SCND
Student Guide
Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA www.cisco.com Tel 408 526-4000 800 553-NETS (6387) Fax 408 526-4100 Cisco Systems International BV Haarlerb ergp ark Haarlerbergweg 13-19 1101 CH Amsterdam The Netherlands www-europe.cisco.com Tel 31 0 20 357 1000 Fax 31 0 20 357 1100 Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA www.cisco.com Tel 408 526-7660 Fax 408 527-0883 www.cisco.com Tel +65 6317 7777 Fax +65 6317 7799 Cisco Systems, Inc. 168...
Introducing the Cisco Integrated Services Router Family
This topic describes the security features of the Cisco Integrated Services Router Family. Integrated Services Router Product Portfolio ,, _ SMB or Enterprise Large . . Small Office - . . n l. n l. Headquarters _ . Small branch Branch Branch , , Home Office and beyond The Cisco 850 Series Access Routers supports broadband cable and Asymmetric Digital Subscriber Line (ADSL) over analog telephone lines. Designed for very small offices, the routers provide secure WAN connectivity with optional...
Worm Virus and Trojan Horse Attacks and Mitigation
A worm executes arbitrary code and installs copies of itself in the memory of the infected computer. The worm can then infect other hosts from the infected computer. A worm is also a program that propagates itself. A worm can spread itself automatically over the network from one computer to the next without user intervention. Worms are not clever or evil, they just take advantage of automatic file sending and receiving features found on many computers. A virus is malicious software that...
Application Layer Attacks and Mitigation
This topic describes the mitigation of application layer attacks. This topic describes the mitigation of application layer attacks. Application layer attacks have these following characteristics Exploit well-known weaknesses, such as those in protocols, that are intrinsic Often use ports that are allowed through a firewall for example, TCP Can never be completely eliminated, There are several methods of executing an application layer attack Exploiting well-known weaknesses One of the most...
Configuring an SSH Server for Secure Management and Reporting
This topic describes the steps used to configure an SSH server for secure management and reporting. Whenever possible, you should use SSH instead of Telnet to manage your Cisco routers. SSH version 1 (SSHv1) is supported in Cisco IOS Release 12.1(1)T and later, while SSH version 2 (SSHv2) is supported in Cisco IOS Release 12.3(4)T and later. Cisco routers configured for SSH act as SSH servers. You must provide an SSH client, such as PuTTY, OpenSSH, or Tera Term, for the administrator...
Test optimize and document the design
After assessing the security state of the network, it is possible to develop a strong security design. The design methodology should consider all aspects of network security and its integration with the core network infrastructure. Use an in-depth, system-wide approach based on industry standards to develop a multilayer defense against directed attacks from hackers or an indiscriminate attack from viruses and worms. Network security design review You need a strong security design from both an...
Enabling Syslog Logging With Cisco SDM
Configure > Additional Tasks > Router Properties > Logging > Edit Configure > Additional Tasks > Router Properties > Logging > Edit The procedure to enable syslog logging on your router using Cisco SDM is shown in the figure. Enter an IP address of a logging host. 2-148 Securing Cisco Network Devices (SND) v2.0 2006 Cisco Systems, Inc. Enter a value in the Community String field. The procedure to enable SNMP, set SNMP community strings, and enter SNMP trap manager information...
In Windows Nt Smb runs on top of NetBT using ports 137 138 UDP and 139 TCP
Hackers are now interested in finding this information Server applications and versions Hackers find out what web, FTP, and mail server versions you are running by listening to TCP and UDP ports and sending random data to each. Hackers cross-reference this information using vulnerability databases to look for potential exploits. The SecurityFocus website at http www.securityfocus.com provides an index of exploits and vulnerabilities. Exploiting selected TCP ports Hackers select TCP ports based...
