802.1X, TrustSec/SGT, MACsec, AAA & CoPP

CCNP ENCOR 350-401 v1.2 EVE-NG / GNS3

مقصدObjectiveObjective

اس لیب میں آپ نیٹ ورک ایکسیس سیکیورٹی سیکھیں گے — 802.1X پورٹ authentication، AAA، MACsec اور TrustSec/SGT کے کانسیپٹس، اور CoPP کانفیگریشن۔ ENCOR D5 کا ٹاپک۔Is lab mein aap network access security seekhenge — 802.1X port authentication, AAA, MACsec aur TrustSec/SGT ke concepts, aur CoPP configuration. ENCOR D5 ka topic.In this lab you will learn network access security — 802.1X port authentication, AAA, MACsec and TrustSec/SGT concepts, and CoPP configuration. An ENCOR D5 topic.

آسان مثالSimple AnalogySimple Analogy

دفتر کی سیکیورٹی سوچیں۔ 802.1X دروازے پر ID کارڈ چیک ہے — کارڈ کے بغیر اندر نہیں۔ AAA تین سوال ہیں: آپ کون ہیں (authentication)، آپ کیا کر سکتے ہیں (authorization)، آپ نے کیا کیا (accounting)۔ MACsec مہر بند لفافہ ہے — راستے میں کوئی پڑھ نہیں سکتا۔ TrustSec/SGT رنگ برنگے بیجز ہیں — پالیسی بیج کے رنگ پر لگتی ہے، نام پر نہیں۔ CoPP مینیجر کا باڈی گارڈ ہے — کنٹرول پلین کو حملوں سے بچاتا ہے۔Daftar ki security socho. 802.1X darwaze par ID card check hai — card ke baghair andar nahi. AAA teen sawal hain: aap kaun hain (authentication), aap kya kar sakte hain (authorization), aap ne kya kiya (accounting). MACsec muhar band lifafa hai — raaste mein koi parh nahi sakta. TrustSec/SGT rang barange badges hain — policy badge ke rang par lagti hai, naam par nahi. CoPP manager ka bodyguard hai — control plane ko hamlon se bachata hai.Think of office security. 802.1X is the ID card check at the door — no entry without a card. AAA asks three questions: who are you (authentication), what can you do (authorization), what did you do (accounting). MACsec is a sealed envelope — no one can read it on the way. TrustSec/SGT are color-coded badges — policy applies to the badge color, not the name. CoPP is the manager's bodyguard — it protects the control plane from attacks.

سیٹ اپLab SetupLab Setup

SW1 سوئچ، RADIUS سرور (192.168.10.100) اور 2 PCs۔ ڈیوائسز: 1x سوئچ 2960 (SW1)، 1x RADIUS سرور، 2x پی سی۔ PC1: 192.168.10.10/24، PC2: 192.168.10.11/24۔SW1 switch, RADIUS server (192.168.10.100) aur 2 PCs. Devices: 1x Switch 2960 (SW1), 1x RADIUS server, 2x PC. PC1: 192.168.10.10/24, PC2: 192.168.10.11/24.SW1 switch, a RADIUS server (192.168.10.100) and 2 PCs. Devices: 1x Switch 2960 (SW1), 1x RADIUS server, 2x PC. PC1: 192.168.10.10/24, PC2: 192.168.10.11/24.

اقداماتStepsSteps

Step 1

SW1 پر AAA آن کریں اور RADIUS سرور بتائیں۔ aaa new-model کے بغیر 802.1X کام نہیں کرے گا۔ سرور کا IP، ports اور key بالکل درست لکھیں۔SW1 par AAA on karo aur RADIUS server batao. aaa new-model ke baghair 802.1X kaam nahi karega. Server ka IP, ports aur key bilkul durust likho.Enable AAA on SW1 and define the RADIUS server. 802.1X won't work without aaa new-model. Write the server's IP, ports and key exactly.

enable
configure terminal
aaa new-model
radius server ISE
address ipv4 192.168.10.100 auth-port 1812 acct-port 1813
key SECRET123
exit
aaa authentication dot1x default group radius
aaa authorization network default group radius
exit

Step 2

پورٹ Fa0/1 پر 802.1X لگائیں۔ authentication port-control auto کا مطلب: پہلے authentication، پھر نیٹ ورک۔ PC پر 802.1X supplicant آن ہونا چاہیے۔Port Fa0/1 par 802.1X lagao. authentication port-control auto ka matlab: pehle authentication, phir network. PC par 802.1X supplicant on hona chahiye.Enable 802.1X on port Fa0/1. authentication port-control auto means: authentication first, then network. The 802.1X supplicant must be on on the PC.

configure terminal
dot1x system-auth-control
interface fa0/1
switchport mode access
authentication port-control auto
dot1x pae authenticator
exit
exit

Step 3

MACsec کا کانسیپٹ: سوئچ اور ڈیوائس کے درمیان تار پر encryption — Layer 2 پر۔ چابیاں MKA پروٹوکول سے بنتی ہیں۔ ENCOR میں صرف concept آتا ہے، کانفگ نہیں۔MACsec ka concept: switch aur device ke darmiyan taar par encryption — Layer 2 par. Chaabiyan MKA protocol se banti hain. ENCOR mein sirf concept aata hai, config nahi.MACsec concept: encryption on the wire between switch and device — at Layer 2. Keys are negotiated by the MKA protocol. ENCOR only asks the concept, not the config.

