&gt;-10 s hello, 40 s dead timers&lt;br /&gt;- DR/BDR election&lt;br /&gt;- dual multicast&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;II. &lt;span style="font-size:130%;"&gt;Point-to-point network&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;-single  operation mode&lt;br /&gt;-10 s hello, 40 s dead&lt;br /&gt;-no DR/BDR&lt;br /&gt;-single multicast&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;III. &lt;span style="font-size:130%;"&gt;NBMA network&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;- &lt;span style="font-weight: bold;"&gt;5&lt;/span&gt; operation modes:  &lt;span style="font-weight: bold;"&gt;2&lt;/span&gt; RFC, &lt;span style="font-weight: bold;"&gt;3&lt;/span&gt; Cisco&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;3.1 NBMA modes&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;1) Non-Broadcast mode (RFC)&lt;/span&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ieNEtWk3S4E/SQBu5shWrUI/AAAAAAAAAHA/_2g7-qEGQl0/s1600-h/ospf+networks%231.bmp"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 298px;" src="http://3.bp.blogspot.com/_ieNEtWk3S4E/SQBu5shWrUI/AAAAAAAAAHA/_2g7-qEGQl0/s400/ospf+networks%231.bmp" alt="" id="BLOGGER_PHOTO_ID_5260326302251396418" border="0" /&gt;&lt;/a&gt;Acts like LAN env -- так как все роутеры в одной подсети, процесс предполагает, что все они имеют connectivity, но на самом деле этом может быть не так. Необходимао настраивать, например настраивать frame-relay maps, чтобы R2 видел R3 через R4, хотя в таблице маршрутизации все может быть ОК.&lt;br /&gt;&lt;br /&gt;Могут быть задержки в установлении neighbour relationship&lt;br /&gt;Neighbors должны быть статически сконфигурены на роутере, который выступает в качестве DR/BDR. На остальных - необязательно.&lt;br /&gt;&lt;br /&gt;Роутер, который будет выступать в качестве DR/BDR должен иметь высший приоритет.&lt;br /&gt;Или остальные - низший.&lt;br /&gt;&lt;br /&gt;&lt;p&gt;DR priorities should be specified to ensure only candidates positioned well in the topology are elected DR and BDR. &lt;/p&gt; &lt;pre&gt;&lt;code&gt;Router(config-if)# neighbor &lt;ip&gt; [priority &lt;priority&gt;] [poll-interval &lt;seconds&gt;]&lt;br /&gt;[cost &lt;cost&gt;]&lt;br /&gt;&lt;/cost&gt;&lt;/seconds&gt;&lt;/priority&gt;&lt;/ip&gt;&lt;/code&gt;&lt;/pre&gt;&lt;ul&gt;&lt;li&gt;      &lt;code&gt;priority&lt;/code&gt; - This can be used to specify a higher priority than what has been configured on the neighbor (but not lower)  &lt;/li&gt;&lt;li&gt;      &lt;code&gt;poll interval&lt;/code&gt; - The rate at which hellos are sent to inactive neighbors (default 120 seconds)  &lt;/li&gt;&lt;li&gt;      &lt;code&gt;cost&lt;/code&gt; - Cost to reach the neighbor  &lt;/li&gt;&lt;/ul&gt;Лучше будет настроить приоритет на обоих сторонах&lt;br /&gt;На соответсвующем интерфейсе соседа (DROTHER)&lt;br /&gt;(config-if)# ip ospf priority 0&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;2) Point-to-multipoint&lt;/span&gt; (RFC)&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_ieNEtWk3S4E/SQFnn-VfwyI/AAAAAAAAAHI/3nQGHgyoYrk/s1600-h/ospf+networks%232.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 298px;" src="http://2.bp.blogspot.com/_ieNEtWk3S4E/SQFnn-VfwyI/AAAAAAAAAHI/3nQGHgyoYrk/s400/ospf+networks%232.JPG" alt="" id="BLOGGER_PHOTO_ID_5260599776191169314" border="0" /&gt;&lt;/a&gt;treats all links almost as p2p links.&lt;br /&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;!!&lt;/span&gt; Cloud &amp;amp; routers must allow broadcast accross links &lt;span style="color: rgb(255, 0, 0);"&gt;!!&lt;/span&gt;&lt;br /&gt;Не нужно дополнительно прописывать никакие frame-relay maps.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;3) Point-to-multipoint non-broadcast&lt;/span&gt; (Cisco)&lt;br /&gt;&lt;br /&gt;То же, что и &lt;span style="font-style: italic;"&gt;p2mp &lt;/span&gt;но позволяет реализовать без broadcast. Но при этом neighbors приходится конфигурить статично вручную.&lt;br /&gt;&lt;br /&gt;4) Broadcast (Cisco)&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_ieNEtWk3S4E/SQFteXd3qCI/AAAAAAAAAHg/RCpTGENXP7E/s1600-h/ospf+networks%233.