dhcp snooping – xavfsizlik texnologiyasi

DOCX 9 pages 178.2 KB Free download

Page preview (5 pages)

Scroll down 👇
1 / 9
4-laboratoriya ishi dhcp snooping – xavfsizlik texnologiyasi. ishdan maqsad. dhcp snooping – xavfsizlik texnologiyasi sozlash ko`nikmalarini hosil qilish. qisqacha nazariy ma'lumotlar dhcp snooping - bu qabul qilinmaydigan deb topilgan dhcp trafigini o'chirib tashlaydigan real tarmoq komutatorining operatsion tizimiga o'rnatilgan 2-darajali xavfsizlik texnologiyasi. dhcp snooping, dhcp mijozlariga ip-manzillarni taklif qiladigan noto'g'ri dhcp-serverlarning oldini oladi. dhcp snooping quyidagilarni amalga oshiradi: ishonchsiz manbalardan kelgan dhcp xabarlarini tekshiradi va yaroqsiz xabarlarni filtrlaydi. ip-manzillari ijaraga olingan ishonchli bo'lmagan xostlar haqida ma'lumotlarni o'z ichiga olgan ma'lumotlar bazasini yaratadi va saqlaydi. ishonchsiz xostlardan keyingi so'rovlarni tekshirish uchun yaratilgan ma'lumotlar bazasidan foydalanadi. dhcp snoopingni faqat simli tarmoq foydalanuvchilar uchun qo’llasa bo’ladi. kirish qatlami xavfsizligi xususiyati sifatida, asosan, dhcp tomonidan xizmat ko'rsatiladigan vlanga kirish portlarini o'z ichiga olgan har qanday komutatorda yoqiladi. dhcp snoopingni o'rnatishda himoya qilmoqchi bo'lgan vlanda dhcp snoopingni yoqishdan oldin ishonchli portlarni (dhcp-serverning tegishli xabarlari o'tadigan portlarni) sozlash kerak. bu clida ham, veb-interfeysda ham amalga oshirilishi …
2 / 9
it rate 2048 switch(config-if) do wr switch(config)#end routerga quyida buyruqlar ketma ketligi kiritiladi. continue with configuration dialog? [yes/no]: no router>enable router#conf t router(config)#interface gigabitethernet 0/0 router(config-if)#no shutdown router(config-if)#ip address 192.168.100.1 255.255.255.0 router(config-if)#ip helper-address 10.10.10.10 router(config-if)#ex router(config)#interface gigabitethernet 0/1 router(config-if)#no shutdown router(config-if)#ip address 10.10.10.1 255.255.255.0 router(config-subif)#do wr router(config-subif)#exit 11.2-rasm. serverga dhcp xizmatini yoqish. 11.3-rasm. hostlarni ip manzil olganligini ko’rish. 11.4-rasm. soxta serverda dhcp xizmatini yoqish. 11.5-rasm. soxta serverdan ip manzil olgan host. 11.6-rasm. dhcp snooping xizmati yoqilgandan so’ng hostning haqiqiy serverdan ip manzil olishi. topshiriq: amaliy ish mavzusi bo'yicha hisobot tayyorlash. hisobotning mazmuni: - ishning raqami va mavzusi; - cisco packettracerda tadqiq qilinayotgan tarmoq topologiyasining tasviri; - tarmoqdagi ip-manzillarni taqsimlash, ulanish diagrammasi (interfeys raqamlari), shu jumladan modelning tavsifi; - foydalanuvchi nomlari va parollari; - tarmoq elementlarini sozlash ro'yxati; - tarmoq elementlariga kirishga urinishlar natijalari. nazorat savollari 1. dhcp xizmati nima? 2. dhcp xizmatida qanday zaifliklar mavjud? 3. dhcp-snooping tarmoq hujumi nima …
3 / 9
‘save remove poo! detaut ons «sb subnet max ttp wl name gateway server mask user server address. ‘sheri 192168... 8883 192.188... 255.255... 248 0.000 0.0.00 /serverpool 0000 0000 0000 0000 512 0000 0000 r serverd physical config ‘services. htte dhcp. dhcpv6. ftp. dns syslog tot \m management radius eap a once interface fastethernet) | service © on oor rosie fares befaut gateway ‘ezrees00 ns server fn stat padiess: [52 i 0 ny subnets — be eg eg a axnum unber of ser eg sree 008 caress 008 7a save = poot eto ows sh subnet mx tip wh same gateway emer gg mask user sener address serveroo 0000 0nd tosntooss2882860 siz 0000 0000 physical config desktop programming attributes uration interface 'p configuration o picp pv4address: ‘subnet mask default gateway dns server |pv6 configuration o automatic ive address: link local address. dns server © static '192.168.100.10 [258.258 255.0 '192.168.100.1 ass © …
4 / 9
e fastethernet] | service © on oor pooiname (armel 2 befaut gateway ezeezi0 ns server fn stat padiess: [52 i 00 2 subnets — be eg eg a axnum unber fers eg sree 008 cadres 008 7a save = poot eto ows sh subnet mx tip wh same gatewsy emer gg mask user sener address serveroo 0000 ona tsateez000 as52682860 288 0000 00.00 laptop2 physical config desktop programming attributes interface fastethernet0 'p configuration o picp v4 address. ‘subnet mask default gateway dns server |pv6 configuration o automatic ve address. link local address. dns server '192.168.200.1 [258.258 255.0 foo.0.0 ass © static [fee0:-200:cff-fese9ce4 rb pcs physical config desktop programming attributes interface 'p configuration © pier address ‘subnet mask default gateway dns server |pv6 configuration o picp ve adgress. link local address: fastethernet0 o static dhcp request successful. 192. 168.200.1 255.256 255.0 00.00 2888 © auto contig © static fegd: 200-ffff-fe23;615a fao …
5 / 9
nfig)? router (config) host router (config) fhostname r.sher rlsher(config)#int gig r.sher(config)#int gigabitzchernet 0/0 r.sher(config-if)#no shut rlsher(config-if)#no shutdown rlsher (config~if) slink-s-changed: interface gigabitethernet0/0, changed state to up slineproto-s-updown: line protocol on interface gigabitethernet0/0, changed state to up r.sher(config-if) #ip add rlsher (config-if)#ip address 192.168.100.1 255.255.255.0, r.sher(config-if) #ip hel usher (config-if)#ip helper-address 10.10.19.9 r.sher(config-if)#int gig r.sher (config-if) texit r.sher(config) int gigabicethernet 0/1 r.sher(config-if) no shut r_sher(config-if) #no shutdown r.sher (config-if)¢ slink-5-changed: interface gigabitetherneto/1, changed state to up slineproto-s-updown: line protocol on interface gigabitethernet0/1, changed state to up r.sher(config-if) #ip add r.sher (config-if)#ip address 10.10.10.0 255.255.255.0 bad mask /24 for address 10.10.10.0 r.sher(config-if) #do we building configuration... [oi r.sher(config-if)#