Step 4

TrustSec/SGT کا کانسیپٹ: ہر ڈیوائس/یوزر کو ایک ٹیگ (SGT نمبر) ملتا ہے، اور پالیسی IP کے بجائے ٹیگ پر لگتی ہے۔ ٹیگ ISE دیتا ہے، پالیسی پورے نیٹ ورک میں ٹیگ دیکھ کر لگتی ہے۔TrustSec/SGT ka concept: har device/user ko ek tag (SGT number) milta hai, aur policy IP ke bajaye tag par lagti hai. Tag ISE deta hai, policy pure network mein tag dekh kar lagti hai.TrustSec/SGT concept: every device/user gets a tag (SGT number), and policy applies to the tag instead of the IP. ISE assigns the tag; policy is enforced across the network based on the tag.

Step 5

CoPP لگائیں — کنٹرول پلین کی حفاظت۔ اہم ٹریفک (SSH، routing protocols) کو الگ class میں ڈال کر rate limit کریں تاکہ حملہ آور CPU نہ گرا سکے۔CoPP lagao — control plane ki hifazat. Ahem traffic (SSH, routing protocols) ko alag class mein daal kar rate limit karo taake hamlawar CPU na gira sake.Configure CoPP — protecting the control plane. Put important traffic (SSH, routing protocols) in a separate class and rate-limit it so an attacker can't bring down the CPU.

configure terminal
ip access-list extended COPP-CRITICAL
permit tcp any any eq 22
permit ospf any any
permit eigrp any any
exit
class-map match-all COPP-CLASS
match access-group name COPP-CRITICAL
exit
policy-map COPP-POLICY
class COPP-CLASS
police 8000 conform-action transmit exceed-action drop
exit
exit
control-plane
service-policy input COPP-POLICY
exit
exit

Step 6

ٹیسٹنگ: PC سے لاگ اِن کریں — RADIUS پر اکاؤنٹ ہو تو پورٹ authorized ہو۔ show authentication sessions سے سیشن دیکھیں۔Testing: PC se log in karo — RADIUS par account ho to port authorized ho. show authentication sessions se session dekho.Testing: log in from the PC — if the account exists on RADIUS, the port becomes authorized. View the session with show authentication sessions.

show dot1x all
show authentication sessions
show policy-map control-plane

تصدیقVerifyVerify

show authentication sessions میں authorized سیشن اور show policy-map control-plane میں پالیسی نظر آئے تو لیب کامیاب۔show authentication sessions mein authorized session aur show policy-map control-plane mein policy nazar aaye to lab kamyab.If show authentication sessions shows an authorized session and show policy-map control-plane shows the policy, the lab is a success.

show authentication sessions
show policy-map control-plane

خرابی دور کرناTroubleshootingTroubleshooting

⚠️ پورٹ unauthorized ہی رہتا ہے، PC کو نیٹ ورک نہیں ملتا۔Port unauthorized hi rehta hai, PC ko network nahi milta.The port stays unauthorized; the PC gets no network.

✅ RADIUS key اور IP دونوں طرف same ہوں۔ سرور reachable ہو (ping کریں)۔ PC پر supplicant آن ہو۔RADIUS key aur IP dono taraf same hon. Server reachable ho (ping karo). PC par supplicant on ho.RADIUS key and IP must match on both sides. The server must be reachable (ping it). The supplicant must be on on the PC.

⚠️ CoPP لگانے کے بعد جائز ٹریفک بھی drop ہو رہا ہے۔CoPP lagane ke baad jayez traffic bhi drop ho raha hai.Legitimate traffic is also being dropped after applying CoPP.

✅ police کی rate بہت کم ہوگی — show policy-map control-plane سے drops دیکھیں اور rate بڑھائیں۔police ki rate bohat kam hogi — show policy-map control-plane se drops dekho aur rate barhao.The police rate is probably too low — check drops with show policy-map control-plane and raise the rate.

انٹرویو سوالاتInterview Q&AInterview Q&A

❓ 802.1X میں supplicant، authenticator اور authentication server کون ہیں؟802.1X mein supplicant, authenticator aur authentication server kaun hain?In 802.1X, who are the supplicant, authenticator and authentication server?

Supplicant یوزر کا PC ہے، authenticator سوئچ کا پورٹ ہے، authentication server RADIUS سرور (جیسے ISE) ہے۔Supplicant user ka PC hai, authenticator switch ka port hai, authentication server RADIUS server (jaise ISE) hai.The supplicant is the user's PC, the authenticator is the switch port, the authentication server is the RADIUS server (like ISE).

❓ CoPP کیوں ضروری ہے؟CoPP kyun zaroori hai?Why is CoPP necessary?

کنٹرول پلین (routing، management) پر حملہ ہو تو پورا روٹر گر سکتا ہے۔ CoPP اہم ٹریفک کو ترجیح دے کر CPU کو محفوظ رکھتا ہے۔Control plane (routing, management) par hamla ho to poora router gir sakta hai. CoPP ahem traffic ko tarjeeh de kar CPU ko mehfooz rakhta hai.If the control plane (routing, management) is attacked, the whole router can fall. CoPP keeps the CPU safe by prioritizing important traffic.