CatOS Switches
Fri, 06 May 2016 | Corporate Internet
The generic security configuration used within Cisco CatOS switches is described in the following steps Step 1 Shut down all unneeded services by issuing the following commands set ip http server disable set cdp disable Step 2 Set passwords and access restrictions. Enable AAA. To set passwords, use the following Set access restrictions with the following commands set ip permit enable telnet set ip permit management-host-address 255.255.255.255 telnet set tacacs server tacacs-server-address set...
- A
- About the Technical Reviewers
- Access Filtering
- Acknowledgments
- Additional SAFE White Papers
- Alternative Campus Module Designs
- Alternative Implementations
- Alternative Medium Sized Network Corporate Internet Module Designs
- Answers to Scenario 181
- Answers to Scenario 182
- Answers to Scenario 183
- Answers to Scenario 184
- Answers to Scenario 186
- AntiDoS Features
- Antispoof Features
- Application Hardening
- Applications Are Targets
- Authentication
- Authentication and Authorization for Access to Critical Resources
- B
- Book Content Updates
- Branch Versus Headend Standalone Considerations for Medium Sized Networks
- Buffer Overflow
- C
- Campus Module in Medium Sized Networks
- Campus Module in Small Networks
- Ccsp Csi Exam Certification Guide
- Characteristics of a Good Security Policy
- Cisco AVVID
- Cisco IOS Firewall Implementation
- Cisco Network Core Security Products
- Cisco Perimeter Security Products
- Cisco Secure IDS Sensors
- Cisco Secure Intrusion Detection System
- Cisco Secure PIX Firewall
- Cisco Secure Policy Manager
- Cisco Secure Scanner
- Cisco VPNEnabled Routers
- Cisco Works VPNSecurity Management Solution
- Classifying Rudimentary Network Attacks
- Classifying Sophisticated Network Attacks
- Command Syntax Conventions
- Components of SAFE Medium Sized Network Design
- Components of SAFE Small Network Design
- Configuration Options for Remote User Network Design
- Contents
- Contents at a Glance
- Corporate Internet Module in Small Networks
- Cost Effective Deployment
- CSI Exam Blueprint
- D
- Dedications
- Defining a Security Policy
- Denial of Service Attacks
- Design Alternatives - 2
- Design Alternatives for the Corporate Internet Module 3
- Design Considerations
- Design Guidelines - 2
- Design Guidelines for the Campus Module
- Design Guidelines for the Corporate Internet Module
- Designing Medium Sized SAFE Networks
- Designing Remote SAFE Networks
- Designing Small SAFE Networks
- Distributed Denial of Service Attacks - 2 3
- Do I Know This Already Quiz - 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23
- Ef
- Exam Registration
- Examining SAFE Design Fundamentals
- Features of This Book
- Feedback Information
- File Management Protocols Trivial File Transfer Protocol
- Firewalls
- Foreword
- Foundation Summary - 2 3 4 5 6 7 8 9 10 11 12 13 14 15
- Foundation Topics - 2
- General Implementation Recommendations - 2
- Gh
- Host Intrusion Detection System Overview
- Hosts Are Targets
- I
- Identity Management Cisco Secure Access Control Server
- IDS Implementation
- IDS Management Console
- IIS Directory Traversal Vulnerability
- Implementing Medium Sized SAFE Networks
- Implementing Small SAFE Networks
- InBand Network Management
- Info
- Inside Interface Filtering
- Internal Threats
- Internal Traffic Filtering - 2
- Intrusion Detection for Critical Resources and Subnets
- IP Spoofing
- IP Spoofing Attacks - 2
- ISP Traffic Filtering
- Key Campus Module Devices
- Key Corporate Internet Module Devices
- Key Devices for Remote User Networks
- M
- ManInThe Middle Attacks
- Mitigating Application Layer Attacks
- Mitigating Denial of Service Attacks
- Mitigating IP Spoofing Attacks
- Mitigating Management Traffic Attacks
- Mitigating ManInThe Middle Attacks
- Mitigating Password Attacks
- Mitigating Port Redirection Attacks
- Mitigating Reconnaissance Attacks
- Mitigating Rudimentary Network Attacks
- Mitigating Sophisticated Network Attacks
- Mitigating Threats in Remote User Networks
- Mitigating Threats in the Campus Module - 2
- Mitigating Threats in the Corporate Internet Module - 2
- Mitigating Threats in the WAN Module
- Monitoring and Control Protocol Simple Network Management Protocol
- N
- Network Infrastructure
- Network Intrusion Detection System Overview
- Network Management
- Network Management Protocols
- Network Posture Visibility
- Networks Are Targets
- Nondistributed Denial of Service Attacks
- Outof Band Network Management
- Outside Interface Filtering - 2
- Packet Sniffers
- Designing and Implementing SAFE Networks
- Password Attacks
- Password Testing
- Perimeter Security
- Port Redirection
- Protecting Against Unauthorized Access
- Public Services Segment Filtering
- Public Services Traffic Filtering - 2
- Public Traffic Filtering
- Public VLAN Traffic Filtering
- Qa - 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23
- R
- Recommended Training for CCSP
- Reconnaissance Attacks
- References
- Remote Access Protocols
- Remote Access Segment Filtering
- Remote Site Firewall
- Reporting and Logging Protocol Syslog
- RFC 2827 Filtering
- Risk Assessment
- Routers - 2
- Routers Are Targets
- S
- Safe A Security Blueprint for Enterprise Networks
- SAFE Architecture Overview
- SAFE Design Fundamentals
- SAFE Design Philosophy
- SAFE Extending the Security Blueprint to Small Midsize and Remote User Networks
- Safe Ip Telephony Security in Depth
- SAFE Modules Overview
- Safe Vpn Ipsec Virtual Private Networks in Depth
- SAFE Wireless LAN Security in Depth Version
- Scenario 181
- Scenario 182
- Scenario 183
- Scenario 184
- Scenario 185
- Scenario 186
- Scenarios for Final Preparation
- Secure Connectivity
- Secure Management and Reporting
- Security and Attack Mitigation Based on Policy
- Security Implementation Throughout the Infrastructure
- Security Management
- Security Policy Characteristics Goals and Components
- Security Policy Components
- Security Policy Goals
- Selecting the Right Product
- Service Control
- Structured Threats
- Support for Emerging Networked Applications
- Switches Are Targets
- T
- The Need for Network Security
- The Security Wheel
- This chapter covers the following topics - 2
- Time Synchronization Protocols Network Time Protocol
- Traffic Rate Limiting
- Trust Exploitation Attacks
- Unauthorized Access Attacks
- Understanding SAFE Network Modules
- Understanding the Campus Module
- Understanding the Corporate Internet Module
- Understanding the WAN Module
- Unstructured Threats
- User Education
- Using the Cisco IOS Firewall Router in Medium Sized Networks
- Using the Cisco IOS Firewall Router in Small Networks
- Using the PIX Firewall in Medium Sized Networks
- Using the PIX Firewall in Small Networks
- Virus and Trojan Horse Applications
- VLAN Segregation
- VPN 3000 Series Concentrator Overview
- VPN Client
- VPN Configuration - 2
- VPN Hardware Client
- VPN Implementation
- WAN Module in Medium Sized Networks
- Warning and Disclaimer
- What Is SAFE
