Section 10.0: Security Violations (6 points)

10.1. Denial of Service (DoS) (3 points)

  1. R1 is experiencing a Denial-of-Service attack from the Internet. Upon investigation by collecting sniffer traces on VLAN_4, it was found that the packets arriving are noninitial IP fragments; packets have FO > 0 with the MF bit set, to a web server 110.50.13.72 in VLAN_3 on port 80. You do not want to allow any fragments to reach the web server. Allow only nonfragmented packets to reach the web server.

10.2. IP Spoofing (3 points)

  1. Simulate a DoS attack from R3 to R8 with ICMP floods, using R2 as a reflector. Use the necessary Loopback-1 for source and destination address as appropriate.

  2. Once you are successful in the above penetration test, configure such that ...

Get CCIE Security Practice Labs now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.