Locking Down the Cisco IOS Router

The security administrator at Company-A must configure the router appropriately to increase the security of the Atlanta office network. The administrator uses the Security Device Manager (SDM) to configure the router and perform a security audit. Using SDM, the administrator can configure the router quickly using the best practices recommended in Chapter 2, "Preparation Phase."

You can complete the following steps to perform a security audit and fix any discrepancies found on the Cisco IOS router.

Step 1 Log in to the Cisco IOS router using SDM.

Step 2 Navigate to Configure > Security Audit, and click the Perform security audit button, as illustrated in Figure 12-21. Alternatively, you can perform a one-step lockdown to configure default recommendations by clicking the One-step lockdown button. In this example, the step-by-step option is selected, which allows you to customize your configuration.

Figure 12-21 Performing a Security Audit with SDM

Figure 12-21 Performing a Security Audit with SDM

Step 3 The Security Audit Wizard welcome screen shown in Figure 12-22 is displayed.

Step 4 Click Next.

Step 5 The Security Audit Interface Configuration screen shown in

Figure 12-23 is displayed. In this example, a Cisco 871 router is used. The outside interface is FastEthernet4, and the inside interface is Vlan 1.

Figure 12-22 Security Audit Wizard Welcome Screen

Figure 12-22 Security Audit Wizard Welcome Screen

Figure 12-23 Security Audit Wizard Interface Configuration Screen

Step 6 Click Next.

Step 7 SDM performs the audit to make sure that the recommended settings are configured on the router. As illustrated in Figure 12-24, the router fails on numerous items.

Figure 12-24 Security Audit Wizard Interface Configuration Screen

Figure 12-24 Security Audit Wizard Interface Configuration Screen

Please wait while SecurityAudit checks Itttis recommended security settings are configured nn tha ranter

No Item Name

Status

I Disable Finger Service 7 Disable PAD Service

3 Disable TCP small servers Service

4 Disable UDP small servers Service

5 Disable IP bootp server Service G Disable GDP

7 Disable IP source route

9 Enable Password encryption Service

3 Enable TCP Keepaltyes Tor Inbound telnet sessions

10 Enable TCP Keepallvas Tor outbound telnet sessions

II Enable Sequence Numbers and Time Stamps on Debugs

12 Enable IP CEF

13 Disable IP Gratuitous Arps

14 Set Scheduler Interna

15 Set TCP SynwaltHme_

Passed ^ Passed Passed ^ Passed

X Not Passed X Not Passed X Not Passed X Not Passed X Not Passed X Not Passed X Not Passed Passed

^ Passed

X Not Passed X Not Passed

Click "Gloss" to continue fixing the Identified security problems or undoing the configured security configurations In the router.

Close I Save Report)

SDM allows you to save a report that lists all the configuration checks that have passed or failed. The report is illustrated in Figure 12-25.

Figure 12-25 Security Audit Report

Hostname ¡company-A-ios-fvv

Report Sammary

No

Item Name

Status

1

Disable Finger Service

S Passed

2

Disable PAD Service

S Passed

3

Disable TCP small servers Service

Passed

1

Disable UDP small servers Service

/ Passed

;

Disable IP bootp server Service

^ Not Passed

s

yjisable CDP

* Not Passed

7

Disable IP source route

^ Not Passed

B

Enable Password encryption Service

* Not Passed

?

