Locking Down the Cisco IOS Router
The security administrator at Company-A must configure the router appropriately to increase the security of the Atlanta office network. The administrator uses the Security Device Manager (SDM) to configure the router and perform a security audit. Using SDM, the administrator can configure the router quickly using the best practices recommended in Chapter 2, "Preparation Phase."
You can complete the following steps to perform a security audit and fix any discrepancies found on the Cisco IOS router.
Step 1 Log in to the Cisco IOS router using SDM.
Step 2 Navigate to Configure > Security Audit, and click the Perform security audit button, as illustrated in Figure 12-21. Alternatively, you can perform a one-step lockdown to configure default recommendations by clicking the One-step lockdown button. In this example, the step-by-step option is selected, which allows you to customize your configuration.
Figure 12-21 Performing a Security Audit with SDM
Figure 12-21 Performing a Security Audit with SDM
Step 3 The Security Audit Wizard welcome screen shown in Figure 12-22 is displayed.
Step 4 Click Next.
Step 5 The Security Audit Interface Configuration screen shown in
Figure 12-23 is displayed. In this example, a Cisco 871 router is used. The outside interface is FastEthernet4, and the inside interface is Vlan 1.
Figure 12-22 Security Audit Wizard Welcome Screen
Figure 12-22 Security Audit Wizard Welcome Screen

- Figure 12-23 Security Audit Wizard Interface Configuration Screen
Step 6 Click Next.
Step 7 SDM performs the audit to make sure that the recommended settings are configured on the router. As illustrated in Figure 12-24, the router fails on numerous items.
Figure 12-24 Security Audit Wizard Interface Configuration Screen
Figure 12-24 Security Audit Wizard Interface Configuration Screen
Please wait while SecurityAudit checks Itttis recommended security settings are configured nn tha ranter
No Item Name
Status
I Disable Finger Service 7 Disable PAD Service
3 Disable TCP small servers Service
4 Disable UDP small servers Service
5 Disable IP bootp server Service G Disable GDP
7 Disable IP source route
9 Enable Password encryption Service
3 Enable TCP Keepaltyes Tor Inbound telnet sessions
10 Enable TCP Keepallvas Tor outbound telnet sessions
II Enable Sequence Numbers and Time Stamps on Debugs
12 Enable IP CEF
13 Disable IP Gratuitous Arps
14 Set Scheduler Interna
15 Set TCP SynwaltHme_
Passed ^ Passed Passed ^ Passed
X Not Passed X Not Passed X Not Passed X Not Passed X Not Passed X Not Passed X Not Passed Passed
^ Passed
X Not Passed X Not Passed
Click "Gloss" to continue fixing the Identified security problems or undoing the configured security configurations In the router.
Close I Save Report)
SDM allows you to save a report that lists all the configuration checks that have passed or failed. The report is illustrated in Figure 12-25.
Figure 12-25 Security Audit Report
Hostname ¡company-A-ios-fvv
Report Sammary
|
No |
Item Name |
Status |
|
1 |
Disable Finger Service |
S Passed |
|
2 |
Disable PAD Service |
S Passed |
|
3 |
Disable TCP small servers Service |
Passed |
|
1 |
Disable UDP small servers Service |
/ Passed |
|
; |
Disable IP bootp server Service |
^ Not Passed |
|
s |
yjisable CDP |
* Not Passed |
|
7 |
Disable IP source route |
^ Not Passed |
|
B |
Enable Password encryption Service |
* Not Passed |
|
? |
Enable TCP Keepaüves for inbound telnet sessions |
^ Not Passed |
|
ID |
Enable TCP Keepaüves for outbound telnet sessions |
* Not Passed |
|
11 |
Enable Sequence Numbers and Time Stamps on Debugs |
^ Not Passed |
|
12 |
Enable IP CEF |
/ Passed |
|
13 |
Disable IP Gratuitous Arps |
Passed |
|
14 |
Set Scheduler Interval |
* Not Passed |
|
15 |
Set TCP Synwait time |
^ Not Passed |
|
16 |
Set Banner |
* Not Passed |
|
17 |
Enable Logging |
^ Not Passed |
|
IE |
Set Enable Secret Password |
* Not Passed |
|
19 |
Disable SNMP |
Passed |
|
20 |
* Not Passed |
|
|
.21 |
Set Users |
^ Not Passed |
|
22 |
Enable Telnet settings |
* Not Passed |
|
23 |
Enable NetFlow Monitoring |
^ Not Passed |
|
24 |
Disable IP Redirects |
* Not Passed |
|
25 |
Disable IP Proxy Arp |
^ Not Passed |
|
26 |
Disable IP Directed Broadcast |
S Passed |
|
27 |
Disable IP Unreachables |
^ Not Passed |
|
28 |
Disable IP Mask Reply |
S Passed |
|
29 |
disable IP Unreachables on Null interface |
^ Not Passed |
|
30 |
inable Unicast RPF on all outside interfaces |
X Not Passed |
|
31 |
inable Firewall on all outside interfaces |
^ Not Passed |
|
32 |
Set Access class on HTTP server service |
* Not Passed |
|
33 |
Set Access class on VTY lines |
X Not Passed |
|
34 |
inable SSHfor access to the router |
^ Not Passed |
|
35 |
inable AAA |
X Not Passed |
Step 8 SDM asks you to enter a new enable secret password and to configure a login banner, as illustrated in Figure 12-26.
