38 Network Mapping – Zenmap Basics
Jacob Christensen; Arjun Nath; and Isha Patel
Network mapping is a critical component of defending enterprise networks. After all, you can’t protect services and devices if you don’t know they are there. Network topology mapping provides information on switches, routers, firewalls, hubs, access points, and end devices. Network mapping has the added benefit of providing insights into traffic flow and network connections, and greatly accelerates troubleshooting network issues.
In this lab, we will use Zenmap to create network topology and run a few network scans to better understand our network.
Learning Objectives
- Learn how to use networking mapping tools to identify live hosts
- Demonstrate how to scan for open ports and identify active services
- Learn how to detect port scans on your network
prerequisites
- Chapter 25 – DNS Part 3
- Chapter 7 – Create a Linux Server
- Chapter 5 – Installing Tiny Core Linux
- Chapter 12 – Create a Kali Linux VM
deliverables
- Screenshot of Zenmap host information
- Screenshot of active ports and running services
- Screenshot of Zenmap’s generated network topology
resources
- N/A
contributors
- Kyle Wheaton, Cybersecurity Student, ERAU-Prescott
- Jungsoo Noh, Cybersecurity Student, ERAU-Prescott
Phase I – Building the Network Topology
The following steps are to create a baseline network for completing this chapter. It makes assumptions about learner knowledge from completing previous labs.
By the end of this lab, your network should look like the following:
- Start GNS3
- Create a new project: LAB_21
NOTE: This lab takes heavy influence from the chapter Domain Name System Part 3 – Dynamic DNS. It is recommended to save that file as a new project and make adjustments to the network as necessary.
- Create a new project: LAB_21
- Build a new LAN with the network address space <IP_ADDRESS>/24
- Use three Tiny Core Linux devices to act as clients
- Add an Ethernet switch
- Add a Kali Linux box to act as the network’s IT administrative laptop
- Connect the LAN to ether3 on a MikroTik router
- On the ether2 of the router, add an Ubuntu Server to act as the network’s DMZ using the network address space of <IP_ADDRESS>/24
- On ether1, add a NAT cloud node to give the network internet connectivity
- Configure the Ubuntu server to host several daemons for the internal LAN
NOTE: Remember to ensure that each service is running and active:
> systemctl status <daemon_name>
Start the services if necessary:
> systemctl start <daemon_name>
- DHCP: isc-dhcp-server.service
- Dynamic DNS: named.service
- Web server: apache2.service
NOTE: No configuration is necessary. Just ensure that the default service is active. This can be verified on the Kali machine by typing the URL http://<IP_ADDRESS>:80 in a Firefox browser. You should see the following default webpage.
- SSH: sshd.service
NOTE: Again, no configuration is necessary. Just ensure that the service is active and running.
- Label and organize