Encrypting Passwords Using the service passwordencryption Command
Encrypts all clear text passwords in the router configuration file Boston(config) service password-encryption Encrypts all clear text passwords in the router configuration file Boston(config) service password-encryption Just like console and vty passwords, auxiliary passwords are not encrypted in the router configuration. This is why it is important to use the service password-encryption command. With the exception of the enable secret password, all Cisco router passwords are, by default,...
DoS Attacks
A DoS attack damages or corrupts your computer system or denies you and others access to your networks, systems, or services. DoS attack techniques almost always use IP spoofing. Yahoo was so, off line for several hours. E*TRADE suffered problems from a similar flood attack. Buy.com was offline for several hours. Amazon.com was offline for more than an hour. CNN was mostly unreachable for 2 hours. DoS attacks are the most publicized form of attack. They are also among the most difficult to...
Change passwords often
When creating passwords for Cisco routers, always keep these rules in mind It is best to have a minimum of 10 characters for a password. Passwords may include the following A mix of uppercase and lowercase characters Passwords should not use dictionary words. Password-leading spaces are ignored, but all spaces after the first character are not ignored. You should decide when and how often the passwords will be changed. You may want to add your own rules to this list to make your passwords even...
Security posture assessment analysis and documentation
By assessing all aspects of the networked business environment, it is possible to determine the ability of the organization to detect, defend against, and respond to network attacks. These are the key activities Security posture assessment The first step in planning network security requires an evaluation of the network security posture of the organization. The security posture assessment provides a snapshot of the security state of the network by conducting a thorough assessment of the network...
The aaa authentication enable default command
After enabling AAA globally on the access server, you need to define the authentication method lists and apply them to lines and interfaces. These authentication method lists are security profiles that indicate the service, PPP, dotlx, or login and authentication method. Up to four authentication methods (local, group TACACS+, group RADIUS, line, or enable authentication) may be applied to a line or interface. A good security practice is to have either local or enable authentication as the...
SNMP Security Is Not My Problem
SNMP was developed to manage nodes (servers, workstations, routers, switches, hubs, and security appliances) on an IP network. All versions of SNMP are application layer protocols that facilitate the exchange of management information between network devices. SNMP is part of the TCP IP protocol suite. SNMP enables network administrators to manage network performance, find and solve network problems, and plan for network growth. SNMP version 1 (SNMPvl) and SNMP version 2 (SNMPv2) are based on...
Setting a Login Failure Rate
This topic describes how to secure administrative access to Cisco routers by setting a login failure rate. Authentication Failure Rate with Logging security authentication failure rate threshold-rate log This command configures the number of allowable unsuccessful login attempts. By default, the router allows 10 login failures before initiating a 15-second delay. This command generates a syslog message when the rate is exceeded. Boston(config) security authentication failure rate 10 log...
Locking Down a Router with Cisco Auto Secure
Cisco AutoSecure will modify the configuration of your device. Cisco AutoSecure configuration enhances the security of the router, but it will not make it absolutely resistant to all security attacks. Is this router connected to internet no y Enter the number of interfaces facing internet 1 1 Enter the interface name that is facing internet FastEthernet0 0 Securing Management plane services Disabling service finger Disabling service pad Disabling udp & tcp small servers Enabling service...
Inband management guidelines
- Apply only to devices needing to be managed or monitored - Decide whether the management channel needs to be open at all times - Keep clocks on hosts and network devices synchronized - Record changes and archive configurations The figure outlines guidelines for OOB and in-band management of the architecture. As a general rule, OOB management is appropriate for large enterprise networks. In smaller networks, in-band management is recommended as a means of achieving a more cost-effective...
Use SYN rate limiting
When attacks involve specific network server applications, such as an HTTP server or an FTP server, the attacker focuses on acquiring and keeping all the available connections supported by that server open. This strategy effectively locks out valid users of the server or service. DoS attacks can also be implemented using common Internet protocols, such as TCP and ICMP. For example, ping of death and teardrop attacks exploit limitations in the TCP IP protocols. While most DoS attacks exploit a...