Step 9 After you enter the new enable secret password and login banner, click Next.
Step 10 SDM allows you to configure an administrative account, as shown in Figure 12-27. To configure a new account, click Add.
Figure 12-26 Configuring a New Enable Secret Password and Login Banner
Figure 12-26 Configuring a New Enable Secret Password and Login Banner

- Figure 12-27 Creating an Administrative Account
Step 11 Enter the username and password, as shown in Figure 12-27. In this example, a user named companyAadmin is created.
Step 12 Click OK after entering the username and password.
Step 13 Click Next to continue with the Security Audit Wizard.
Step 14 In the next screen, SDM allows you to enable logging and configure a system log (SYSLOG) server, as illustrated in Figure 12-28.
Figure 12-28 Configuring Logging
Figure 12-28 Configuring Logging
Step 15 In this example, the logging level is set to informational (level 6), and the SYSLOG server IP address is 10.100.10.222.
Step 16 Click Next.
Step 17 The Advanced Firewall Configuration Wizard welcome screen is displayed, as shown in Figure 12-29.
Step 18 Click Next.
Step 19 Check the inside and outside interfaces. In this example, FastEthernet4 is the outside interface, and Vlan1 is the inside interface. This is illustrated in Figure 12-30.
Figure 12-29 Advanced Firewall Configuration Wizard Welcome Screen
Figure 12-29 Advanced Firewall Configuration Wizard Welcome Screen

- Figure 12-30 IOS Firewall Inside and Outside Interface Selection
Step 20 Click Next.
Step 21 The screen shown in Figure 12-31 is displayed. In this screen, SDM
allows you to enable predefined application security policies. You can use the slider to select the security level. In this example, the security level is set to High.
Figure 12-31 Application Security Policies
Figure 12-31 Application Security Policies
Step 22 Click Next.
Step 23 The SDM Wizard allows you enter the primary and secondary DNS servers for name resolution, as illustrated in Figure 12-32. In this example, the primary DNS server is 10.100.10.21, and the secondary DNS server is 10.100.10.22.
Step 24 Click Next after entering the DNS server information.
Step 25 A summary screen lists the configuration changes, as illustrated in
Figure 12-33. Click Finish to send the configuration changes to the Cisco IOS router.
Figure 12-S2 DNS Server Configuration
Figure 12-S2 DNS Server Configuration

- Figure 12-33 Security Audit Wizard Summary Screen
Example 12-2 shows the CLI configuration of the router at the Atlanta office after completing the previous steps.
Example 12-2 CLI Configuration of the Cisco IOS Router at the Atlanta Office company-A-ios-fw#show running-config Building configuration... Current configuration : 8080 bytes !
version 12.4 no service pad service tcp-keepalives-in service tcp-keepalives-out service timestamps debug datetime msec localtime show-timezone service timestamps log datetime msec localtime show-timezone service password-encryption service sequence-numbers !
hostname company-A-ios-fw !
boot-start-marker boot-end-marker !
no logging buffered logging console critical enable secret 5 $1$XlSV$Pa0oIYeuSY5CZOGXXOJjF/ !
aaa authentication login local_authen local aaa authorization exec local_author local !
aaa session-id common no ip source-route ip cef !
ip tcp synwait-time 10 no ip bootp server ip name-server 10.100.10.21 ip name-server 10.100.10.22 ip ssh time-out 60
ip ssh authentication-retries 2 !
