CPE Configurations: Presented by Salman Zia/DM-CC
CPE Configurations: Presented by Salman Zia/DM-CC
CPE Configurations: Presented by Salman Zia/DM-CC
• Certifications
– Cisco
• CCNP R&S
• CCNA R&S
Objective
• CPE Concepts
• PPPoE Configurations
• MAC Address Filtering
• WiFi Configurations
Course content
1. CPE
2. Common Terms Used in CPE Configurations
3. Accessing CPEs
4. PPPoE Configurations
5. Wi-Fi Configurations
6. Configuring Router as an Access Point
7. MAC Address Filtering
What is CPE?
• Refers to equipment at customer end
– Includes telephones, routers, switches, or purchased
set-top boxes for use with Communications Service
Providers' services
– Ownership
NAYAtel CPE Examples
– TP-Link
• 740N/1043ND/Archer C7/EC 120/Archer C2
– Alcatel GPON
• I221E / I241WS
– Huawei GPON
• HG8247 / HG8247H/EG 8247H5/EG8147X6
– HD Box/Joy Box
– STB
– ATAs
Common Terms Used in CPE
Configurations
NAT stands for network address translation. It’s a way to map multiple local private
addresses to a public one before transferring the information. Organizations that want
multiple devices to employ a single IP address use NAT, as do most home routers.
Ports and Applications
A TCP/UDP port identifies an application/service on a machine in a TCP/IP network. On a
TCP/IP network every device must have an IP address. The IP address identifies the
device. However a device can run multiple applications/services. The port identifies the
application/service running on the machine
Ports 0-1023
Well-known ports
For system processes
Ports 1024-49151
Registered port: for use with a certain protocol/application
Given by IANA
Ports >49151
Dynamic / Private ports
TCP vs UDP
Ports and Applications
Some important ports are:
• Port forwarding or port mapping is a name given to the combined technique of:
• DHCP is a client-server protocol that uses DHCP servers and DHCP clients.
• A DHCP server is a machine that runs a service that can lease out IP addresses and
other TCP/IP information to any client that requests them.
• This includes subnet mask information, default gateway IP addresses and domain
name system (DNS) addresses.
• The DHCP server typically has a pool of IP addresses that it is allowed to distribute to
clients, and these clients lease an IP address from the pool for a specific period of
time, usually several days.
• Once the lease is ready to expire, the client contacts the server to arrange for
renewal.
DHCP Handshake Process
Firewall
WEP:
It stands for Wired Equivalent Privacy introduced in 1999. The key length for WEP is 10
characters for 40/64-bit and 26 characters for 128-bit. WEP’s main flaw is that it uses
static encryption keys. It was revised on number of occasion but still over time numerous
security flaws were discovered in the WEP standard. As early as 2001 proof-of-concept
exploits were floating around and by 2005 the FBI gave a public demonstration (in an
effort to increase awareness of WEP’s weaknesses) where they cracked WEP passwords
in minutes using freely available software. The Wi-Fi Alliance officially retired WEP in
2004
Wireless Security
WPA: It stands for Wi-Fi Protected Access and introduced as replacement for WEP. The
key length used is between 8-63 characters. It uses TKIP encryption method. Over time,
TKIP was found to be flawed and to overcome this, WPA2 was introduced.
WPA2: It uses Advanced Encryption Standard (AES) for encryption instead of TKIP. The
key length used is between 8-63 characters which is same as WPA. To make WPA2
backward compatible, it also has the option to use TKIP. WPA2-AES should be used on all
devices as it is the most secure method available
WPA3: WPA3 provides improvements to the general Wi-Fi encryption, using Simultaneous
Authentication of Equals (SAE). This allows for better functionality so WPA3-Personal
networks with simple passphrases aren’t so simple for hackers to crack using off-site,
brute-force, dictionary-based cracking attempts like it was with WPA/WPA2. The key
length used is 128-bit encryption in WPA3-Personal mode.The encryption with WPA3-
Personal is more individualized. Users on a WPA3-Personal network can’t ever snoop on
another’s WPA3-Personal traffic, even when the user has the Wi-Fi password and is
successfully connected.
Accessing CPEs
• GUI
– LAN/WLAN
– WAN
• Telnet
CPE Configurations
– PPPoE
– Wi-Fi
– Router as an Access Point
– MAC Address Filtering
Nayatel N-Doctor
• N Doctor App is used to troubleshoot
issues related to Wi Fi.