Cisco Integrated Security Portfolio
This topic describes the positioning of the Cisco integrated security portfolio. Cisco SOHO 90 Cisco 800 Cisco 1700 Cisco 2600 Cisco 3600 Cisco 3700 Cisco 7xxx Series Routers Series Routers Series Routers Series Routers Intrusion Detection and Prevention Systems Cisco PIX 500 Series Security Appliances Cisco ASA 5500 Series Adaptive Security Appliances Cisco ASA 5500 Series Adaptive Security Appliances Cisco PIX 500 Series Security Appliances Cisco SOHO 90 Cisco 800 Cisco 1700 Cisco 2600 Cisco...
Components of Network Security Design
This topic describes the factors that you need to consider when designing a network security system. Business goals and risk analysis drive the need for network security. Regardless of the security implications, business needs must come first. If your business cannot function because of security concerns, you have a problem. The security system design must accommodate the goals of the business, not hinder them. Risk analysis includes these two key elements What does the cost-benefit analysis of...
Launching Cisco SDM
SDM will be launched from the PC using the If you installed Cisco SDM on an administrator PC, go to the Microsoft Windows program menu (choose Start > Programs (All Programs) > Cisco Systems > Cisco SDM). Then provide the IP address of the LAN interface on the router as configured previously with the Cisco SDM Express Wizard in the Cisco SDM Launcher window. If Cisco SDM is on the router flash memory, open a web browser and enter the new IP address of the LAN interface there. Follow the...
Programs and utilities
Uwhois The http www.uwhois.com web interface performs whois lookups, forward and reverse DNS searches, and traceroutes. Nmap Network Mapper (Nmap) is a free open source utility for network exploration or security auditing. Nmap rapidly scans large networks and single hosts. Go to http www.insecure.org nmap . Foundstone ScanLine Foundstone ScanLine is a Microsoft Windows NT-based port scanner. 2006 Cisco Systems, Inc. Introduction to Network Security Policies 1-83 Keep all sensitive data off...
Sets the minimum length of all Cisco IOS passwords
Boston(config) security passwords min-length 10 Cisco IOS Release 12.3(1) and later allows administrators to set the minimum character length for all router passwords using the security passwords global configuration command. This command provides enhanced security access to the router by allowing you to specify a minimum password length (0 to 16 characters) this eliminates common passwords that are short and prevalent on most networks, such as lab and cisco. This command affects user...
Threats to and Attacks on Routers
Information theft Examples of attack techniques IP fragmentation attacks for DoS Some general threats to routers include (but are not limited to) unauthorized access, session hijacking, rerouting, masquerading, DoS, eavesdropping, and information theft. Unauthorized access may occur when one of the following occurs Session hijacking may occur if an attacker can insert falsified IP packets after session establishment via IP spoofing, sequence number prediction and alteration, or other methods....
Enables secure calls from Cisco IP phones to Cisco Call Manager
The High Density Voice Network Module (NM-HDV) contains five 72-pin single inline memory module (SIMM) sockets or banks for packet PVDMs numbered 0 through 4. Each socket can be filled with a single 72-pin PVDM. The PVDMs must be installed starting from slot 0. Note PVDM and PVDM2 modules are not interchangeable. Use PVDM modules with the NM- HDV network module only, and use PVDM2 modules with the NM-HDV2 network module only. The PVDM2 modules are used with onboard voice interface cards on the...
Adaptive Threat Defense
ATD is the ultimate goal of the Cisco Self-Defending Network. This topic describes the components of the ATD phase of Cisco Self-Defending Network strategy. ATD Products, Services, and Architecture Example Access Control, Packet Inspection Firewall Services Application Intelligence, Content Identity, Virtualization, QoS Inspection, Virus Mitigation Segmentation, Traffic Visibility IPS and Antivirus Services Network Intelligence Application Inspection, Use Enforcement, Web Control Application...