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 298px;" src="http://4.bp.blogspot.com/_ieNEtWk3S4E/SQFteXd3qCI/AAAAAAAAAHg/RCpTGENXP7E/s400/ospf+networks%233.JPG" alt="" id="BLOGGER_PHOTO_ID_5260606208208250914" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;Full emulation of broadcast env in NBMA network. Full mesh required. Single subnet required&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;5) Point-to-point&lt;/span&gt; (Cisco)&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://4.bp.blogspot.com/_ieNEtWk3S4E/SQFu5UBD24I/AAAAAAAAAHo/abMjAWa2UmY/s1600-h/ospf+networks%234.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer; width: 400px; height: 298px;" src="http://4.bp.blogspot.com/_ieNEtWk3S4E/SQFu5UBD24I/AAAAAAAAAHo/abMjAWa2UmY/s400/ospf+networks%234.JPG" alt="" id="BLOGGER_PHOTO_ID_5260607770650205058" border="0" /&gt;&lt;/a&gt;Full emulation of p2p env. Each DLCI acts as p2p link.&lt;br /&gt;1) needs subinf to be configured&lt;br /&gt;2) needs different subnets&lt;br /&gt;&lt;br /&gt;Maybe the best mode for NBMA. Меньше всего проблемы, наиболее детерминированное поведение.&lt;br /&gt;&lt;br /&gt;&lt;table width="100%"&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;strong&gt;NBMA&lt;/strong&gt;&lt;/td&gt;    &lt;td&gt;&lt;strong&gt;Point-to-multipoint&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;broadcast&lt;/strong&gt;&lt;/td&gt;    &lt;td&gt;&lt;strong&gt;Point-to-multipoint&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;nonbroadcast&lt;/strong&gt;&lt;/td&gt;    &lt;td&gt;&lt;strong&gt;Broadcast&lt;/strong&gt;&lt;/td&gt;    &lt;td&gt;&lt;strong&gt;Point-to-point&lt;/strong&gt;&lt;/td&gt;    &lt;/tr&gt;    &lt;tr&gt;    &lt;td&gt;&lt;strong&gt;DR/BDR&lt;/strong&gt;&lt;/td&gt;    &lt;td&gt;Yes&lt;/td&gt;    &lt;td&gt;No&lt;/td&gt;    &lt;td&gt;No&lt;/td&gt;    &lt;td&gt;Yes&lt;/td&gt;    &lt;td&gt;No&lt;/td&gt;    &lt;/tr&gt;    &lt;tr&gt;    &lt;td&gt;&lt;strong&gt;Identify neighbor?&lt;/strong&gt;&lt;/td&gt;    &lt;td&gt;Yes&lt;/td&gt;    &lt;td&gt;No&lt;/td&gt;    &lt;td&gt;Yes&lt;/td&gt;    &lt;td&gt;No&lt;/td&gt;    &lt;td&gt;No&lt;/td&gt;    &lt;/tr&gt;    &lt;tr&gt;    &lt;td&gt;&lt;strong&gt;Hello/dead timers&lt;/strong&gt;&lt;/td&gt;    &lt;td&gt;30/120&lt;/td&gt;    &lt;td&gt;30/120&lt;/td&gt;    &lt;td&gt;30/120&lt;/td&gt;    &lt;td&gt;10/40&lt;/td&gt;    &lt;td&gt;10/40&lt;/td&gt;    &lt;/tr&gt;    &lt;tr&gt;    &lt;td&gt;&lt;strong&gt;Standard&lt;/strong&gt;&lt;/td&gt;    &lt;td&gt;RFC&lt;/td&gt;    &lt;td&gt;RFC&lt;/td&gt;    &lt;td&gt;Cisco&lt;/td&gt;    &lt;td&gt;Cisco&lt;/td&gt;    &lt;td&gt;Cisco&lt;/td&gt;    &lt;/tr&gt;    &lt;tr&gt;    &lt;td&gt;&lt;strong&gt;Network supported&lt;/strong&gt;&lt;/td&gt;    &lt;td&gt;Full mesh&lt;/td&gt;    &lt;td&gt;Any&lt;/td&gt;    &lt;td&gt;Any&lt;/td&gt;    &lt;td&gt;Full mesh&lt;/td&gt;    &lt;td&gt;Point-to-point&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-3331486196639628666?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/3331486196639628666/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=3331486196639628666' title='Комментарии: 1'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/3331486196639628666'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/3331486196639628666'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/10/ospf-network-types.html' title='OSPF network types'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_ieNEtWk3S4E/SQBu5shWrUI/AAAAAAAAAHA/_2g7-qEGQl0/s72-c/ospf+networks%231.bmp' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-6808455078267850137</id><published>2008-10-22T11:06:00.004+04:00</published><updated>2008-10-23T15:18:16.381+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><title type='text'>Implementing &amp; verification OSPF</title><content type='html'>&lt;h3&gt;Configuring OSPF in a Single Area&lt;/h3&gt; &lt;p&gt;Necessary information: &lt;/p&gt; &lt;ul&gt;&lt;li&gt;      OSPF process ID (locally significant)  &lt;/li&gt;&lt;li&gt;      Participating interfaces  &lt;/li&gt;&lt;li&gt;      Area ID  &lt;/li&gt;&lt;li&gt;      Router ID  &lt;/li&gt;&lt;/ul&gt;  &lt;h4&gt;Enable OSPF&lt;/h4&gt; &lt;pre&gt;&lt;code&gt;Router(config)# router ospf &lt;process&gt;&lt;br /&gt;&lt;/process&gt;&lt;/code&gt;&lt;/pre&gt; &lt;h4&gt;Configure Included Networks&lt;/h4&gt; &lt;pre&gt;&lt;code&gt;Router(config-router)# network &lt;network&gt; &lt;wildcard&gt; area&lt;br /&gt;&lt;/wildcard&gt;&lt;/network&gt;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;A