国产探花免费观看_亚洲丰满少妇自慰呻吟_97日韩有码在线_资源在线日韩欧美_一区二区精品毛片,辰东完美世界有声小说,欢乐颂第一季,yy玄幻小说排行榜完本

首頁 > 學院 > 網絡通信 > 正文

路由器安全配置速查表(一)

2019-11-05 00:48:18
字體:
來源:轉載
供稿:網友

Specific Recommendations: Router access 

1. Shut down unneeded services on the router. Servers that are not running cannot break. Also, more memory and PRocessor slots are available. Start by running the show proc command on the router, then turn off clearly unneeded facilities and services. Some servers that should almost always be turned off and the corresponding commands to disable them are listed below.  

Small services (echo, discard, chargen, etc.)  
no service tcp-small-servers  
no service udp-small-servers  
BOOTP - no ip bootp server  
Finger - no service finger  
HTTP - no ip http server  
SNMP - no snmp-server 

2. Shut down unneeded services on the routers. These services allow certain packets to pass through the router, or send special packets, or are used for remote router configuration. Some services that should almost always be turned off and the corresponding commands to 
disable them are listed below.  

CDP - no cdp run  
Remote config. - no service config  
Source routing - no ip source-route 

3. The&interfaces on the router can be made more secure by using certain commands in the Configure Interface mode. These commands should be applied to every interface.  

Unused interfaces - shutdown  
No Smurf attacks - no ip directed-broadcast  
Mask replies - no ip mask-reply  
Ad-hoc routing - no ip proxy-arp 

4. The console line, the auxiliary line and the virtual terminal lines on the router can be made more secure in the Configure Line mode. The console line and the virtual terminal lines should be secured as shown below. The Aux line should be disabled, as shown below, if it is not being used.  

Console Line - line con 0 
exec-timeout 5 0 
login  
Auxiliary Line - line aux 0 
no exec 
exec-timeout 0 10 
transport input none  
VTY lines - line vty 0 4 
exec-timeout 5 0 
login 
transport input telnet ssh 

5. PassWords can be configured more securely as well. Configure the Enable Secret password, which is protected with an md5-based algorithm. Also, configure passwords for the console line,the auxiliary line and the virtual terminal lines. Provide basic protection for the user and line passwords using the service passwordencryption command. See examples below.  

Enable secret - enable secret 0 2manyRt3s  
Console Line - line con 0 
password Soda-4-jimmY  
Auxiliary Line - line aux 0 
password Popcorn-4-sara  
VTY Lines - line vty 0 4 
password Dots-4-georg3  
Basic protection - service password-encryption 


6. Consider adopting SSH, if your router supports it, for all remote administration.  

7. Protect your router configuration file from unauthorized disclosure.



發表評論 共有條評論
用戶名: 密碼:
驗證碼: 匿名發表
主站蜘蛛池模板: 临武县| 都昌县| 玉溪市| 英吉沙县| 会同县| 晋宁县| 桐城市| 哈巴河县| 甘孜| 烟台市| 衡阳市| 元谋县| 阿坝| 高碑店市| 全南县| 务川| 洛浦县| 皮山县| 平阳县| 台东县| 宁南县| 诏安县| 宜川县| 鞍山市| 上高县| 峨眉山市| 旅游| 西乌珠穆沁旗| 寿光市| 武宣县| 深水埗区| 铁力市| 靖安县| 郑州市| 新余市| 台东县| 高邮市| 兴仁县| 巴青县| 历史| 柳林县|