30 April 2013

How to generate TCP traffic to/from a Cisco router

Found a nifty hidden command on Cisco IOS routers that generates TCP traffic from router to router.

TTCP Receiver
To setup a server to accept a connection do the following on a router:

R2#ttcp receive
ttcp-r: buflen=8192, align=16384/0, port=5001
rcvwndsize=4128, delayedack=yes  tcp
ttcp-r: accept from 10.2.1.2 (mss 536, sndwnd 4128, rcvwnd 3592)
ttcp-r: 16777216 bytes in 1296360 ms (1296.360 real seconds) (~11 kB/s) +++
ttcp-r: 32293 I/O calls
ttcp-r: 0 sleeps (0 ms total) (0 ms average)

TTCP Transmitter
To initiate a connection do the following on a second router:

R6#ttcp tran 2.2.2.2
ttcp-t: buflen=8192, nbuf=2048, align=16384/0, port=5001  tcp  -> 2.2.2.2
ttcp-t: connect (mss 536, sndwnd 4128, rcvwnd 4128)
ttcp-t: 16777216 bytes in 1296140 ms (1296.140 real seconds) (~11 kB/s) +++
ttcp-t: 2048 I/O calls
ttcp-t: 0 sleeps (0 ms total) (0 ms average)

You can just use TTCP command by itself to access more specific configuration options (change port/etc).

R2#ttcp
transmit or receive [receive]:
perform tcp half close [n]:
receive buflen [8192]:
bufalign [16384]:
bufoffset [0]:
port [5001]:
sinkmode [y]:
rcvwndsize [4128]:
delayed ACK [y]:
show tcp information at end [n]:

To quit the connection you do the “Ctrl+Shift+6, X” break sequence and you get the following:

ttcp-t: buflen=8192, nbuf=2048, align=16384/0, port=5002  tcp  -> 3.3.3.3
ttcp-t: connect (mss 536, sndwnd 4128, rcvwnd 4128)
ttcp-t: 16777216 bytes in 1415708 ms (1415.708 real seconds) (~10 kB/s) +++
ttcp-t: 2048 I/O calls
ttcp-t: 0 sleeps (0 ms total) (0 ms average)

The rate is presented in Bytes per second…  so to get bits per second :

(Total bytes transmitted * 8) / Total Seconds = bits per second.

Summary
This was very handy in a virtual lab when trying to generate traffic matching QoS marking/scheduling policy. Throughput-wise I’ve been able to generate around 450Kbps in the virtual lab which is good enough for my situation/testing. Since it is pretty raw you have to figure out optimal TCP sliding window sizes in order to congest links with more latency. This is more of a consideration for doing it on live routers with some real distance between them (i.e. RTT higher than 50ms). 

You can also configure a PC to be a receiver/transmitter as well but I haven't tried this. I believe there is an application you can get from Cisco's download page.

29 January 2013

Setting up SecureCRT - Change Default Appearance + Auto-create Log File On Connect

This is just a collection of convenient settings I've found elsewhere on the Internet. SecureCRT is a nice little piece of software to have in sitting on your laptop to connect to console/Telnet/SSH sessions you frequent/etc. Some of the settings I'd prefer to change from the default, mainly around appearance and with it not automatically creating a log file on connect.

Change Default Appearance
To change the default colour theme do the following:

  1. Go to Options > Global Options
  2. Under General > Default Session on left
  3. Click Edit Default Settings
  4. Navigate to Appearance in left pane
  5. Select the desired Color Theme in the drop down box
Turn on Auto-Create Log with Automatic Log File Name
To setup SecureCRT to log everything (trust me, it's useful from time to time)... pretty much follow the first 3 steps above then:
  1. Navigate to Log File in left pane
  2. Under the Log File Name entry box, type in the path and name of the log file to use. For me I said the following: "C:\Console Logs\%Y-%M-%D.%h:%m - %H -- %S.txt"
The % variables are all listed in the help file as follows:
  • %H - hostname
  • %S - session name
  • %Y - four-digit year
  • %M - two-digit month
  • %D - two-digit day of the month
  • %h - two-digit hour
  • %m - two-digit minute
  • %s - two-digit seconds
  • %t - three-digit milliseconds
  • %% - percent (%)
  • %envvar% - environment variable
Thanks for reading. Hope it helps.

23 November 2012

Cisco ASA: Anyconnect - How to source how many users and which users are logged in via Anyconnect?

With standard IPSEC/ISAKMP I am used to running "show crypto isa sa detail" style commands to figure out how many and who is logged into a client VPN session. With AnyConnect the above commands don't work. As AnyConnect is typically configured as a SSL VPN client, you have to use a different set of commands to troubleshoot. The below is for the Cisco ASA product set... there should be something similar for IOS devices.


FW01# show vpn-sessiondb anyconnect 
Session Type: AnyConnect
Username     : bob                Index        : 71
Assigned IP  : 10.0.1.1            Public IP    : x.x.x.x
Protocol     : AnyConnect-Parent SSL-Tunnel
License      : AnyConnect Essentials
Encryption   : RC4                    Hashing      : none SHA1
Bytes Tx     : 399272098              Bytes Rx     : 10860313
Group Policy : VPN_CLIENT_POLICY      Tunnel Group : VPN
Login Time   : 09:04:59 EST Fri Nov 23 2012
Duration     : 7h:02m:46s
Inactivity   : 0h:00m:00s
NAC Result   : Unknown
VLAN Mapping : N/A                    VLAN         : none
[...]
The above shows all active users logged into the SSL VPN client. You get their username, public IP and mapped VPN IP as well as the encryption mechanisms used. Pretty handy.

If you are just after an overview of how many users are connected the below is a good starting point. For the below I had 3 active VPN tunnels in use below.


FW01# show vpn-sessiondb          
---------------------------------------------------------------------------
VPN Session Summary                                                      
---------------------------------------------------------------------------
                               Active : Cumulative : Peak Concur : Inactive
                             ----------------------------------------------
AnyConnect Client            :      3 :         20 :           4 :        0
  SSL/TLS/DTLS               :      3 :         20 :           4 :        0
Clientless VPN               :      0 :          4 :           1
  Browser                    :      0 :          4 :           1
---------------------------------------------------------------------------
Total Active and Inactive    :      3             Total Cumulative :     24
Device Total VPN Capacity    :    250
Device Load                  :     1%
---------------------------------------------------------------------------
---------------------------------------------------------------------------
Tunnels Summary
---------------------------------------------------------------------------
                               Active : Cumulative : Peak Concurrent  
                             ----------------------------------------------
Clientless                   :      0 :          7 :               2
AnyConnect-Parent            :      3 :         17 :               4
SSL-Tunnel                   :      3 :         22 :               4
---------------------------------------------------------------------------
Totals                       :      6 :         46
---------------------------------------------------------------------------
 Hope this helps someone. Thanks for reading.