single interface can be specified by supplying its IP address and a null wildcard mask:&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;code&gt;network 192.168.0.1 0.0.0.0 area 0&lt;/code&gt; &lt;/p&gt;  &lt;h4&gt;Router ID&lt;/h4&gt; &lt;p&gt;If no router ID has been administratively declared, a router will choose the highest loopback IP address. If no loopback addresses are present, the highest IP address of the first active interface will be used. &lt;/p&gt; &lt;p&gt;A router ID can be manually specified: &lt;/p&gt; &lt;pre&gt;&lt;code&gt;Router(config-router)# router-id &lt;ip&gt;&lt;br /&gt;&lt;/ip&gt;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Best practice dictates the creation of a loopback address to be used as the router ID for stability and continuity: &lt;/p&gt; &lt;pre&gt;&lt;code&gt;Router(config)# interface loopback 0&lt;br /&gt;Router(config-if)# ip address &lt;ip&gt; &lt;subnet&gt;&lt;br /&gt;&lt;/subnet&gt;&lt;/ip&gt;&lt;/code&gt;&lt;/pre&gt; &lt;h4&gt;Default Cost&lt;/h4&gt; &lt;p&gt;Link cost is a 16-bit value (0-65535); default cost is calculated as 100Mbps/interface bandwidth. (Interfaces 100Mbps and faster are assigned a cost of 1.) &lt;/p&gt; &lt;p&gt;OSPF cost can be manually specified per interface: &lt;/p&gt; &lt;pre&gt;&lt;code&gt;Router(config-if)# ip ospf cost &lt;cost&gt;&lt;br /&gt;&lt;/cost&gt;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;An alternative to defining static costs per interface is to change the numerator bandwidth (default 100Mbps): &lt;/p&gt; &lt;pre&gt;&lt;code&gt;Router(config-router)# ospf auto-cost reference-bandwidth &lt;reference&gt;&lt;br /&gt;&lt;/reference&gt;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reference speed is a 32-bit value (1 - 4294967). If reference speed is modified, the same modification should be performed on all routers within the area. &lt;/p&gt;  &lt;h4&gt;Router Priority&lt;/h4&gt; &lt;p&gt;Default DR election priority is 1, and a router with a priority of 0 will not become a DR. Priority range is 0 - 255. &lt;/p&gt; &lt;pre&gt;&lt;code&gt;Router(config-if)# ip ospf priority &lt;priority&gt;&lt;br /&gt;&lt;/priority&gt;&lt;/code&gt;&lt;/pre&gt; &lt;h3&gt;Verifying OSPF Configuration&lt;/h3&gt; &lt;ul&gt;&lt;li&gt;&lt;p&gt;&lt;code&gt;show ip ospf&lt;/code&gt; - OSPF process details &lt;/p&gt;   &lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;code&gt;show ip ospf&lt;/code&gt; database - Contents of the topology database &lt;/p&gt;   &lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;code&gt;show ip ospf&lt;/code&gt; interface - Interfaces participating in OSPF &lt;/p&gt;   &lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;code&gt;show ip ospf&lt;/code&gt; neighbor - Neighbor information &lt;/p&gt;   &lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;code&gt;show ip protocols&lt;/code&gt; - Displays all active routing protocols &lt;/p&gt;   &lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;code&gt;show ip route&lt;/code&gt; &lt;/p&gt;   &lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;code&gt;debug ip ospf events&lt;/code&gt; &lt;/p&gt;   &lt;/li&gt;&lt;li&gt;&lt;p&gt;&lt;code&gt;debug ip packet&lt;/code&gt;&lt;/p&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="color: rgb(255, 0, 0);"&gt;!!&lt;/span&gt; &lt;span style="font-style: italic;"&gt;В дебаге роутер определяется router-id&lt;/span&gt; &lt;span style="color: rgb(255, 0, 0);"&gt;!! &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ieNEtWk3S4E/SP7TWQCbs4I/AAAAAAAAAG4/Rrsrs-huNcU/s1600-h/ospf_verif%231.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_ieNEtWk3S4E/SP7TWQCbs4I/AAAAAAAAAG4/Rrsrs-huNcU/s400/ospf_verif%231.JPG" alt="" id="BLOGGER_PHOTO_ID_5259873794031072130" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;# clear ip ospf process&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-6808455078267850137?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/6808455078267850137/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=6808455078267850137' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/6808455078267850137'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/6808455078267850137'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/10/implementing-troubleshooting-ospf.html' title='Implementing &amp; verification OSPF'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_ieNEtWk3S4E/SP7TWQCbs4I/AAAAAAAAAG4/Rrsrs-huNcU/s72-c/ospf_verif%231.