




已阅读5页,还剩26页未读, 继续免费阅读
版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
CiscoDeviceHardening,DisablingUnusedCiscoRouterNetworkServicesandInterfaces,VulnerableRouterServicesandInterfaces,VulnerableRouterServicesandInterfaces,CiscoIOSrouterscanbeusedas:EdgedevicesFirewallsInternalroutersDefaultservicesthatcreatepotentialvulnerabilities(e.g.,BOOTP,CDP,FTP,TFTP,NTP,Finger,SNMP,TCP/UDPminorservices,IPsourcerouting,andproxyARP).Vulnerabilitiescanbeexploitedindependentlyoftherouterplacement.,VulnerableRouterServices,Disableunnecessaryservicesandinterfaces(BOOTP,CDP,FTP,TFTP,NTP,PAD,andTCP/UDPminorservices)Disablecommonlyconfiguredmanagementservices(SNMP,HTTP,andDNS)Ensurepathintegrity(ICMPredirectsandIPsourcerouting)Disableprobesandscans(finger,ICMPunreachables,andICMPmaskreplies)Ensureterminalaccesssecurity(identandTCPkeepalives)DisablegratuitousandproxyARPDisableIPdirectedbroadcast,RouterHardeningConsiderations,Attackerscanexploitunusedrouterservicesandinterfaces.Administratorsdonotneedtoknowhowtoexploittheservices,buttheyshouldknowhowtodisablethem.Itistedioustodisabletheservicesindividually.Anautomatedmethodisneededtospeedupthehardeningprocess.,LockingDownRouterswithAutoSecure,WhatisAutoSecure?,AutoSecurehelpssecureCiscoIOSnetworksbyperformingtheserouterfunctions:DisablesinsecureglobalservicesEnablessecurity-basedglobalservicesDisablesinsecureinterfaceservicesEnablesappropriatesecurityloggingSecuresrouteradministrativeaccessSecurestheroutermanagementplaneSecurestherouterforwardingplane,AutoSecureOperationModes,AutoSecurecanbedeployedusingoneofthefollowingtwomodesofoperation:Interactivemode:Promptstheuserwithoptionstoenableanddisableservicesandothersecurity-relatedfeaturesNoninteractivemode:Automaticallyexecutestheautosecurecommandusingrecommendeddefaultsettings,AutoSecureFunctions,AutoSecurecanselectivelylockdown:Managementplaneservicesandfunctions:Finger,PAD,UDP&TCPsmallservers,passwordencryption,TCPkeepalives,CDP,BOOTP,HTTP,sourcerouting,gratuitousARP,proxyARP,ICMP(redirects,mask-replies),directedbroadcast,MOP,bannerAlsoprovidespasswordsecurityandSSHaccessForwardingplaneservicesandfunctions:CEF,trafficfilteringwithACLsFirewallservicesandfunctions:CiscoIOSFirewallinspectionforcommonprotocolsLoginfunctions:PasswordsecurityNTPprotocolSSHaccessTCPInterceptservices,AutoSecureFailureScenarios,IfAutoSecurefailstocompleteitsoperation,yourrunningconfigurationmaybecorrupt:In12.3(8)TandlaterreleasesPre-autosecureconfigurationsnapshotisstoredintheflashunderfilenamepre_autosec.cfgRoll-backrevertstheroutertoitspre-autosecureconfigurationCommand:configurereplaceflash:pre_autosec.cfgPriorto12.3(8)T,youshouldsavetherunningconfigurationbeforerunningAutoSecure,AutoSecureProcessOverview,AutoSecureProcessOverview,autosecuremanagement|forwardingno-interact|fullntp|login|ssh|firewall|tcp-intercept,router#,LaunchesAutoSecureMainstepswiththeinteractivefulloption:Identifyoutsideinterfaces.Securethemanagementplane.Createsecuritybanner.Configurepasswords,AAA,andSSH.Securetheinterfacesettings.Securetheforwardingplane.,StartandInterfaceSelection,Router#autosecure-AutoSecureConfiguration-*AutoSecureconfigurationenhancesthesecurityoftherouterbutitwillnotmakerouterabsolutelysecurefromallsecurityattacks*AlltheconfigurationdoneaspartofAutoSecurewillbeshownhere.Formoredetailsofwhyandhowthisconfigurationisuseful,andanypossiblesideeffects,pleaserefertoCiscodocumentationofAutoSecure.Atanypromptyoumayenter