Está en la página 1de 3

 

Lab 4
Scenario: cloud-based mitigation

Overview

Description
In this lab we will configure Pravail APS cloud signaling and use it to
protect against volumetric attack.
Protected data center is connected with 2Mbps last mile that can be easily
overwhelmed by a DDoS attack. Your goal is to configure Cloud Signaling
between Pravail APS and cloud-based Peakflow SP/TMS and test Cloud
Signaling operation during a DDoS attack.
For management and monitoring of Pravail APS a separate out-of-band
DCN is used. For Cloud Signaling regular uplink path should be setup.

DCN Cloud Signaling path

mgt1 mgt0
ext0 int0
Internet
2 Mbps
last mile
Pravail APS Victim Web Server

Objectives
After completing this lab, you will be able to do the following: (Tasks)

• Configure cloud signaling


• Test cloud signaling

• Mitigate volumetric attacks with Cloud Signaling support


• Monitor cloud signaling status

Student 31 L4-1
Cloud signaling Lab 4

Equipment/Tools
The following equipment is required to complete this lab:
• web browser
When accessing training labs, you will be prompted for Training Portal
Authentication. Use following credentials:

• Login: student31
• Password: 76obQMem21

Estimated Completion Time


• The estimated completion time for this lab is 30 minutes.

Cloud signaling preparation

Cloud signaling configuration

1. Using web browser log onto your Pravail APS appliance;

2. Navigate to Administration->Cloud Signaling

3. Click “Enable Cloud Signaling”

4. Use 192.168.2.129 as a cloud signaling server.

This setting is typically provided by cloud signaling server operator.

5. Specify PravailAPS31 as a Pravail ID.

This setting is typically provided by cloud signaling server operator.

6. Enter 4g86rhAHxule as Cloud Signaling Password.

This setting is typically provided by cloud signaling server operator.

7. Enter https://sp-cloud.training.arbor.net/ as Management Portal


URL

8. Save your settings

Monitoring and testing cloud signaling


In this task we will look at options for monitoring and testing cloud
signaling

L4-2 Student 31 Pravail APS 5.6


Lab 4 Cloud signaling

1. To check if HTTPS handshake works properly use “Test Connection”


button on cloud signaling configuration page
2. Check cloud widget to see if UDP heartbeats are working properly

Mitigating volumetric attack with cloud signaling support


1. Check that your victim server is responding by navigating to
https://victim-pod31.training.arbor.net/
2. Ask instructor to launch volumetric against victim server
3. Verify that the victim is no longer available
4. Click Activate button on Cloud Signaling Widget of View Protection
Group page or Summary page to request cloud-based mitigation
5. Wait for a minute for routing convergence to complete
6. Once attack is mitigated, check again if web server is responding
7. If you have activated cloud signaling from the Summary page, then
after few minutes check cloud signaling widget status to see volume of
traffic mitigated by Peakflow SP/TMS in the cloud
8. On Cloud Signaling widget, click on Tools drop down menu and select
Management Portal option. Log into Peakflow SP using scoped account
with following credentials:
• User name: student31
• Password: 76obQMem21
9. Click on ongoing mitigation and inspect interface available for MSSP
customer

This completes the lab exercise. Please let instructor know that you’ve
finished the lab and the attack should be now stopped and after
attack is stopped, deactivate cloud signaling request.

Student 31 L4-3

También podría gustarte