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-5243527897052729332</id><published>2008-10-20T18:32:00.019+04:00</published><updated>2008-10-28T12:12:06.024+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><category scheme='http://www.blogger.com/atom/ns#' term='ospf'/><title type='text'>OSPF basics</title><content type='html'>All OSPF routers in an area share the same Link State Database (LSDB).&lt;br /&gt;&lt;br /&gt;All areas must be connected to backbone area 0 ( исключение - использование virtual link - только если нет другого выхода). OSPF requires hierachical design&lt;br /&gt;&lt;br /&gt;hello broadcast/p2p - 10 s&lt;br /&gt;NBMA               -  30 s&lt;br /&gt;&lt;br /&gt;dead timer - 4 x hello&lt;br /&gt;&lt;p&gt;OSPF tables: &lt;/p&gt; &lt;ul&gt;&lt;li&gt;      Neighbor table  &lt;/li&gt;&lt;li&gt;      Topology database  &lt;/li&gt;&lt;li&gt;      Routing table  &lt;/li&gt;&lt;/ul&gt;multicast &lt;span style="font-style: italic;font-family:arial;font-size:100%;"  &gt;&lt;code&gt;224.0.0.5&lt;/code&gt;&lt;/span&gt; -DR_other, common&lt;br /&gt;            &lt;span style="font-size:100%;"&gt;&lt;span style="font-style: italic;"&gt;224.0.0.6&lt;/span&gt;&lt;/span&gt; - DR, BDR in broadcast env&lt;br /&gt;&lt;br /&gt;cost = 100 / bandwidth_in_mbs&lt;br /&gt;&lt;br /&gt;DR &amp;amp; BDR has to be elected in every shared segment&lt;br /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ieNEtWk3S4E/SP3hPFut-0I/AAAAAAAAAGw/YwK3XDhsv48/s1600-h/ospf_basics%232.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_ieNEtWk3S4E/SP3hPFut-0I/AAAAAAAAAGw/YwK3XDhsv48/s400/ospf_basics%232.JPG" alt="" id="BLOGGER_PHOTO_ID_5259607589191023426" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;DR, BDR election&lt;br /&gt;1) priority&lt;br /&gt;2) highest router-id&lt;br /&gt;&lt;p&gt;HELLO packet&lt;br /&gt;&lt;/p&gt; &lt;ul&gt;&lt;li&gt;      Router ID - 32-bit unique number (IP address)  &lt;/li&gt;&lt;li&gt;      Hello/dead intervals - Timers  &lt;/li&gt;&lt;li&gt;      Neighbor list - List of neighboring router IDs  &lt;/li&gt;&lt;li&gt;      Area ID  &lt;/li&gt;&lt;li&gt;      Priority - Used in electing the DR and BDR  &lt;/li&gt;&lt;li&gt;      DR and BDR  &lt;/li&gt;&lt;li&gt;      Authentication (if enabled)  &lt;/li&gt;&lt;li&gt;      Stub Area Flag - On if this is a stub area  &lt;/li&gt;&lt;/ul&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;font-size:130%;" &gt;Neighbor relationship&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;1. Determine Router ID&lt;/span&gt;&lt;br /&gt;&lt;img src="file:///C:/DOCUME%7E1/PTARAT%7E1.INF/LOCALS%7E1/Temp/moz-screenshot.jpg" alt="" /&gt;&lt;br /&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ieNEtWk3S4E/SPyZc2eXVJI/AAAAAAAAAGo/UhaNxprziPs/s1600-h/ospf+neighbors%231.JPG"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_ieNEtWk3S4E/SPyZc2eXVJI/AAAAAAAAAGo/UhaNxprziPs/s400/ospf+neighbors%231.JPG" alt="" id="BLOGGER_PHOTO_ID_5259247185800156306" border="0" /&gt;&lt;/a&gt;1) router id hard-coded (best practice)&lt;br /&gt;2) highest loobback int (lo int can be pingable)&lt;br /&gt;3) highest physical int  (only active int participate)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;! router ID changes only after reboot or ospf process reload !&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;&lt;span style="font-weight: bold;"&gt;2&lt;span style="font-style: italic;"&gt;. &lt;/span&gt;Add interfaces to LSBD&lt;/span&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt; (&lt;/span&gt;dictated by &lt;span style="font-style: italic;"&gt;network&lt;/span&gt; command)&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;3. Send HELLO on choosen interfaces&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;(**DOWN state**)&lt;span style="font-weight: bold;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;HELLO&lt;span style="font-style: italic;"&gt; &lt;/span&gt;contains:&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;1) Router ID&lt;br /&gt;2) Hello &amp;amp; dead timers *&lt;br /&gt;3) Network mask *&lt;br /&gt;4) Area id *&lt;br /&gt;5) Neighbors&lt;br /&gt;6) Router priority&lt;br /&gt;7) DR/ BDR ip address&lt;br /&gt;8) Authentication password *&lt;br /&gt;9) Stub flag *&lt;br /&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;* - must match&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="font-weight: bold;"&gt;4. Receive HELLO&lt;/span&gt;&lt;/span&gt;&lt;span style="font-style: italic;"&gt; (**INIT** state)&lt;br /&gt;&lt;/span&gt;&lt;span&gt;Check * to match.