The terminal can be a dumb terminal or a PC with terminal emulation software
Configuring secure administrative access is an extremely important security task. If an unauthorized person were to gain administrative access to a router, the person could alter routing parameters, disable routing functions, or discover and gain access to other systems in the network. Strong passwords and similar secrets, such as Simple Network Management Protocol (SNMP) community strings, are the primary defense against unauthorized access to your router. The best way to handle most passwords...
Trust Exploitation
A hacker leverages existing trust relationships. by a hacker. User psmith Pat Smith by a hacker. User psmith Pat Smith Although it is not an attack in itself, trust exploitation refers to an individual taking advantage of a trust relationship within a network. An example of trust exploitation occurs when a perimeter network is connected to a corporate network. These two network segments often house DNS, Simple Mail Transfer Protocol (SMTP), and HTTP servers. Because these servers all reside on...
Port redirectors can help bypass port filters routers and firewalls and may even be encrypted over a Secure Sockets
Back doors provide hackers with a way into the system if they are detected trying to enter through the front door, or if they want to enter the system without being detected. The most common backdoor point is a listening port that provides remote access to the system for users (hackers) who do not have, or do not want to use, access or administrative privileges. Firewalls or router filtering may prevent the hacker from later accessing these ports. However, common router filtering may not block...
Launching Cisco SDM Express
- For a new router, in a web browser go to - For existing routers go to https < router IP address> The first time that you access the router by web browser, you will get the Cisco SDM Express wizard. On a new router, you can access Cisco SDM Express from your PC web browser by going to IP address http 10.10.10.1. The factory default router configuration file that comes with Cisco SDM configures the router Ethernet IP address to 10.10.10.1. If the proper files are loaded on the router flash...
Generation of system logging messages for login detection
The Cisco IOS Login Enhancements feature allows users to better secure their Cisco IOS devices when creating a virtual connection, such as Telnet, SSH, or HTTP. Thus, users can help slow down dictionary attacks and help protect their router from a possible denial of service (DoS) attack. To better configure security when opening a virtual login connection, these requirements have been added to the login process Delays between successive login attempts Login shutdown if DoS attacks are suspected...
Verifies that the login blockfor command is issued
To enable a login delay and to log successful and failed attempts to login, use the commands shown in the figure. This sample output from the show login command verifies that the login block-for command is issued. In this example, the command is configured to block login hosts for 100 seconds if more than 15 (16 or more) login requests fail within 100 seconds. Five login requests have already failed. A default login delay of 1 seconds is applied. No Quiet-Mode access list has been configured....
Setting Multiple Privilege Levels
This topic describes how to secure administrative access to Cisco routers by setting multiple privilege levels. privilege mode level level command reset command Level 0 is predefined for user-level access privileges. Levels 1 to 14 may be customized for user-level privileges. Level 15 is predefined for enable mode (enable command). Boston(config) privilege exec level 2 ping Boston(config) enable secret level 2 Patriot2006 Cisco routers enable you to configure various privilege levels for your...
Enables password checking at login for vty Telnet sessions
Boston(config) line vty 0 4 Boston(config-line) login Boston(config-line) password Cisco routers support multiple Telnet sessions (up to five simultaneous sessions by default, and more can be added), each serviced by a logical vty line. By default, Cisco routers do not have any line-level passwords configured for these vty lines. If you enable password checking, you must also configure a vty password before attempting to access the router using Telnet. If you fail to configure a vty password...
Password Attack Example
L0phtCrack can take the hashes of passwords and generate clear text passwords from them. Passwords are computed using two methods Just as with packet sniffer and IP spoofing attacks, a brute-force password attack can provide access to accounts that attackers then use to modify critical network files and services. For example, an attacker compromises your network integrity by modifying your network routing tables. This trick reroutes all network packets to the attacker before transmitting them...
