




已阅读5页,还剩26页未读, 继续免费阅读
版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
CiscoDeviceHardening,DisablingUnusedCiscoRouterNetworkServicesandInterfaces,VulnerableRouterServicesandInterfaces,VulnerableRouterServicesandInterfaces,CiscoIOSrouterscanbeusedas:EdgedevicesFirewallsInternalroutersDefaultservicesthatcreatepotentialvulnerabilities(e.g.,BOOTP,CDP,FTP,TFTP,NTP,Finger,SNMP,TCP/UDPminorservices,IPsourcerouting,andproxyARP).Vulnerabilitiescanbeexploitedindependentlyoftherouterplacement.,VulnerableRouterServices,Disableunnecessaryservicesandinterfaces(BOOTP,CDP,FTP,TFTP,NTP,PAD,andTCP/UDPminorservices)Disablecommonlyconfiguredmanagementservices(SNMP,HTTP,andDNS)Ensurepathintegrity(ICMPredirectsandIPsourcerouting)Disableprobesandscans(finger,ICMPunreachables,andICMPmaskreplies)Ensureterminalaccesssecurity(identandTCPkeepalives)DisablegratuitousandproxyARPDisableIPdirectedbroadcast,RouterHardeningConsiderations,Attackerscanexploitunusedrouterservicesandinterfaces.Administratorsdonotneedtoknowhowtoexploittheservices,buttheyshouldknowhowtodisablethem.Itistedioustodisabletheservicesindividually.Anautomatedmethodisneededtospeedupthehardeningprocess.,LockingDownRouterswithAutoSecure,WhatisAutoSecure?,AutoSecurehelpssecureCiscoIOSnetworksbyperformingtheserouterfunctions:DisablesinsecureglobalservicesEnablessecurity-basedglobalservicesDisablesinsecureinterfaceservicesEnablesappropriatesecurityloggingSecuresrouteradministrativeaccessSecurestheroutermanagementplaneSecurestherouterforwardingplane,AutoSecureOperationModes,AutoSecurecanbedeployedusingoneofthefollowingtwomodesofoperation:Interactivemode:Promptstheuserwithoptionstoenableanddisableservicesandothersecurity-relatedfeaturesNoninteractivemode:Automaticallyexecutestheautosecurecommandusingrecommendeddefaultsettings,AutoSecureFunctions,AutoSecurecanselectivelylockdown:Managementplaneservicesandfunctions:Finger,PAD,UDP&TCPsmallservers,passwordencryption,TCPkeepalives,CDP,BOOTP,HTTP,sourcerouting,gratuitousARP,proxyARP,ICMP(redirects,mask-replies),directedbroadcast,MOP,bannerAlsoprovidespasswordsecurityandSSHaccessForwardingplaneservicesandfunctions:CEF,trafficfilteringwithACLsFirewallservicesandfunctions:CiscoIOSFirewallinspectionforcommonprotocolsLoginfunctions:PasswordsecurityNTPprotocolSSHaccessTCPInterceptservices,AutoSecureFailureScenarios,IfAutoSecurefailstocompleteitsoperation,yourrunningconfigurationmaybecorrupt:In12.3(8)TandlaterreleasesPre-autosecureconfigurationsnapshotisstoredintheflashunderfilenamepre_autosec.cfgRoll-backrevertstheroutertoitspre-autosecureconfigurationCommand:configurereplaceflash:pre_autosec.cfgPriorto12.3(8)T,youshouldsavetherunningconfigurationbeforerunningAutoSecure,AutoSecureProcessOverview,AutoSecureProcessOverview,autosecuremanagement|forwardingno-interact|fullntp|login|ssh|firewall|tcp-intercept,router#,LaunchesAutoSecureMainstepswiththeinteractivefulloption:Identifyoutsideinterfaces.Securethemanagementplane.Createsecuritybanner.Configurepasswords,AAA,andSSH.Securetheinterfacesettings.Securetheforwardingplane.,StartandInterfaceSelection,Router#autosecure-AutoSecureConfiguration-*AutoSecureconfigurationenhancesthesecurityoftherouterbutitwillnotmakerouterabsolutelysecurefromallsecurityattacks*AlltheconfigurationdoneaspartofAutoSecurewillbeshownhere.Formoredetailsofwhyandhowthisconfigurationisuseful,andanypossiblesideeffects,pleaserefertoCiscodocumentationofAutoSecure.Atanypromptyoumayenter?forhelp.Usectrl-ctoabortthissessionatanyprompt.GatheringinformationabouttherouterforAutoSecureIsthisrouterconnectedtointernet?no:yEnterthenumberofinterfacesfacinginternet1:1InterfaceIP-AddressOK?MethodStatusProtocolEthernet0/0YESNVRAMupupEthernet0/1YESNVRAMupupEntertheinterfacenamethatisfacinginternet:Ethernet0/1,SecuringManagementPlaneServices,SecuringManagementplaneservices.DisablingservicefingerDisablingservicepadDisablingudp&tcpsmallserversEnablingservicepasswordencryptionEnablingservicetcp-keepalives-inEnablingservicetcp-keepalives-outDisablingthecdpprotocolDisablingthebootpserverDisablingthehttpserverDisablingthefingerserviceDisablingsourceroutingDisablinggratuitousarp,CreatingSecurityBanner,HereisasampleSecurityBannertobeshownateveryaccesstodevice.Modifyittosuityourenterpriserequirements.AuthorisedAccessonlyThissystemisthepropertyofSo-&-So-Enterprise.UNAUTHORISEDACCESSTOTHISDEVICEISPROHIBITED.Youmusthaveexplicitpermissiontoaccessthisdevice.Allactivitiesperformedonthisdeviceareloggedandviolationsofofthispolicyresultindisciplinaryaction.EnterthesecuritybannerPutthebannerbetweenkandk,wherekisanycharacter:%ThissystemisthepropertyofCiscoSystems,Inc.UNAUTHORIZEDACCESSTOTHISDEVICEISPROHIBITED.%,PasswordsandAAA,EnablesecretiseithernotconfiguredorissameasenablepasswordEnterthenewenablesecret:Curium96ConfigurationoflocaluserdatabaseEntertheusername:student1Enterthepassword:student1ConfiguringaaalocalauthenticationConfiguringconsole,Auxandvtylinesforlocalauthentication,exec-timeout,transportSecuringdeviceagainstLoginAttacksConfigurethefollowingparametersBlockingPeriodwhenLoginAttackdetected:300MaximumLoginfailureswiththedevice:3Maximumtimeperiodforcrossingthefailedloginattempts:60,SSHandInterface-SpecificServices,ConfigureSSHserver?yes:yEnterthehostname:R2Enterthedomain-name:ConfiguringinterfacespecificAutoSecureservicesDisablingthefollowingipservicesonallinterfaces:noipredirectsnoipproxy-arpnoipunreachablesnoipdirected-broadcastnoipmask-replyDisablingmoponEthernetinterfaces,ForwardingPlane,VerificatonandDeployment,SecuringForwardingplaneservices.EnablingCEF(Thismightimpactthememoryrequirementsforyourplatform)EnablingunicastrpfonallinterfacesconnectedtointernetConfigureCBACFirewallfeature?yes/no:yesThisistheconfigurationgenerated:noservicefingernoservicepadnoserviceudp-small-serversnoservicetcp-small-serversservicepassword-encryption.Applythisconfigurationtorunning-config?yes:y,LockingDownRouterswiththeSDM,SecurityDeviceManager,SDMautomatedhardeningfeatures:SecurityAuditOne-StepLockdown,SDMSecurityAuditOverview,Thesecurityauditcomparesrouterconfigurationagainstrecommendedsettings.Examplesoftheauditinclude:Shutdownunneededservers.Disableunneededservices.Applythefirewalltotheoutsideinterfaces.DisableorhardenSNMP.Shutdownunusedinterfaces.Checkpasswordstrength.EnforcetheuseofACLs.,SDMSecurityAudit:MainWindow,1.,2.,3.,SDMSecurityAuditWizard,SDMSecurityAuditInterfaceConfiguration,SDMSecurityAudit,SDMSecurityAudit:F
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 个人消费分期还款合同范本
- 人力资源公司劳务合作合同模板
- 采购地源热泵的合同模板
- 小学信息技术第三册 学生机器人1选修教学设计 苏科版
- 小学数学人教版(2024)五年级上册一个数除以小数获奖教学设计及反思
- 专卖店合同样本集萃
- 供应链合同廉洁合作承诺书
- 小学数学北师大版三年级下册分一分(二)第4课时教学设计
- 2024年04月浙江丽水市遂昌县卫生健康局下属事业单位招聘卫生专技人员32人笔试历年专业考点(难、易错点)附带答案详解
- 2024年04月河南省鹤壁市事业单位联考招聘275人笔试历年专业考点(难、易错点)附带答案详解
- 社会福利 课件汇 高和荣 第1-5章 绪论- 社会福利主体
- 治疗室换药室消毒管理制度
- 2025版轮胎进出口贸易与代理服务合同范本4篇
- 2024年开封大学高职单招职业技能测验历年参考题库(频考版)含答案解析
- 危险化学品购销的合同范本
- 实时荧光聚合酶链反应临床实验室应用指南(WST-230-2024)
- 口腔医院市场营销新入职员工培训
- 瑞幸咖啡副店长认证考试题库
- 2024年生鲜配送与城市社区团购合作框架协议3篇
- 2024年出版专业资格考试《出版专业基础知识》中级真题及答案
- 大语言模型基础微课版课件 第7章 提示工程与微调
评论
0/150
提交评论