Enable TCP Keepaüves for inbound telnet sessions

^ Not Passed

ID

Enable TCP Keepaüves for outbound telnet sessions

* Not Passed

11

Enable Sequence Numbers and Time Stamps on Debugs

^ Not Passed

12

Enable IP CEF

/ Passed

13

Disable IP Gratuitous Arps

Passed

14

Set Scheduler Interval

* Not Passed

15

Set TCP Synwait time

^ Not Passed

16

Set Banner

* Not Passed

17

Enable Logging

^ Not Passed

IE

Set Enable Secret Password

* Not Passed

19

Disable SNMP

Passed

20

Set Scheduler Allocate

* Not Passed

.21

Set Users

^ Not Passed

22

Enable Telnet settings

* Not Passed

23

Enable NetFlow Monitoring

^ Not Passed

24

Disable IP Redirects

* Not Passed

25

Disable IP Proxy Arp

^ Not Passed

26

Disable IP Directed Broadcast

S Passed

27

Disable IP Unreachables

^ Not Passed

28

Disable IP Mask Reply

S Passed

29

disable IP Unreachables on Null interface

^ Not Passed

30

inable Unicast RPF on all outside interfaces

X Not Passed

31

inable Firewall on all outside interfaces

^ Not Passed

32

Set Access class on HTTP server service

* Not Passed

33

Set Access class on VTY lines

X Not Passed

34

inable SSHfor access to the router

^ Not Passed

35

inable AAA

X Not Passed

Step 8 SDM asks you to enter a new enable secret password and to configure a login banner, as illustrated in Figure 12-26.

Step 9 After you enter the new enable secret password and login banner, click Next.

Step 10 SDM allows you to configure an administrative account, as shown in Figure 12-27. To configure a new account, click Add.

Figure 12-26 Configuring a New Enable Secret Password and Login Banner

Figure 12-26 Configuring a New Enable Secret Password and Login Banner

Figure 12-27 Creating an Administrative Account

Step 11 Enter the username and password, as shown in Figure 12-27. In this example, a user named companyAadmin is created.

Step 12 Click OK after entering the username and password.

Step 13 Click Next to continue with the Security Audit Wizard.

Step 14 In the next screen, SDM allows you to enable logging and configure a system log (SYSLOG) server, as illustrated in Figure 12-28.

Figure 12-28 Configuring Logging

Figure 12-28 Configuring Logging

Step 15 In this example, the logging level is set to informational (level 6), and the SYSLOG server IP address is 10.100.10.222.

Step 16 Click Next.

Step 17 The Advanced Firewall Configuration Wizard welcome screen is displayed, as shown in Figure 12-29.

Step 18 Click Next.

Step 19 Check the inside and outside interfaces. In this example, FastEthernet4 is the outside interface, and Vlan1 is the inside interface. This is illustrated in Figure 12-30.

Figure 12-29 Advanced Firewall Configuration Wizard Welcome Screen

Figure 12-29 Advanced Firewall Configuration Wizard Welcome Screen

Figure 12-30 IOS Firewall Inside and Outside Interface Selection

Step 20 Click Next.

Step 21 The screen shown in Figure 12-31 is displayed. In this screen, SDM

allows you to enable predefined application security policies. You can use the slider to select the security level. In this example, the security level is set to High.

Figure 12-31 Application Security Policies

Figure 12-31 Application Security Policies

Step 22 Click Next.

Step 23 The SDM Wizard allows you enter the primary and secondary DNS servers for name resolution, as illustrated in Figure 12-32. In this example, the primary DNS server is 10.100.10.21, and the secondary DNS server is 10.100.10.22.

Step 24 Click Next after entering the DNS server information.

Step 25 A summary screen lists the configuration changes, as illustrated in

Figure 12-33. Click Finish to send the configuration changes to the Cisco IOS router.

Figure 12-S2 DNS Server Configuration

Figure 12-S2 DNS Server Configuration

Figure 12-33 Security Audit Wizard Summary Screen

Example 12-2 shows the CLI configuration of the router at the Atlanta office after completing the previous steps.

Example 12-2 CLI Configuration of the Cisco IOS Router at the Atlanta Office company-A-ios-fw#show running-config Building configuration... Current configuration : 8080 bytes !

version 12.4 no service pad service tcp-keepalives-in service tcp-keepalives-out service timestamps debug datetime msec localtime show-timezone service timestamps log datetime msec localtime show-timezone service password-encryption service sequence-numbers !

hostname company-A-ios-fw !

boot-start-marker boot-end-marker !

no logging buffered logging console critical enable secret 5 $1$XlSV$Pa0oIYeuSY5CZOGXXOJjF/ !

aaa authentication login local_authen local aaa authorization exec local_author local !

aaa session-id common no ip source-route ip cef !