RFC 3704 filtering at the perimeter router should be used to mitigate the chance of an outside attacker spoofing the
The first recommendation is to use IPsec, SSH, or SSL to encrypt management traffic to protect sensitive information such as the device configuration, passwords, and other sensitive data. Regardless of whether you use SSH, SSL, or Telnet for remote access to the managed device, you should also configure ACLs to allow only management servers to connect to the device. Deny and log all attempts from other IP addresses logged. Implement RFC 3704 filtering at the ingress router to reduce the chance...
Mitigating Worm Attacks
Worm attack mitigation requires diligence on the part of system and network administration staff. Coordination between system administration, network engineering, and security operations personnel is critical in responding effectively to a worm incident. There are four recommended steps for worm attack mitigation Containment Contain the spread of the worm inside your network and within your network. Compartmentalize uninfected parts of your network. Inoculation Start patching all systems and,...
Adds commands or interfaces to a view
Router(config-view) commands exec include show version Next, you must assign the commands allowed to the selected view. The syntax for the commands command is as follows commands parser-mode include include-exclusive exclude all interface interfacename command Adds commands or interfaces to a view The mode in which the specified command exists Adds a command or an interface to the view and allows the same command or interface to be added to an additional view Adds a command or an interface to...
Cisco Career Certifications Cisco Certified Security Professional
Expand Your Professional Options and Advance Your Career Professional-level recognition in network security Recommended Training Through Cisco Learning Partners Securing Networks with PIX and ASA (SNPA) Implementing Cisco Intrusion Prevention Systems (IPS) You are encouraged to join the Cisco Certification Community, a discussion forum open to anyone holding a valid Cisco Career Certification (such as Cisco CCIE , CCNA , CCDA , CCNP , CCDP , CCIP , CCVP , or CCSP ). It provides a gathering...
Anatomy of a Worm Attack
The anatomy of a worm attack is as follows The enabling vulnerability A worm installs itself on a vulnerable system. Propagation mechanism After gaining access to devices, a worm replicates and selects new targets. Payload After the worm infects the device, the attacker has access to the host often as a privileged user. Attackers use a local exploit to escalate their privilege level to the administrator level. 2006 Cisco Systems, Inc. Introduction to Network Security Policies 1-67
Troubleshooting AAA for Cisco Routers
This topic explains how to troubleshoot AAA on a Cisco peripheral router using debug aaa commands. Use these debug commands on your routers to trace AAA packets and monitor authentication, authorization, or accounting activities The debug aaa authentication command displays debugging messages on authentication functions. The debug aaa authorization command displays debugging messages on authorization functions. The debug aaa accounting command displays debugging messages on accounting...
HELLO Welcome to httpwwwwormcom Hacked By Chinese
Port redirectors can help bypass port filters, routers, and firewalls, and can evade intrusion detection. For example, assume that a firewall has ports 80 (HTTP) and 443 (HTTPS) open by default, but port 443 is unused. Assume that there is a database server on port 3389 (ms-wbt-server). A hacker can select port 443 as a listening port and remain undetected. The hacker can then set up a port redirector without disrupting operations. A port redirector takes traffic coming in on one port and...
Step 6 show secure bootset
The Cisco IOS Resilient Configuration feature enables a router to secure and maintain a working copy of the running image and configuration so that those files can withstand malicious attempts to erase the contents of persistent storage (NVRAM and flash storage). A great challenge for network operators is the total downtime experienced after a router has been compromised and its operating software and configuration data erased from its persistent storage. The operator must retrieve an archived...
Configuring AAA with Cisco SDM
AAA can also be configured and edited using Cisco SDM. After the aaa new-model command has been configured on the router using the CLI, choose Additional Tasks > AAA. The figure shows the AAA Authentication Login configuration screen. It shows the two login authentication method lists configured on the router. One is the default method list, and the other is the sdm_vpn_xauth_ml_1 method list. Both method lists use the local database to perform login authentication. This screen can be used to...




















