דילוג לתוכן הראשי
AD Academy
CCNA — יסודות רשתות Cisco
מתחילים12 דקותעודכן לאחרונה: נושא 12 מתוך 12

Port Security, SSH והקשחת ציוד

לסגור את דלת הכניסה: הגבלת MAC, ניהול מוצפן וכיבוי שירותים מיותרים.

לא הושלם

מה תלמדו כאן

  • איך מגבילים MAC בפורט
  • למה SSH ולא Telnet
  • אילו שירותים מיותרים לכבות

כדאי לקרוא לפני הנושא הזה:ACL: Standard מול Extended וסדר הכללים

אנלוגיה: Telnet זה לצעוק את הסיסמה במסדרון, SSH זה לומר אותה בלחש בחדר סגור. זה מנעול על השקע בקיר — רק המכשיר המוכר יכול להתחבר.

Port Security — שלוש תגובות להפרה

  • protect — מפיל את התעבורה החורגת בשקט, בלי התראה.
  • restrict — מפיל תעבורה ומייצר Log ומונה הפרות.
  • shutdown (ברירת מחדל) — מעביר את הפורט ל־err-disabled עד התערבות ידנית.
  • sticky — המתג לומד את ה־MAC הראשון ושומר אותו בתצורה.
  • aging — מוחק MAC שנלמד אחרי X דקות, נוח לחדרי ישיבות.
! Port Security על פורט משתמש
Switch(config-if)# switchport mode access
Switch(config-if)# switchport port-security
Switch(config-if)# switchport port-security maximum 2
Switch(config-if)# switchport port-security mac-address sticky
Switch(config-if)# switchport port-security violation restrict

! SSH במקום Telnet
Switch(config)# hostname SW1
Switch(config)# ip domain-name lab.local
Switch(config)# crypto key generate rsa modulus 2048
Switch(config)# username admin privilege 15 secret StrongPass!23
Switch(config)# ip ssh version 2
Switch(config)# line vty 0 15
Switch(config-line)# transport input ssh
Switch(config-line)# login local
Switch(config-line)# exec-timeout 5 0

! הקשחה בסיסית
Switch(config)# service password-encryption
Switch(config)# enable secret StrongEnable!23
Switch(config)# no ip http server
Switch(config)# banner motd #Authorized access only#
Switch(config)# line console 0
Switch(config-line)# password ConsolePass!23
Switch(config-line)# login

! בדיקות ושחזור פורט
Switch# show port-security interface gi0/1
Switch# show ip ssh
Switch(config-if)# shutdown
Switch(config-if)# no shutdown
bash
ארכיטקטורה ותיאוריה — מתחת למכסה המנוע

הקשחה = לצמצם את משטח התקיפה של הציוד עצמו: הצפנת ניהול, סיסמאות חזקות, כיבוי שירותים מיותרים, לוגים ותיעוד.

  • Telnet שולח סיסמאות בטקסט גלוי — SSHv2 בלבד; דורש hostname, domain-name ומפתח RSA 2048.
  • enable secret שומר hash (Type 8/9) בעוד enable password שמור כמעט בטקסט גלוי.
  • service password-encryption הוא הצפנה חלשה (Type 7) — לא סומכים עליה.
  • לכבות: CDP לכיוון רשתות לא מהימנות, HTTP server, DNS lookup אקראי, פורטים לא בשימוש (shutdown).
  • + /TACACS: אימות מול במקום סיסמאות מקומיות משותפות.
הגדרה מעשית (CLI)
R(config)# hostname CORE-SW1
R(config)# ip domain-name lab.local
R(config)# crypto key generate rsa modulus 2048
R(config)# ip ssh version 2
R(config)# username admin privilege 15 secret Str0ng!Pass
R(config)# enable secret Str0ng!Enable
R(config)# line vty 0 15
R(config-line)# transport input ssh
R(config-line)# login local
R(config-line)# exec-timeout 5 0
R(config)# no ip http server
R(config)# no ip http secure-server
R(config)# banner motd #Authorized access only#
R(config)# logging host 192.168.10.50
R(config)# ntp server 192.168.10.10
R(config)# interface range gi0/21-23
R(config-if-range)# shutdown
R# copy running-config startup-config
bash
תרחישי אמת בארגון
  • כל ציוד הרשת שולח syslog לשרת מרכזי / — בלי זה אין חקירת אירועים.
  • גישת ניהול רק מ־VLAN ניהול ייעודי ודרך Jump Server.
  • התחברות מנהלים עם חשבון אישי דרך / — יש תיעוד מי עשה מה.
  • גיבוי קונפיגורציות אוטומטי לפני כל שינוי.
אבחון ופתרון תקלות
R# show ip ssh
R# show users
R# show running-config | include username|enable|transport
R# show logging
R# show version              ! uptime, IOS version
R# show inventory
bash
  • SSH לא עולה → חסר domain-name או מפתח RSA; ה־modulus חייב 768 ומעלה (מומלץ 2048).
  • התחברות נדחית → line vty ללא login local או ללא username מקומי.
  • 'איבדנו את הקונפיג אחרי אתחול' → לא בוצע copy running-config startup-config.
  • אין לוגים בשרת → בדוק logging host, קישוריות UDP 514 ושעון NTP.
מילון מונחים ושורת פקודות מהירה
  • SSH: hostname + ip domain-name + crypto key generate rsa + ip ssh version 2
  • enable secret (חזק) ולא enable password
  • transport input ssh — סוגר Telnet
  • copy run start / write memory — לשמור!

בדוק את עצמך

מה עושה מצב violation restrict?

מה חייבים להגדיר לפני יצירת מפתח RSA ל־SSH?

העמוד הזה עזר לך?