אנלוגיה: Telnet זה לצעוק את הסיסמה במסדרון, SSH זה לומר אותה בלחש בחדר סגור. זה מנעול על השקע בקיר — רק המכשיר המוכר יכול להתחבר.
Port Security — שלוש תגובות להפרה
- protect — מפיל את התעבורה החורגת בשקט, בלי התראה.
- restrict — מפיל תעבורה ומייצר Log ומונה הפרות.
- shutdown (ברירת מחדל) — מעביר את הפורט ל־err-disabled עד התערבות ידנית.
- sticky — המתג לומד את ה־MAC הראשון ושומר אותו בתצורה.
- aging — מוחק MAC שנלמד אחרי X דקות, נוח לחדרי ישיבות.
! Port Security על פורט משתמש
Switch(config-if)# switchport mode access
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security maximum 2
Switch(config-if)# switchport port-security mac-address sticky
Switch(config-if)# switchport port-security violation restrict
! SSH במקום Telnet
Switch(config)# hostname SW1
Switch(config)# ip domain-name lab.local
Switch(config)# crypto key generate rsa modulus 2048
Switch(config)# username admin privilege 15 secret StrongPass!23
Switch(config)# ip ssh version 2
Switch(config)# line vty 0 15
Switch(config-line)# transport input ssh
Switch(config-line)# login local
Switch(config-line)# exec-timeout 5 0
! הקשחה בסיסית
Switch(config)# service password-encryption
Switch(config)# enable secret StrongEnable!23
Switch(config)# no ip http server
Switch(config)# banner motd #Authorized access only#
Switch(config)# line console 0
Switch(config-line)# password ConsolePass!23
Switch(config-line)# login
! בדיקות ושחזור פורט
Switch# show port-security interface gi0/1
Switch# show ip ssh
Switch(config-if)# shutdown
Switch(config-if)# no shutdownbashארכיטקטורה ותיאוריה — מתחת למכסה המנוע
הקשחה = לצמצם את משטח התקיפה של הציוד עצמו: הצפנת ניהול, סיסמאות חזקות, כיבוי שירותים מיותרים, לוגים ותיעוד.
- Telnet שולח סיסמאות בטקסט גלוי — SSHv2 בלבד; דורש hostname, domain-name ומפתח RSA 2048.
- enable secret שומר hash (Type 8/9) בעוד enable password שמור כמעט בטקסט גלוי.
- service password-encryption הוא הצפנה חלשה (Type 7) — לא סומכים עליה.
- לכבות: CDP לכיוון רשתות לא מהימנות, HTTP server, DNS lookup אקראי, פורטים לא בשימוש (shutdown).
- + /TACACS: אימות מול במקום סיסמאות מקומיות משותפות.
הגדרה מעשית (CLI)
R(config)# hostname CORE-SW1
R(config)# ip domain-name lab.local
R(config)# crypto key generate rsa modulus 2048
R(config)# ip ssh version 2
R(config)# username admin privilege 15 secret Str0ng!Pass
R(config)# enable secret Str0ng!Enable
R(config)# line vty 0 15
R(config-line)# transport input ssh
R(config-line)# login local
R(config-line)# exec-timeout 5 0
R(config)# no ip http server
R(config)# no ip http secure-server
R(config)# banner motd #Authorized access only#
R(config)# logging host 192.168.10.50
R(config)# ntp server 192.168.10.10
R(config)# interface range gi0/21-23
R(config-if-range)# shutdown
R# copy running-config startup-configbashתרחישי אמת בארגון
- כל ציוד הרשת שולח syslog לשרת מרכזי / — בלי זה אין חקירת אירועים.
- גישת ניהול רק מ־VLAN ניהול ייעודי ודרך Jump Server.
- התחברות מנהלים עם חשבון אישי דרך / — יש תיעוד מי עשה מה.
- גיבוי קונפיגורציות אוטומטי לפני כל שינוי.
אבחון ופתרון תקלות
R# show ip ssh
R# show users
R# show running-config | include username|enable|transport
R# show logging
R# show version ! uptime, IOS version
R# show inventorybash- SSH לא עולה → חסר domain-name או מפתח RSA; ה־modulus חייב 768 ומעלה (מומלץ 2048).
- התחברות נדחית → line vty ללא login local או ללא username מקומי.
- 'איבדנו את הקונפיג אחרי אתחול' → לא בוצע copy running-config startup-config.
- אין לוגים בשרת → בדוק logging host, קישוריות UDP 514 ושעון NTP.
מילון מונחים ושורת פקודות מהירה
- SSH: hostname + ip domain-name + crypto key generate rsa + ip ssh version 2
- enable secret (חזק) ולא enable password
- transport input ssh — סוגר Telnet
- copy run start / write memory — לשמור!