?forhelp.Usectrl-ctoabortthissessionatanyprompt.GatheringinformationabouttherouterforAutoSecureIsthisrouterconnectedtointernet?no:yEnterthenumberofinterfacesfacinginternet1:1InterfaceIP-AddressOK?MethodStatusProtocolEthernet0/0YESNVRAMupupEthernet0/1YESNVRAMupupEntertheinterfacenamethatisfacinginternet:Ethernet0/1,SecuringManagementPlaneServices,SecuringManagementplaneservices.DisablingservicefingerDisablingservicepadDisablingudp&tcpsmallserversEnablingservicepasswordencryptionEnablingservicetcp-keepalives-inEnablingservicetcp-keepalives-outDisablingthecdpprotocolDisablingthebootpserverDisablingthehttpserverDisablingthefingerserviceDisablingsourceroutingDisablinggratuitousarp,CreatingSecurityBanner,HereisasampleSecurityBannertobeshownateveryaccesstodevice.Modifyittosuityourenterpriserequirements.AuthorisedAccessonlyThissystemisthepropertyofSo-&-So-Enterprise.UNAUTHORISEDACCESSTOTHISDEVICEISPROHIBITED.Youmusthaveexplicitpermissiontoaccessthisdevice.Allactivitiesperformedonthisdeviceareloggedandviolationsofofthispolicyresultindisciplinaryaction.EnterthesecuritybannerPutthebannerbetweenkandk,wherekisanycharacter:%ThissystemisthepropertyofCiscoSystems,Inc.UNAUTHORIZEDACCESSTOTHISDEVICEISPROHIBITED.%,PasswordsandAAA,EnablesecretiseithernotconfiguredorissameasenablepasswordEnterthenewenablesecret:Curium96ConfigurationoflocaluserdatabaseEntertheusername:student1Enterthepassword:student1ConfiguringaaalocalauthenticationConfiguringconsole,Auxandvtylinesforlocalauthentication,exec-timeout,transportSecuringdeviceagainstLoginAttacksConfigurethefollowingparametersBlockingPeriodwhenLoginAttackdetected:300MaximumLoginfailureswiththedevice:3Maximumtimeperiodforcrossingthefailedloginattempts:60,SSHandInterface-SpecificServices,ConfigureSSHserver?yes:yEnterthehostname:R2Enterthedomain-name:ConfiguringinterfacespecificAutoSecureservicesDisablingthefollowingipservicesonallinterfaces:noipredirectsnoipproxy-arpnoipunreachablesnoipdirected-broadcastnoipmask-replyDisablingmoponEthernetinterfaces,ForwardingPlane,VerificatonandDeployment,SecuringForwardingplaneservices.EnablingCEF(Thismightimpactthememoryrequirementsforyourplatform)EnablingunicastrpfonallinterfacesconnectedtointernetConfigureCBACFirewallfeature?yes/no:yesThisistheconfigurationgenerated:noservicefingernoservicepadnoserviceudp-small-serversnoservicetcp-small-serversservicepassword-encryption.Applythisconfigurationtorunning-config?yes:y,LockingDownRouterswiththeSDM,SecurityDeviceManager,SDMautomatedhardeningfeatures:SecurityAuditOne-StepLockdown,SDMSecurityAuditOverview,Thesecurityauditcomparesrouterconfigurationagainstrecommendedsettings.Examplesoftheauditinclude:Shutdownunneededservers.Disableunneededservices.Applythefirewalltotheoutsideinterfaces.DisableorhardenSNMP.Shutdownunusedinterfaces.Checkpasswordstrength.EnforcetheuseofACLs.,SDMSecurityAudit:MainWindow,1.,2.,3.,SDMSecurityAuditWizard,SDMSecurityAuditInterfaceConfiguration,SDMSecurityAudit,SDMSecurityAudit:F
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 进场经营协议书模板7篇
- 卷帘门施工合同协议书样本6篇
- 智能城市智慧社区建设2025年可行性研究报告
- 电气火灾隐患排查治理总结
- 供电所安全生产情况汇报
- 留守儿童安全培训
- 自来水管道保暖施工合同5篇
- 工程设计安全合同6篇
- 消费者食品健康意识研究-洞察及研究
- 皮下给药与移植免疫病理-洞察及研究
- 转让店铺欠款协议书
- 2024年黑龙江省《宪法知识竞赛必刷100题》考试题库【研优卷】
- 《建筑电气安装》课件
- 《山东省房屋市政施工安全监督要点》及《安全监督“二十要”》2025
- 2025年湖南环境生物职业技术学院单招职业技能考试题库带答案
- 生物安全管理体系文件
- 河道疏浚外运施工方案
- 银行职业介绍课件
- 辽宁省盘锦市大洼区田家学校2024-2025学年九年级上学期第四次质量检测语文试卷
- 砖砌围墙施工方案
- 《人工智能导论》(第2版)高职全套教学课件
评论
0/150
提交评论