ip tcp synwait-time 10 no ip bootp server ip name-server 10.100.10.21 ip name-server 10.100.10.22 ip ssh time-out 60

ip ssh authentication-retries 2 !

parameter-map type protocol-info msn-servers server name messenger.hotmail.com server name gateway.messenger.hotmail.com server name webmessenger.msn.com

parameter-map type protocol-info aol-servers server name login.oscar.aol.com server name toc.oscar.aol.com server name oam-d09a.blue.aol.com

Example 12-2 CLI Configuration of the Cisco IOS Router at the Atlanta Office (Continued) parameter-map type protocol-info yahoo-servers

server

name

scs.

msg.yahoo.com

server

name

scsa

.msg.

yahoo.com

server

name

scsb

.msg.

yahoo.com

server

name

scsc

.msg.

yahoo.com

server

name

scsd

.msg.

yahoo.com

server

name

cs16

.msg.

dcn.yahoo.

com

server

name

cs19

.msg.

dcn.yahoo.

com

server

name

cs42

.msg.

dcn.yahoo.

com

server

name

cs53

.msg.

dcn.yahoo.

com

server

name

cs54

.msg.

dcn.yahoo.

com

server

name

adsl

.vip.

scd.yahoo.

com

server

name

radio1.launch.vip.dal.yahoo.com

server

name

inl.

msg.vip.re2.yahoo.com

server

name

datal.my.

vip.sc5.yahoo.com

server

name

addressl.

pim.vip.mud.yahoo.com

server

name

edit

.messenger.yahoo.com

server

name

messenger

.yahoo.com

server

name

http

.pager.yahoo.com

server

name

privacy.yahoo.com

server

name

csa.

yahoo

.com

server

name

csb.

yahoo

.com

server

name

csc.

yahoo

.com

parameter-map type regex sdm-regex-nonascii pattern ["\x00-\x80]

username companyAadmin password 7 02050D4808095E731F ! !

class-map type inspect smtp match-any sdm-app-smtp match data-length gt 5000000 class-map type inspect http match-any sdm-app-nonascii match req-resp header regex sdm-regex-nonascii class-map type inspect imap match-any sdm-app-imap match invalid-command class-map type inspect match-any sdm-cls-insp-traffic match protocol dns match protocol https match protocol icmp match protocol imap match protocol pop3 match protocol tcp match protocol udp class-map type inspect match-all sdm-insp-traffic match class-map sdm-cls-insp-traffic class-map type inspect match-all sdm-protocol-pop3 match protocol pop3

continues

Example 12-2 CLI Configuration of the Cisco IOS Router at the Atlanta Office (Continued)

class-map type inspect match-any sdm-cls-icmp-access match protocol icmp match protocol tcp match protocol udp class-map type inspect match-any sdm-cls-protocol-im match protocol ymsgr yahoo-servers match protocol msnmsgr msn-servers match protocol aol aol-servers class-map type inspect pop3 match-any sdm-app-pop3

match invalid-command class-map type inspect http match-any sdm-http-blockparam match request port-misuse im match request port-misuse p2p match request port-misuse tunneling match req-resp protocol-violation class-map type inspect match-all sdm-protocol-im match class-map sdm-cls-protocol-im class-map type inspect match-all sdm-icmp-access match class-map sdm-cls-icmp-access class-map type inspect match-all sdm-invalid-src match access-group 100

class-map type inspect

http match-any sdm-app-httpmethods

match

request

method

bcopy

match

request

method

bdelete

match

request

method

bmove

match

request

method

bpropfind

match

request

method

bproppatch

match

request

method

connect

match

request

method

copy

match

request

method

delete

match

request

method

edit

match

request

method

getattribute

match

request

method

getattributenames

match

request

method

getproperties

match

request

method

index

match

request

method

lock

match

request

method

mkcol

match

request

method

mkdir

match

request

method

move

match

request

method

notify

match

request

method

options

match

request

method

poll

match

request

method

post

match

request

method

propfind

match

request

method

proppatch

match

request

method

put

match

request

method

revadd

match

request

method

revlabel

match

request

method

revlog

match

request

method

revnum

match

request

method

save

match

request

method

search

Example 12-2 CLI Configuration of the Cisco IOS Router at the Atlanta Office (Continued)