&lt;/span&gt;&lt;span style="font-style: italic;"&gt; &lt;/span&gt;&lt;span&gt;If conditions do not match you'll see cycling from **DOWN** to **INIT**&lt;/span&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;5. Send HELLO reply (&lt;/span&gt;&lt;span style="font-style: italic;"&gt;** 2-way state**&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;)&lt;br /&gt;&lt;/span&gt;&lt;span&gt;Router&lt;/span&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;&lt;span&gt;checks if it listed as neighbor in the received hello:&lt;br /&gt;If &lt;span style="font-style: italic;"&gt;yes&lt;/span&gt;  ----&gt; just reset dead timers, neighbor relationship have been already established earlier&lt;br /&gt;If &lt;span style="font-style: italic;"&gt;no&lt;/span&gt;   -----&gt; adds as new neighbor&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;6. Master - Slave determine&lt;/span&gt; ( &lt;span style="font-style: italic;"&gt;**Exstart state **&lt;/span&gt; )&lt;br /&gt;&lt;br /&gt;determined by priority; router-id breaks the tie&lt;br /&gt;Master send DBD first.&lt;br /&gt;&lt;span style="font-style: italic; font-weight: bold;"&gt;DBD&lt;/span&gt; = Database Desciption ("cliff notes" - заметки на полях - краткое описание topology DB)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;7. DBD are acknowleged and received&lt;/span&gt; (&lt;span style="font-style: italic;"&gt;**Loading state**&lt;/span&gt;)&lt;br /&gt;&lt;br /&gt;Router просматривает DBD и если находит там сети, о которых он не знает, он запрашивает подробную инфу &lt;/span&gt;&lt;span&gt;об этих сетках&lt;/span&gt;&lt;span&gt; через Link-State Request (&lt;span style="font-weight: bold;"&gt;LSR&lt;/span&gt;). В ответ приходит Link-State Updates (&lt;span style="font-weight: bold;"&gt;LSU&lt;/span&gt;) c запрошеной инфой. LSU - своего рода контейнер, содержаший индивидуальные Link State Advertisement ( &lt;span style="font-weight: bold;"&gt;LSA&lt;/span&gt;) о каждой анонсируемой сети.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;8. Neighbors are synchronized&lt;/span&gt; (&lt;span style="font-style: italic;"&gt;**FULL state**)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-style: italic;"&gt;Now it's time to start Dijkstra SPF algorithm to analyze received data&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="font-style: italic; color: rgb(255, 0, 0);"&gt;&lt;span&gt;!&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="font-style: italic; color: rgb(255, 0, 0);"&gt;&lt;span&gt;!&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="font-style: italic; color: rgb(255, 0, 0);"&gt;&lt;span&gt;! &lt;span style="color: rgb(0, 0, 0);"&gt;In broadcast env every router establish **FULL state** only with DR &amp;amp;BDR, with DR_Other **2-way state** established &lt;/span&gt;!&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="font-style: italic; color: rgb(255, 0, 0);"&gt;&lt;span&gt;!&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&lt;span style="font-style: italic; color: rgb(255, 0, 0);"&gt;&lt;span&gt;!&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;h4&gt;Packet Types&lt;/h4&gt; &lt;p&gt;OSPF is IP protocol 89. &lt;/p&gt; &lt;ul&gt;&lt;li&gt;      Hello - Used to establish communication with directly connected neighbors  &lt;/li&gt;&lt;li&gt;      Database Descriptor (DBD) - Lists router IDs from which the router has an LSA and its current sequence number  &lt;/li&gt;&lt;li&gt;      Link State Request (LSR) - Request for an LSA  &lt;/li&gt;&lt;li&gt;      Link State Update (LSU) - Reply to an LSR with the requested information  &lt;/li&gt;&lt;li&gt;      Link State Acknowledgment (LSAck) - Used to confirm receipt of link-state information  &lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;span&gt;&lt;span style="font-style: italic;"&gt;&lt;span style="font-style: italic;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-5243527897052729332?