ISCW10S05L02关闭不需要服务.ppt_第1页
ISCW10S05L02关闭不需要服务.ppt_第2页
ISCW10S05L02关闭不需要服务.ppt_第3页
ISCW10S05L02关闭不需要服务.ppt_第4页
ISCW10S05L02关闭不需要服务.ppt_第5页
已阅读5页,还剩26页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

CiscoDeviceHardening,DisablingUnusedCiscoRouterNetworkServicesandInterfaces,VulnerableRouterServicesandInterfaces,VulnerableRouterServicesandInterfaces,CiscoIOSrouterscanbeusedas:EdgedevicesFirewallsInternalroutersDefaultservicesthatcreatepotentialvulnerabilities(e.g.,BOOTP,CDP,FTP,TFTP,NTP,Finger,SNMP,TCP/UDPminorservices,IPsourcerouting,andproxyARP).Vulnerabilitiescanbeexploitedindependentlyoftherouterplacement.,VulnerableRouterServices,Disableunnecessaryservicesandinterfaces(BOOTP,CDP,FTP,TFTP,NTP,PAD,andTCP/UDPminorservices)Disablecommonlyconfiguredmanagementservices(SNMP,HTTP,andDNS)Ensurepathintegrity(ICMPredirectsandIPsourcerouting)Disableprobesandscans(finger,ICMPunreachables,andICMPmaskreplies)Ensureterminalaccesssecurity(identandTCPkeepalives)DisablegratuitousandproxyARPDisableIPdirectedbroadcast,RouterHardeningConsiderations,Attackerscanexploitunusedrouterservicesandinterfaces.Administratorsdonotneedtoknowhowtoexploittheservices,buttheyshouldknowhowtodisablethem.Itistedioustodisabletheservicesindividually.Anautomatedmethodisneededtospeedupthehardeningprocess.,LockingDownRouterswithAutoSecure,WhatisAutoSecure?,AutoSecurehelpssecureCiscoIOSnetworksbyperformingtheserouterfunctions:DisablesinsecureglobalservicesEnablessecurity-basedglobalservicesDisablesinsecureinterfaceservicesEnablesappropriatesecurityloggingSecuresrouteradministrativeaccessSecurestheroutermanagementplaneSecurestherouterforwardingplane,AutoSecureOperationModes,AutoSecurecanbedeployedusingoneofthefollowingtwomodesofoperation:Interactivemode:Promptstheuserwithoptionstoenableanddisableservicesandothersecurity-relatedfeaturesNoninteractivemode:Automaticallyexecutestheautosecurecommandusingrecommendeddefaultsettings,AutoSecureFunctions,AutoSecurecanselectivelylockdown:Managementplaneservicesandfunctions:Finger,PAD,UDP&TCPsmallservers,passwordencryption,TCPkeepalives,CDP,BOOTP,HTTP,sourcerouting,gratuitousARP,proxyARP,ICMP(redirects,mask-replies),directedbroadcast,MOP,bannerAlsoprovidespasswordsecurityandSSHaccessForwardingplaneservicesandfunctions:CEF,trafficfilteringwithACLsFirewallservicesandfunctions:CiscoIOSFirewallinspectionforcommonprotocolsLoginfunctions:PasswordsecurityNTPprotocolSSHaccessTCPInterceptservices,AutoSecureFailureScenarios,IfAutoSecurefailstocompleteitsoperation,yourrunningconfigurationmaybecorrupt:In12.3(8)TandlaterreleasesPre-autosecureconfigurationsnapshotisstoredintheflashunderfilenamepre_autosec.cfgRoll-backrevertstheroutertoitspre-autosecureconfigurationCommand:configurereplaceflash:pre_autosec.cfgPriorto12.3(8)T,youshouldsavetherunningconfigurationbeforerunningAutoSecure,AutoSecureProcessOverview,AutoSecureProcessOverview,autosecuremanagement|forwardingno-interact|fullntp|login|ssh|firewall|tcp-intercept,router#,LaunchesAutoSecureMainstepswiththeinteractivefulloption:Identifyoutsideinterfaces.Securethemanagementplane.Createsecuritybanner.Configurepasswords,AAA,andSSH.Securetheinterfacesettings.Securetheforwardingplane.,StartandInterfaceSelection,Router#autosecure-AutoSecureConfiguration-*AutoSecureconfigurationenhancesthesecurityoftherouterbutitwillnotmakerouterabsolutelysecurefromallsecurityattacks*AlltheconfigurationdoneaspartofAutoSecurewillbeshownhere.Formoredetailsofwhyandhowthisconfigurationisuseful,andanypossiblesideeffects,pleaserefertoCiscodocumentationofAutoSecure.Atanypromptyoumayenter?forhelp.Usectrl-ctoabortthissessionatanyprompt.GatheringinformationabouttherouterforAutoSecureIsthisrouterconnectedtointernet?no:yEnterthenumberofinterfacesfacinginternet1:1InterfaceIP-AddressOK?MethodStatusProtocolEthernet0/0YESNVRAMupupEthernet0/1YESNVRAMupupEntertheinterfacenamethatisfacinginternet:Ethernet0/1,SecuringManagementPlaneServices,SecuringManagementplaneservices.DisablingservicefingerDisablingservicepadDisablingudp&tcpsmallserversEnablingservicepasswordencryptionEnablingservicetcp-keepalives-inEnablingservicetcp-keepalives-outDisablingthecdpprotocolDisablingthebootpserverDisablingthehttpserverDisablingthefingerserviceDisablingsourceroutingDisablinggratuitousarp,CreatingSecurityBanner,HereisasampleSecurityBannertobeshownateveryaccesstodevice.Modifyittosuityourenterpriserequirements.AuthorisedAccessonlyThissystemisthepropertyofSo-&-So-Enterprise.UNAUTHORISEDACCESSTOTHISDEVICEISPROHIBITED.Youmusthaveexplicitpermissiontoaccessthisdevice.Allactivitiesperformedonthisdeviceareloggedandviolationsofofthispolicyresultindisciplinaryaction.EnterthesecuritybannerPutthebannerbetweenkandk,wherekisanycharacter:%ThissystemisthepropertyofCiscoSystems,Inc.UNAUTHORIZEDACCESSTOTHISDEVICEISPROHIBITED.%,PasswordsandAAA,EnablesecretiseithernotconfiguredorissameasenablepasswordEnterthenewenablesecret:Curium96ConfigurationoflocaluserdatabaseEntertheusername:student1Enterthepassword:student1ConfiguringaaalocalauthenticationConfiguringconsole,Auxandvtylinesforlocalauthentication,exec-timeout,transportSecuringdeviceagainstLoginAttacksConfigurethefollowingparametersBlockingPeriodwhenLoginAttackdetected:300MaximumLoginfailureswiththedevice:3Maximumtimeperiodforcrossingthefailedloginattempts:60,SSHandInterface-SpecificServices,ConfigureSSHserver?yes:yEnterthehostname:R2Enterthedomain-name:ConfiguringinterfacespecificAutoSecureservicesDisablingthefollowingipservicesonallinterfaces:noipredirectsnoipproxy-arpnoipunreachablesnoipdirected-broadcastnoipmask-replyDisablingmoponEthernetinterfaces,ForwardingPlane,VerificatonandDeployment,SecuringForwardingplaneservices.EnablingCEF(Thismightimpactthememoryrequirementsforyourplatform)EnablingunicastrpfonallinterfacesconnectedtointernetConfigureCBACFirewallfeature?yes/no:yesThisistheconfigurationgenerated:noservicefingernoservicepadnoserviceudp-small-serversnoservicetcp-small-serversservicepassword-encryption.Applythisconfigurationtorunning-config?yes:y,LockingDownRouterswiththeSDM,SecurityDeviceManager,SDMautomatedhardeningfeatures:SecurityAuditOne-StepLockdown,SDMSecurityAuditOverview,Thesecurityauditcomparesrouterconfigurationagainstrecommendedsettings.Examplesoftheauditinclude:Shutdownunneededservers.Disableunneededservices.Applythefirewalltotheoutsideinterfaces.DisableorhardenSNMP.Shutdownunusedinterfaces.Checkpasswordstrength.EnforcetheuseofACLs.,SDMSecurityAudit:MainWindow,1.,2.,3.,SDMSecurityAuditWizard,SDMSecurityAuditInterfaceConfiguration,SDMSecurityAudit,SDMSecurityAudit:F

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论