Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
IPexpert’s CCIE Security Proctor Guide – Version 4.1 Section 13<br />
R6(config-ext-nacl)#deny udp 192.1.6.0 0.0.0.255 any eq 20000 timerange<br />
WEEKEND<br />
R6(config-ext-nacl)#permit ip any any<br />
R6#show access-list 131<br />
Extended IP access list 131<br />
10 deny tcp 192.1.6.0 0.0.0.255 any eq 25000 time-range WEEKDAYS<br />
(inactive)<br />
20 deny udp 192.1.6.0 0.0.0.255 any eq 20000 time-range WEEKEND<br />
(inactive)<br />
30 permit ip any any<br />
R6#show time-range<br />
time-range entry: WEEKDAYS (inactive)<br />
periodic weekdays 9:00 to 15:59<br />
used in: IP ACL entry<br />
time-range entry: WEEKEND (inactive)<br />
periodic weekend 10:00 to 14:59<br />
used in: IP ACL entry<br />
R6#<br />
9.5 - Disable Unnecessary Services (2 Points)<br />
a) Disable the DHCP Service on R6.<br />
b) Verify that it is disabled by typing Show ip socket.<br />
R6#show ip socket<br />
Proto Remote Port Local Port In Out Stat TTY OutputIF<br />
17 0.0.0.0 0 6.6.6.6 5060 0 0 211 0<br />
17 --listen-- 6.6.6.6 68 0 0 1 0<br />
17 --listen-- 6.6.6.6 2887 0 0 11 0<br />
17 0.0.0.0 0 6.6.6.6 67 0 0 2211 0<br />
17 0.0.0.0 0 6.6.6.6 2517 0 0 11 0<br />
88 --listen-- 6.6.6.6 26 0 0 0 0<br />
17 192.1.12.65 514 6.6.6.6 56286 0 0 211 0<br />
17 --listen-- 6.6.6.6 123 0 0 1 0<br />
R6#<br />
R6(config)#no service dhcp<br />
R6#show ip socket<br />
Proto Remote Port Local Port In Out Stat TTY OutputIF<br />
17 0.0.0.0 0 6.6.6.6 5060 0 0 211 0<br />
17 --listen-- 6.6.6.6 68 0 0 1 0<br />
17 --listen-- 6.6.6.6 2887 0 0 11 0<br />
17 0.0.0.0 0 6.6.6.6 2517 0 0 11 0<br />
88 --listen-- 6.6.6.6 26 0 0 0 0<br />
17 192.1.12.65 514 6.6.6.6 56286 0 0 211 0<br />
17 --listen-- 6.6.6.6 123 0 0 1 0<br />
R6#<br />
Copyright IPexpert, Inc. (http://www.ipexpert.com) 2007. All Rights Reserved. 365