Want to read more?

Download all 9 pages for free via Telegram.

Download full file

About "dhcp snooping – xavfsizlik texnologiyasi"

4-laboratoriya ishi dhcp snooping – xavfsizlik texnologiyasi. ishdan maqsad. dhcp snooping – xavfsizlik texnologiyasi sozlash ko`nikmalarini hosil qilish. qisqacha nazariy ma'lumotlar dhcp snooping - bu qabul qilinmaydigan deb topilgan dhcp trafigini o'chirib tashlaydigan real tarmoq komutatorining operatsion tizimiga o'rnatilgan 2-darajali xavfsizlik texnologiyasi. dhcp snooping, dhcp mijozlariga ip-manzillarni taklif qiladigan noto'g'ri dhcp-serverlarning oldini oladi. dhcp snooping quyidagilarni amalga oshiradi: ishonchsiz manbalardan kelgan dhcp xabarlarini tekshiradi va yaroqsiz xabarlarni filtrlaydi. ip-manzillari ijaraga olingan ishonchli bo'lmagan xostlar haqida ma'lumotlarni o'z ichiga olgan ma'lumotlar bazasini yaratadi va saqlaydi. ishonchsiz xostlardan keyingi so'rovlarni teksh...

This file contains 9 pages in DOCX format (178.2 KB). To download "dhcp snooping – xavfsizlik texnologiyasi", click the Telegram button on the left.

Tags: dhcp snooping – xavfsizlik texn… DOCX 9 pages Free download Telegram