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/5243527897052729332/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=5243527897052729332' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/5243527897052729332'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/5243527897052729332'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/10/ospf-basics.html' title='OSPF basics'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_ieNEtWk3S4E/SP3hPFut-0I/AAAAAAAAAGw/YwK3XDhsv48/s72-c/ospf_basics%232.JPG' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-8689366599614600613</id><published>2008-10-14T21:25:00.003+04:00</published><updated>2008-10-14T21:37:25.728+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cisco'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><category scheme='http://www.blogger.com/atom/ns#' term='expo'/><title type='text'>Сертификация в ИБ</title><content type='html'>Сертификация и стандарты&lt;br /&gt;1) Международные&lt;br /&gt;2) Национальные&lt;br /&gt;3) Отраслевые (от ЦБ для финансовой сферы, от Газпрома)&lt;br /&gt;4) Корпоративные&lt;br /&gt;&lt;br /&gt;Также делятся на&lt;br /&gt;1) Обязательные&lt;br /&gt;2) Спорные / неявно обязательные&lt;br /&gt;3) Рекомендованные&lt;br /&gt;4) Best practices&lt;br /&gt;&lt;br /&gt;В  России в сфере ИБ основные регуляторы:&lt;br /&gt;1) ФСБ&lt;br /&gt;2) ФСТЭК&lt;br /&gt;3) Минком-связь (последнее время)&lt;br /&gt;4) МинОбороны&lt;br /&gt;5) ФСО&lt;br /&gt;6) СВР (служба внешней разведки)&lt;br /&gt;&lt;br /&gt;Плюс неосновные:&lt;br /&gt;1) ЦБ&lt;br /&gt;2) Газпром&lt;br /&gt;3) PCI Council&lt;br /&gt;&lt;br /&gt;Сертификаты:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;PCI DSS&lt;/span&gt; ( сертификация для работы с платежными системами VISA, MasterCard, Dinner Club, JCB)&lt;br /&gt;последняя версия 1.2 (от 10.2008)&lt;br /&gt;12 требований&lt;br /&gt;см док Cisco Secure Store для PCI&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ФСТЭК СТР-К &lt;/span&gt;(основной базовый документ ФСТЭК на данный момент)&lt;br /&gt;&lt;br /&gt;ФСБ защита персданных&lt;br /&gt;NME-RVPN серт КС1 и КС2&lt;br /&gt;&lt;br /&gt;PACE (cisco)&lt;br /&gt;Cisco NCM - аудит на соответствие требованиям сертификации. Не только циско, поддерживает 35 вендоров.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-8689366599614600613?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/8689366599614600613/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=8689366599614600613' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/8689366599614600613'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/8689366599614600613'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/10/1-2-3-4-1-2-3-4-best-practices-1-2-3-4.html' title='Сертификация в ИБ'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-3217512582727885308</id><published>2008-09-24T15:54:00.004+04:00</published><updated>2009-01-14T16:49:07.420+03:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='eigrp'/><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><title type='text'>EIGRP Metric</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://1.bp.blogspot.com/_ieNEtWk3S4E/SNoqnqRWlYI/AAAAAAAAAGA/RWDkCut1k78/s1600-h/eigrp_metric.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://1.bp.blogspot.com/_ieNEtWk3S4E/SNoqnqRWlYI/AAAAAAAAAGA/RWDkCut1k78/s400/eigrp_metric.jpg" alt="" id="BLOGGER_PHOTO_ID_5249555176504071554" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;By default only &lt;span style="font-weight: bold;"&gt;Delay&lt;/span&gt; and &lt;span style="font-weight: bold;"&gt;Bandwidth&lt;/span&gt; are used. Both of them are statically configured values&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-3217512582727885308?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/3217512582727885308/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=3217512582727885308' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/3217512582727885308'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/3217512582727885308'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/09/eigrp-metric.html' title='EIGRP Metric'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://1.bp.blogspot.com/_ieNEtWk3S4E/SNoqnqRWlYI/AAAAAAAAAGA/RWDkCut1k78/s72-c/eigrp_metric.