network forensics week 11

For the last week of lecture based class we learned about routers, switches and firewalls.

Switches

  • mas MAC addresses to switch ports
  • locate physical location of MAC
  • contains ARP tables
    • MAC address to IP address resolution
    • location for the ARP request
    • IP address
    • Mac address
    • age from initial ARP request
  • contains CAM tables
    • very fast memory
    • maps mac addresses to physical switch ports
    • very volatile

Routers

  • Network topology
  • traffic throguh the router
  • logged data
  • may be compromised

Firewalls

  • vast logs
    • Connection attempts
    • protocols used
    • application
  • configurable to collect more data

Leave a Comment

Please note: Comment moderation is enabled and may delay your comment. There is no need to resubmit your comment.