parameter-map type protocol-info msn-servers server name messenger.hotmail.com server name gateway.messenger.hotmail.com server name webmessenger.msn.com
parameter-map type protocol-info aol-servers server name login.oscar.aol.com server name toc.oscar.aol.com server name oam-d09a.blue.aol.com
|
server |
name |
scs. |
msg.yahoo.com |
||
|
server |
name |
scsa |
.msg. |
yahoo.com |
|
|
server |
name |
scsb |
.msg. |
yahoo.com |
|
|
server |
name |
scsc |
.msg. |
yahoo.com |
|
|
server |
name |
scsd |
.msg. |
yahoo.com |
|
|
server |
name |
cs16 |
.msg. |
dcn.yahoo. |
com |
|
server |
name |
cs19 |
.msg. |
dcn.yahoo. |
com |
|
server |
name |
cs42 |
.msg. |
dcn.yahoo. |
com |
|
server |
name |
cs53 |
.msg. |
dcn.yahoo. |
com |
|
server |
name |
cs54 |
.msg. |
dcn.yahoo. |
com |
|
server |
name |
adsl |
.vip. |
scd.yahoo. |
com |
|
server |
name |
radio1.launch.vip.dal.yahoo.com |
|||
|
server |
name |
inl. |
msg.vip.re2.yahoo.com |
||
|
server |
name |
datal.my. |
vip.sc5.yahoo.com |
||
|
server |
name |
addressl. |
pim.vip.mud.yahoo.com |
||
|
server |
name |
edit |
.messenger.yahoo.com |
||
|
server |
name |
messenger |
.yahoo.com |
||
|
server |
name |
http |
.pager.yahoo.com |
||
|
server |
name |
privacy.yahoo.com |
|||
|
server |
name |
csa. |
yahoo |
.com |
|
|
server |
name |
csb. |
yahoo |
.com |
|
|
server |
name |
csc. |
yahoo |
.com |
|
parameter-map type regex sdm-regex-nonascii pattern ["\x00-\x80]
username companyAadmin password 7 02050D4808095E731F ! !
class-map type inspect smtp match-any sdm-app-smtp match data-length gt 5000000 class-map type inspect http match-any sdm-app-nonascii match req-resp header regex sdm-regex-nonascii class-map type inspect imap match-any sdm-app-imap match invalid-command class-map type inspect match-any sdm-cls-insp-traffic match protocol dns match protocol https match protocol icmp match protocol imap match protocol pop3 match protocol tcp match protocol udp class-map type inspect match-all sdm-insp-traffic match class-map sdm-cls-insp-traffic class-map type inspect match-all sdm-protocol-pop3 match protocol pop3
continues
Example 12-2 CLI Configuration of the Cisco IOS Router at the Atlanta Office (Continued)
class-map type inspect match-any sdm-cls-icmp-access match protocol icmp match protocol tcp match protocol udp class-map type inspect match-any sdm-cls-protocol-im match protocol ymsgr yahoo-servers match protocol msnmsgr msn-servers match protocol aol aol-servers class-map type inspect pop3 match-any sdm-app-pop3
match invalid-command class-map type inspect http match-any sdm-http-blockparam match request port-misuse im match request port-misuse p2p match request port-misuse tunneling match req-resp protocol-violation class-map type inspect match-all sdm-protocol-im match class-map sdm-cls-protocol-im class-map type inspect match-all sdm-icmp-access match class-map sdm-cls-icmp-access class-map type inspect match-all sdm-invalid-src match access-group 100
|
class-map type inspect |
http match-any sdm-app-httpmethods |
||
|
match |
request |
method |
bcopy |
|
match |
request |
method |
bdelete |
|
match |
request |
method |
bmove |
|
match |
request |
method |
bpropfind |
|
match |
request |
method |
bproppatch |
|
match |
request |
method |
connect |
|
match |
request |
method |
copy |
|
match |
request |
method |
delete |
|
match |
request |
method |
edit |
|
match |
request |
method |
getattribute |
|
match |
request |
method |
getattributenames |
|
match |
request |
method |
getproperties |
|
match |
request |
method |
index |
|
match |
request |
method |
lock |
|
match |
request |
method |
mkcol |
|
match |
request |
method |
mkdir |
|
match |
request |
method |
move |
|
match |
request |
method |
notify |
|
match |
request |
method |
options |
|
match |
request |
method |
poll |
|
match |
request |
method |
post |
|
match |
request |
method |
propfind |
|
match |
request |
method |
proppatch |
|
match |
request |
method |
put |
|
match |
request |
method |
revadd |
|
match |
request |
method |
revlabel |
|
match |
request |
method |
revlog |
|
match |
request |
method |