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-2218878980285759143</id><published>2008-09-24T15:45:00.003+04:00</published><updated>2008-09-24T15:50:28.964+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cisco'/><category scheme='http://www.blogger.com/atom/ns#' term='eigrp'/><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><title type='text'>EIGRP Msg</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ieNEtWk3S4E/SNoo5gmYUQI/AAAAAAAAAF4/zTj2XV2BZKo/s1600-h/eigrp_msg.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_ieNEtWk3S4E/SNoo5gmYUQI/AAAAAAAAAF4/zTj2XV2BZKo/s400/eigrp_msg.jpg" alt="" id="BLOGGER_PHOTO_ID_5249553284122300674" border="0" /&gt;&lt;/a&gt;Multicast address for EIGRP routers&lt;span style="font-weight: bold;"&gt; 224.0.0.10&lt;br /&gt;Update msg -&lt;/span&gt; sends triggered update&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Query - &lt;/span&gt;asks about routes&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;ACK&lt;/span&gt; - собственный механизм подтверждения получения. (Все кроме hello)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-2218878980285759143?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/2218878980285759143/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=2218878980285759143' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2218878980285759143'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2218878980285759143'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/09/eigrp-msg.html' title='EIGRP Msg'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_ieNEtWk3S4E/SNoo5gmYUQI/AAAAAAAAAF4/zTj2XV2BZKo/s72-c/eigrp_msg.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-5536996119520079487</id><published>2008-09-24T13:56:00.010+04:00</published><updated>2008-09-24T14:18:53.191+04:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cisco'/><category scheme='http://www.blogger.com/atom/ns#' term='eigrp'/><category scheme='http://www.blogger.com/atom/ns#' term='routing'/><category scheme='http://www.blogger.com/atom/ns#' term='bsci notes'/><title type='text'>EIGRP Terminology</title><content type='html'>&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://3.bp.blogspot.com/_ieNEtWk3S4E/SNoSTY2t6mI/AAAAAAAAAFg/Q2p9DvWhO_8/s1600-h/eigrp_terminology.jpg"&gt;&lt;img style="margin: 0px auto 10px; display: block; text-align: center; cursor: pointer;" src="http://3.bp.blogspot.com/_ieNEtWk3S4E/SNoSTY2t6mI/AAAAAAAAAFg/Q2p9DvWhO_8/s400/eigrp_terminology.jpg" alt="" id="BLOGGER_PHOTO_ID_5249528439952501346" border="0" /&gt;&lt;/a&gt;(c) CBT nuggets&lt;br /&gt;&lt;span style="text-decoration: underline;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="font-weight: bold;"&gt;AD&lt;/span&gt; - advertised distance. For example 1900 in our case for net 10.1.2.0./24&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;FD&lt;/span&gt; - Feaseble distance = AD + cost. For example FD (R1) = 600 +10  for net 10.1.2.0./24&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Successor&lt;/span&gt; - Primary route ( goes to the routing table)&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Feaseble Successor&lt;/span&gt; - backup route. Must match condition - &lt;span style="font-style: italic; font-weight: bold; color: rgb(51, 51, 255);"&gt;AD must be less then FD of the successor&lt;/span&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Active route&lt;/span&gt; - route is actively search (&lt;span style="font-style: italic;"&gt;DUAL&lt;/span&gt;) for path to net. Smth failed. If there is feaseble successor, backup route goes routing table without recalculation&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Passive route&lt;/span&gt; - everything allright.&lt;br /&gt;&lt;br /&gt;Feaseble successor shows in topology table &lt;span style="font-weight: bold;"&gt;#sh ip eigrp topology&lt;br /&gt;&lt;/span&gt;&lt;a onblur="try {parent.deselectBloggerImageGracefully();} catch(e) {}" href="http://2.bp.blogspot.com/_ieNEtWk3S4E/SNoT_PVlbkI/AAAAAAAAAFw/WrnWGZfoNZU/s1600-h/eigrp_topology+example.jpg"&gt;&lt;img style="margin: 0pt 10px 10px 0pt; float: left; cursor: pointer;" src="http://2.bp.blogspot.com/_ieNEtWk3S4E/SNoT_PVlbkI/AAAAAAAAAFw/WrnWGZfoNZU/s320/eigrp_topology+example.jpg" alt="" id="BLOGGER_PHOTO_ID_5249530292823486018" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="file:///C:/Users/ash/AppData/Local/Temp/moz-screenshot.jpg" alt="" /&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-5536996119520079487?