Articles

TESTING BUILT-IN SECURITY MECHANISMS OF L2+ NETWORK DEVICES USING NMAP UNDER ACTIVE CONSOLE ACCESS

Download PDF Article on eLIBRARY.RU

Abstract

The article examines the effectiveness of built-in security mechanisms of L2+ network devices under network scanning performed using the nmap utility. The relevance of the study is determined by the widespread use of managed network devices in corporate and educational networks, as well as by the need to minimize the attack surface of management interfaces without deploying additional security tools. Special attention is paid to the analysis of the management plane in the presence of active console access. The purpose of the study is to assess the network accessibility of management services and the state of network ports in the default configuration of network devices from different vendors. The research objects include a MikroTik CRS326-24G-2S+ managed switch and Cisco routers of the 1900 and 800 series. The experimental methodology is based on active network reconnaissance techniques using TCP SYN scanning and on correlating scanning results with actual device configurations obtained via console access. The study shows that in the default configuration the examined devices remain detectable at the IP level but do not expose open remote management services. Management ports are identified as filtered or closed, indicating the operation of built-in traffic filtering and access restriction mechanisms. It is demonstrated that the presence of active console access does not directly affect the results of network scanning. The obtained results confirm the effectiveness of default security configurations in reducing the network attack surface and may be applied in network security assessments as well as in educational and training environments.

Online viewer

References

  1. Компьютерные сети. Принципы, технологии, протоколы : юбилейное издание, доп. и испр. — Санкт-Петербург : Питер, 2024. — 1008 с.
  2. Anderson, R. Security Engineering: A Guide to Building Dependable Distributed Systems / R. Anderson. — 3rd ed. — Indianapolis : Wiley, 2020. — 1182 p.
  3. Использование Nmap для обнаружения сетевых служб и идентификации сервисов [Электронный ресурс]. — URL: https://labex.io/ru/tutorials/nmap-how-to-use-nmap-for-network-discovery-and-service-identification-in-cybersecurity-415099 (дата обращения: 19.11.2025).
  4. Уймин, А. Г. Сетевое и системное администрирование. Демонстрационный экзамен КОД 1.1 : учебно-методическое пособие для СПО / А. Г. Уймин. — 3-е изд., стер. — Санкт-Петербург : Лань, 2022. — 480 с. — ISBN 978-5-8114-9255-8.
  5. Denzler, P. An iterative and toolchain-based approach to automate scanning and mapping computer networks / P. Denzler, R. Teixeira // arXiv.org. — 2017. — URL: https://arxiv.org/abs/1710.01026 (дата обращения: 06.12.2025).
  6. Lyon, G. F. Nmap Network Scanning: The Official Nmap Project Guide to Network Discovery and Security Scanning / G. F. Lyon. — Sunnyvale : Insecure.Com LLC, 2009. — 468 p.
  7. Полное руководство по сетевому сканированию с использованием Nmap [Электронный ресурс]. — URL: https://codeby.net/threads/kniga-po-nmap-na-russkom-polnoye-rukovodstvo-po-setevomu-skanirovaniyu.67190/ (дата обращения: 21.11.2025).

License

Copyright (c) 2025 I. K. Selivanov , D. A. Ledenev (Authors)

Keywords