revnum |
|
match |
request |
method |
save |
|
match |
request |
method |
search |
Example 12-2 CLI Configuration of the Cisco IOS Router at the Atlanta Office (Continued)
|
match |
request |
method |
setattribute |
|
match |
request |
method |
startrev |
|
match |
request |
method |
stoprev |
|
match |
request |
method |
subscribe |
|
match |
request |
method |
trace |
|
match |
request |
method |
unedit |
|
match |
request |
method |
unlock |
|
match |
request |
method |
unsubscribe |
|
class-map type |
inspect |
match-all sdm-protocol-http |
|
match protocol http class-map type inspect match-all sdm-protocol-smtp match protocol smtp class-map type inspect match-all sdm-protocol-imap match protocol imap
policy-map type inspect sdm-permit-icmpreply class type inspect sdm-icmp-access inspect class class-default pass policy-map type inspect http sdm-action-app-http class type inspect http sdm-http-blockparam log reset class type inspect http sdm-app-httpmethods log reset class type inspect http sdm-app-nonascii log reset class class-default policy-map type inspect smtp sdm-action-smtp class type inspect smtp sdm-app-smtp reset class class-default policy-map type inspect imap sdm-action-imap class type inspect imap sdm-app-imap log reset class class-default policy-map type inspect pop3 sdm-action-pop3 class type inspect pop3 sdm-app-pop3 log reset class class-default policy-map type inspect sdm-inspect class type inspect sdm-invalid-src drop log class type inspect sdm-protocol-http inspect service-policy http sdm-action-app-http continues
Example 12-2 CLI Configuration of the Cisco IOS Router at the Atlanta Office (Continued)
class type inspect sdm-protocol-smtp inspect service-policy smtp sdm-action-smtp class type inspect sdm-protocol-imap inspect service-policy imap sdm-action-imap class type inspect sdm-protocol-pop3 inspect service-policy pop3 sdm-action-pop3 class type inspect sdm-protocol-im drop log class type inspect sdm-insp-traffic inspect class class-default policy-map type inspect sdm-permit class class-default
zone security out-zone zone security in-zone zone-pair security sdm-zp-self-out source self destination out-zone service-policy type inspect sdm-permit-icmpreply zone-pair security sdm-zp-out-self source out-zone destination self service-policy type inspect sdm-permit zone-pair security sdm-zp-in-out source in-zone destination out-zone service-policy type inspect sdm-inspect interface Null0 no ip unreachables
interface FastEthernet0 !
interface FastEthernetl !
interface FastEthernet2 !
interface FastEthernet3 !
interface FastEthernet4 description $FW_OUTSIDE$ ip address 209.165.200.231 255.255.255.0 no ip redirects no ip unreachables no ip proxy-arp zone-member security out-zone ip route-cache flow duplex auto
Example 12-2 CLI Configuration of the Cisco IOS Router at the Atlanta Office (Continued)
speed auto
interface Vlanl description $FW_INSIDE$ ip address 10.100.10.1 255.255.255.0 no ip redirects no ip unreachables no ip proxy-arp zone-member security in-zone ip route-cache flow
ip route 0.0.0.0 0.0.0.0 209.165.200.225 !
ip http server no ip http secure-server !
logging trap informational logging 10.100.10.222
access-list 100 remark SDM_ACL Category=128 access-list 100 permit ip host 255.255.255.255 any access-list 100 permit ip 127.0.0.0 0.255.255.255 any access-list 100 permit ip 209.165.200.0 0.0.0.255 any access-list 101 remark VTY Access-class list access-list 101 remark SDM_ACL Category=1 access-list 101 permit ip 10.100.10.0 0.0.0.255 any access-list 101 deny ip any any no cdp run control-plane !
banner login "C*** THIS IS A RESTRICTED SYSTEM, UNAUTHORIZED ACCESS"C !
line con 0 login authentication local_authen no modem enable transport output telnet line aux 0 login authentication local_authen transport output telnet line vty 0 4 access-class 101 in authorization exec local_author login authentication local_authen transport input telnet ssh
scheduler max-task-time 5000 scheduler allocate 4000 1000 scheduler interval 500 end
Continue reading here: Configuring Siteto Site VPN
Was this article helpful?