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/5536996119520079487/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=5536996119520079487' title='Комментарии: 1'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/5536996119520079487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/5536996119520079487'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/09/eigrp-terminology.html' title='EIGRP Terminology'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/_ieNEtWk3S4E/SNoSTY2t6mI/AAAAAAAAAFg/Q2p9DvWhO_8/s72-c/eigrp_terminology.jpg' height='72' width='72'/><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-2397238526597404008</id><published>2008-01-31T13:17:00.001+03:00</published><updated>2008-01-31T13:17:39.760+03:00</updated><title type='text'></title><content type='html'>.. в процессе настройки ситуация менялась интересным образом: "должно работать но не работает" - "должно работать и работает" - " НЕ должно работать, но работает сцуко ! " ))&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-2397238526597404008?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/2397238526597404008/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=2397238526597404008' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2397238526597404008'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2397238526597404008'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/01/blog-post.html' title=''/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7514463516099385727.post-2804762566600681822</id><published>2008-01-19T11:52:00.000+03:00</published><updated>2008-01-19T13:04:26.209+03:00</updated><title type='text'>Тестим GS</title><content type='html'>Действительно просто. Гугль молодцом - раз, два, три и блог готов. Очень мне последнее время импонирует простота. Вообще, в конечном итоге, в мире победит простота. Посмотрите хотя бы на Ethernet и ...автомат Калашникова ) Они чем-то похожи - оба жутко простые, дешевые и поэтому ужасно популярные ) Еще одна тенденция - интеграция всего и вся. Раньше, помнится, я был категорически против всех этих камерфонов, плейрфонов, коммуникаторов и смартфонов - ну хреново они выполняли свои функции, пусть и разнообразные.... заметно хуже нежели специализированные девайсы. Но прогресс не стоит на месте и сейчас все это вполне юзабельно, а главное..... опять же очень просто =)  К чему это я.... Ах, да,  а  ведь  онлайн-сервисы идут  тем же путем ) Всем интересно кто же победит Google services или Windows Live ?  Google раньше сориентировался в ситуации, спору нет, у них уже сформировалось преданное коммьюнити, их сервисы разнообразнее, функциональнее и все такое.... Вот только у Microsoft тупо больше денег =) И фактическая монополия на уровне home pc, и, что еще важнее, на mobile devices. Чувствую Live прямо таки станет неотделимой частью Windows. А в этом случае, если только Live не будет заметно хуже GS,  полная победа ему обеспечена. А если будет хуже - просто большая часть рынка, как это происходит с IE ( который кстати в v7 стал вполне юзабелен). А если MS еще и догадается купить LJ..... кто-то из них его точно купит ;) Как было с youtube. Имхо гуглю стоит подружиться с яблоками... Яблоки действительно становятся конкурентом MS %) Даже у нас в России, где стоят бешеных денег ! Хотя парни из google товарищи амбициозные, могут и собственный дистр Линуха сваять ))&lt;br /&gt;Вообщем развитие событий обещает быть интересным. Увидим ли мы  банкротство Голиафа или  же  МС как всегда останется у руля ? Хмм....&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7514463516099385727-2804762566600681822?l=tgzzz.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://tgzzz.blogspot.com/feeds/2804762566600681822/comments/default' title='Комментарии к сообщению'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=7514463516099385727&amp;postID=2804762566600681822' title='Комментарии: 0'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2804762566600681822'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7514463516099385727/posts/default/2804762566600681822'/><link rel='alternate' type='text/html' href='http://tgzzz.blogspot.com/2008/01/gs.html' title='Тестим GS'/><author><name>tgz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
