• b9b8-最好的免费学习资料站!请记住我们的网址:www.b9b8.com
您当前位置: b9b8学习网文章资讯考试频道计算机考试思科认证路由器安全配置速查表(一)

路由器安全配置速查表(一)

日期:01-23 15:46:02|b9b8学习网| http://www.b9b8.com |思科认证|人气:471

路由器安全配置速查表(一),本站还有更多关于思科认证,思科认证考试,思科认证培训,思科认证网络工程师,思科网络认证,思科认证体系相关的资料。www.b9b8.com

Specific Recommendations: Router Access

1. Shut down unneeded services on the router. Servers that are not running cannot break. Also, more memory and processor slots are available. Start by running the show proc command on the router, then turn off clearly unneeded facilities and services. Some servers that should almost always be turned off and the corresponding commands to disable them are listed below.

Small services (echo, discard, chargen, etc.)
no service tcp-small-servers
no service udp-small-servers
BOOTP - no ip bootp server
Finger - no service finger
HTTP - no ip http server
SNMP - no snmp-server

2. Shut down unneeded services on the routers. These services allow certain packets to pass through the router, or send special packets, or are used for remote router configuration. Some services that should almost always be turned off and the corresponding commands to
disable them are listed below.

CDP - no cdp run
Remote config. - no service config
Source routing - no ip source-route

3. The interfaces on the router can be made more secure by using certain commands in the Configure Interface mode. These commands should be applied to every interface.

Unused interfaces - shutdown
No Smurf attacks - no ip directed-broadcast
Mask replies - no ip mask-reply
Ad-hoc routing - no ip proxy-arp

4. The console line, the auxiliary line and the virtual terminal lines on the router can be made more secure in the Configure Line mode. The console line and the virtual terminal lines should be secured as shown below. The Aux line should be disabled, as shown below, if it is not being used.

Console Line - line con 0
exec-timeout 5 0
login
Auxiliary Line - line aux 0
no exec
exec-timeout 0 10
transport input none
VTY lines - line vty 0 4
exec-timeout 5 0
login
transport input telnet ssh

5. Passwords can be configured more securely as well. Configure the Enable Secret password, which is protected with an MD5-based algorithm. Also, configure passwords for the console line, the auxiliary line and the virtual terminal lines. Provide basic protection for the user and line passwords using the service passwordencryption command. See examples below.

Enable secret - enable secret 0 2manyRt3s
Console Line - line con 0
password Soda-4-jimmY
Auxiliary Line - line aux 0
password Popcorn-4-sara
VTY Lines - line vty 0 4
password Dots-4-georg3
Basic protection - service password-encryption

6. Consider adopting SSH, if your router supports it, for all remote administration. ks.54yjs.cn

7. Protect your router configuration file from unauthorized disclosure.

如果觉得路由器安全配置速查表(一)不错,可以推荐给好友哦。
本文Tags:考试频道 - 计算机考试 - 思科认证,思科认证考试,思科认证培训,思科认证网络工程师,思科网络认证,思科认证体系

+评论

☉本站仅仅提供一个观摩学习的环境,将不对任何资源负法律责任。所有资源请在下载后24小时内删除。如果您觉得满意,请购买正版!

联系本站 - 教案中心 - 试题下载 - 教学反思 - 句子大全 - 收藏本站 - 文章阅读 - 全站地图 - 热门专题