Sba Inb23304-Network Security Oct2024
Sba Inb23304-Network Security Oct2024
Name
Weightage 10%
SECTION A:
INSTRUCTIONS:
*Note: Where ‘X’ is your number in this course student name list in ECITIE. Refer name
list in PDF file link (Class_NetSec_Name_List_Oct2024.pdf) available in VLE.
Example: 10)_Abdul-Halim_522198765_SkillBased_Oct24.pkt
1
INB23304 NETWORK SECURITY
OCTOBER 2024 CONFIDENTIAL
Based Figure 1, note that network 192.168.10.0/24 is the local network and network
192.168.20.0/24 is the remote network. The network topology shows three routers. Your task is
to:
1) Perform necessary ‘Router Hardening’ techniques that you have learned to enhance device
security.
2) Use suitable configuration at routers to enable ‘secure’ communication (tunnel) between
local site and the remote site, without R3 (ISP) router able to see pass through packets.
Routers R1 and R2 to support a site-to-site communication when traffic flows to-and-fro their
respective LANs. R3 acts as a pass-through and has no knowledge of communication between
R1 and R2.
You may refer to the Table 1 and Table 2 for ISAKMP and IPSec parameters.
Parameters R1 R2
Key distribution ISAKMP ISAKMP
method
Encryption algorithm AES AES
Hash Algorithm SHA-1 SHA-1
Authentication method Pre-shared Pre-share
Key exchange DH 2 DH 2
IKE SA Lifetime 86400 86400
ISAKMP Key vpnSTS99 vpnSTS99
2
INB23304 NETWORK SECURITY
OCTOBER 2024 CONFIDENTIAL
Parameter R1 R2
Transform set VPN-SITE VPN-SITE
Peer Hostname R2 R1
Peer IP Address 172.17.1.1 172.16.1.1
Network to be encrypted 192.168.10.0 192.168.20.0
Crypto Map name VPN-MAP VPN-MAP
SA Establishment ipsec-isakmp ipsec-isakmp
Assessment:
At the end, command show crypto ipsec sa will be used to verify the match interesting
packet between network 192.168.10.0 (local) and 192.168.20.0 (remote).
Remarks:
*Note: Where ‘X’ is your number in this course student name list in ECITIE. Refer
name list in PDF file link (Class_NetSec_Name_List_Oct2024.pdf) available in VLE.
Please use <netsecpa55> as all/any password set at device in your packet tracer to
ease marking process.
3
INB23304 NETWORK SECURITY
OCTOBER 2024 CONFIDENTIAL
ATTACHMENT
SKILL BASED ASSESSMENT (SBA) RUBRICS
Set access list for LAN to LAN: did not set access listwrongly configured access list configured access listconfigured access list
Set interesting traffic from local site at R1. 0.5 at all configured partially, and completely, but only completely, and 2
Set interesting traffic from remote site at access list partially correct partially correct correctly
R2.
4
INB23304 NETWORK SECURITY