Section 10.0: Security Violations (8 points)

10.1. DoS Attack (4 points)

  1. An intruder can potentially compromise a router and use it as a launch pad to attack other devices on the network.

  2. Assume R3 is compromised and an attacker is launching an ICMP flood attack to R2.

  3. Use an appropriate method on R3 to prevent this.

  4. Do not configure an ACL on any interface on R2 or R3 to achieve this task.

  5. Make sure R2 is able to ping R3.

10.2. High CPU Caused by an Attack (4 points)

  1. R8 is experiencing a HIGH CPU, causing flaps in BGP and OSPF neighbors.

  2. It has been noticed that there are an unusually high number of logs related to RSHELL. See the snip from the following router log. These seem to be the main cause of the issue.

     .May 20 20:22:01.204 GMT-3: %RCMD-4-RSHPORTATTEMPT: ...

Get CCIE Security Practice Labs now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.