match

request

method

setattribute

match

request

method

startrev

match

request

method

stoprev

match

request

method

subscribe

match

request

method

trace

match

request

method

unedit

match

request

method

unlock

match

request

method

unsubscribe

class-map type

inspect

match-all sdm-protocol-http

match protocol http class-map type inspect match-all sdm-protocol-smtp match protocol smtp class-map type inspect match-all sdm-protocol-imap match protocol imap

policy-map type inspect sdm-permit-icmpreply class type inspect sdm-icmp-access inspect class class-default pass policy-map type inspect http sdm-action-app-http class type inspect http sdm-http-blockparam log reset class type inspect http sdm-app-httpmethods log reset class type inspect http sdm-app-nonascii log reset class class-default policy-map type inspect smtp sdm-action-smtp class type inspect smtp sdm-app-smtp reset class class-default policy-map type inspect imap sdm-action-imap class type inspect imap sdm-app-imap log reset class class-default policy-map type inspect pop3 sdm-action-pop3 class type inspect pop3 sdm-app-pop3 log reset class class-default policy-map type inspect sdm-inspect class type inspect sdm-invalid-src drop log class type inspect sdm-protocol-http inspect service-policy http sdm-action-app-http continues

Example 12-2 CLI Configuration of the Cisco IOS Router at the Atlanta Office (Continued)

class type inspect sdm-protocol-smtp inspect service-policy smtp sdm-action-smtp class type inspect sdm-protocol-imap inspect service-policy imap sdm-action-imap class type inspect sdm-protocol-pop3 inspect service-policy pop3 sdm-action-pop3 class type inspect sdm-protocol-im drop log class type inspect sdm-insp-traffic inspect class class-default policy-map type inspect sdm-permit class class-default

zone security out-zone zone security in-zone zone-pair security sdm-zp-self-out source self destination out-zone service-policy type inspect sdm-permit-icmpreply zone-pair security sdm-zp-out-self source out-zone destination self service-policy type inspect sdm-permit zone-pair security sdm-zp-in-out source in-zone destination out-zone service-policy type inspect sdm-inspect interface Null0 no ip unreachables

interface FastEthernet0 !

interface FastEthernetl !

interface FastEthernet2 !

interface FastEthernet3 !

interface FastEthernet4 description $FW_OUTSIDE$ ip address 209.165.200.231 255.255.255.0 no ip redirects no ip unreachables no ip proxy-arp zone-member security out-zone ip route-cache flow duplex auto

Example 12-2 CLI Configuration of the Cisco IOS Router at the Atlanta Office (Continued)

speed auto

interface Vlanl description $FW_INSIDE$ ip address 10.100.10.1 255.255.255.0 no ip redirects no ip unreachables no ip proxy-arp zone-member security in-zone ip route-cache flow

ip route 0.0.0.0 0.0.0.0 209.165.200.225 !

ip http server no ip http secure-server !

logging trap informational logging 10.100.10.222

access-list 100 remark SDM_ACL Category=128 access-list 100 permit ip host 255.255.255.255 any access-list 100 permit ip 127.0.0.0 0.255.255.255 any access-list 100 permit ip 209.165.200.0 0.0.0.255 any access-list 101 remark VTY Access-class list access-list 101 remark SDM_ACL Category=1 access-list 101 permit ip 10.100.10.0 0.0.0.255 any access-list 101 deny ip any any no cdp run control-plane !

banner login "C*** THIS IS A RESTRICTED SYSTEM, UNAUTHORIZED ACCESS"C !

line con 0 login authentication local_authen no modem enable transport output telnet line aux 0 login authentication local_authen transport output telnet line vty 0 4 access-class 101 in authorization exec local_author login authentication local_authen transport input telnet ssh

scheduler max-task-time 5000 scheduler allocate 4000 1000 scheduler interval 500 end

Continue reading here: Configuring Siteto Site VPN

Was this article helpful?

0 0