Saturday, February 3, 2024

mac securecrt send cisco break to rommon

 in securecrt configure session with VT220 keyboard mapping and press F5 continuously when the router boots.

Wednesday, January 31, 2024

OpenWRT linksys with TC and NETEM

 

install openwrt on e4200v2 

Open ssh and http on the WAN (disable firewall)

Via GUI of openwrt (LuCi) install tc-full and kmod-netem

Inject some delay:

tc qdisc add dev internet root netem delay 10ms

Disable delay:

tc qdisc del dev internet root

tc -s qdisc ls dev internet

Sunday, January 7, 2024

vmware esxi letsencrypt certificate

 Good info on how to install ssl certificate on esxi

(note that I run 6.5 which only seems to work with w2c 1.0.0)

https://github.com/w2c/letsencrypt-esxi/wiki/Installation-via-Web-UI

https://www.it-connect.fr/vmware-esxi-lets-encrypt-la-solution-pour-obtenir-un-certificat-ssl-gratuit/

Wednesday, August 23, 2023

Defining traffic in Ostinato 

The following only applies if you are sending unidirectional traffic and don't care about the traffic not returning. 
 
When you don't resolve the MAC layer (ARP), then there's no need to define devices. Just add streams and in "Protocol Data", open "Media Access Protocol" and make destination the next hop mac (ip neigh show) and source as increment to simulate MAC addresses


Now add the IPv4 IPs


and make sure that the number of packets sent is the same as your source amount





Thursday, June 22, 2023

 

NAT



symmetric NAT = Dynamic PAT (Cisco FWs)

 ASA Firewall allow traceroute


access-list outside_acl_in extended permit icmp any any time-exceeded
access-list outside_acl_in extended permit icmp any any unreachable
!
access-group outside_acl_in in interface outside

!
policy-map global_policy
 class inspection_default
  inspect icmp
  inspect icmp error

Friday, September 16, 2022

 

EVE-NG gateway via Cloud0 not reachable    


If a ping to a gateway outside of vmware doesn't work and you're sure that the promiscuous/forged mode in the virtual switch in vSphere is configured correctly, i.e.

router10.0.35.20---Cloud0-EVENG10.0.35.5-----LABSWITCH---LABROUTER(Arista with virtual-router 10.0.35.1)

Router#show arp
Protocol  Address          Age (min)  Hardware Addr   Type   Interface
Internet  10.0.35.19              -   aabb.cc00.3d00  ARPA   Ethernet0/0
Router#ping 10.0.35.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.0.35.1, timeout is 2 seconds:
.....
Success rate is 0 percent (0/5)

ping from router to 10.0.35.1 doesn't work then do a ping towards the real IP 10.0.35.3.

Router#ping 10.0.35.3
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.0.35.3, timeout is 2 seconds:
.!!!!

This will populate the ARP table on the router with 10.0.35.1 also for some reaso

Router#show arp
Protocol  Address          Age (min)  Hardware Addr   Type   Interface
Internet  10.0.35.1               0   001c.7300.0099  ARPA   Ethernet0/0
Internet  10.0.35.3               0   444c.a869.07dd  ARPA   Ethernet0/0
Internet  10.0.35.19              -   aabb.cc00.3d00  ARPA   Ethernet0/0


and then ping to 10.0.35.1 will work

Router#ping 10.0.35.1 
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.0.35.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms

YAML Files for ESP32

 Gree Versati III https://gist.github.com/slanckma/3bad4ff49545488a3719766bdf0cdc76 TUF-2000M Water flow sensor https://gist.github.com/slan...