Vault7: CIA Hacking Tools Revealed
Navigation: » Latest version
Owner: User #14587667
Bumble - Test Notes
6/19/2015
- Installed HP MSR 4080 chassis in Rack 2/Pod 4.
- Installed MPU-100 (x2), and SPU-100 cards into MSR 4080 chassis.
6/23/2015
- Racked and Setup console access for Cisco 2911 and 3845 in Rack 2 to use for Bumble testing.
- Configure E1 cards in 2911:
HWIC0 (2E1): card type e1 0 0
HWIC1 (1E1): card type e1 0 1
- Configure E1 cards in 2911:
- Created RANCID project for Bumble network devices. Added 2911, 3845.
- Added static route to 10.9.8.0/24
- Setup MSR
- Configure static IP, static route to 10.9.8.0/24, NTPNetwork Time Protocol client
6/24/2015
- Requested POS card and E1 cables (MSR (DB15) <-> Cisco (RJ48C)) from User #73739.
7/10/2015
- Installed 4-port E1 card in MSR
- Racked Cisco 3825 (from old cabinet) and 2811 (from NDBNetwork Devices Branch lab). Configured console server and connected ethernet cables to TOR2 gi1/0/5-6.
- Backed up original 2811 config and connected to network (IP = 172.20.100.226)
7/16/2015
- Configured MSR to Cisco E1 links
7/17/2015
- Configured MSR to Cisco Mutilink ppp lines (3E1).
- Installed 1E1 HWIC into 2811. Upon reboot, the 2811 gives a memory error and will not boot.
7/18/2015
- Installed 2E1 HWIC in 3845. Removed old 1E1 HWIC.
- Configured 4E1 on 3845 (IP = 8.10.1.30) and MSR.
- Determine OSPFOpen Shortest Path First configuration in target config.
osfp 1
import-route direct # Redistribute networks of local active interfaces
import-route static #Redistribute static routes
area 0.0.0.0
network 192.168.168.4 0.0.0.3 #Enable OSPFOpen Shortest Path First on the interface attached to this network
7/30/2015
- Configured SNMPSimple Network Management Protocol on MSR and SolarWinds.
- Configured 3825 (NE40 surrogate).
7/31/2015
- Configured netstream on MSR. Confirmed int gi2/0/0 is being monitored by solardwinds.
- Completed SNMPSimple Network Management Protocol configuration on MSR.
- Configured lo0, 1, and 2 on 3825.
- Configured OSPFOpen Shortest Path First on 3825 and MSR.
ToDo:
ID | Status | Task |
---|---|---|
1 | complete | User #14587667 Get 2800 router from NDBNetwork Devices Branch Lab (R6/U27) |
6 | incomplete | User #14587667 Put 1E1 HWIC in 2800 router |
7 | complete | User #14587667 Setup SNMPSimple Network Management Protocol on solarwinds and configure MSR. |
8 | incomplete | User #14587667 Setup loopbacks on MSR neighbor routes. Use downstream IPs from MSR static routes. |
9 | incomplete | User #14587667 Connect ASRAzure Site Recovery to another router via fiber. |
5 | incomplete | User #14587667 Configure syslog server |
3 | incomplete | User #14587667 Configure OSPFOpen Shortest Path First on MSR |
10 | incomplete | User #14587667 Configure OSPFOpen Shortest Path First on Cisco (Grabe new router and use Gig int for OSPFOpen Shortest Path First - per target config). Use IP 192.168.168.5/30 on MSR and 192.168.168.6 on Cisco. |
2 | incomplete | User #14587667 Configure E1 links |
11 | incomplete | User #14587667 Configure netstream on MSR interface to TRCore (in-/out-bound). |
12 | incomplete | User #14587667 Configure netstream on MSR interface to 2911 (inbound). |
13 | complete | User #14587667 Confirm netflow is being collect by SolarWinds |