Secure Management and Reporting Planning Considerations

This topic explains the factors you must consider when planning the secure management and reporting configuration of network devices. Secure Management and Reporting Planning Considerations Which are the most important logs How are important messages separated from routine notifications How do you prevent tampering with logs How do you make sure time stamps match What log data is needed in criminal investigations How do you deal with the volume of log messages How do you manage all the devices...

Vulnerable Router Services

Disable unnecessary services and interfaces (BOOTP, CDP, FTP, TFTP, NTP, PAD, and TCP UDP minor services) Disable commonly configured management services (SNMP, HTTP, and DNS) Ensure path integrity (ICMP redirects and IP source routing) Disable probes and scans (finger, ICMP unreachables, and ICMP mask replies) Ensure terminal access security (ident and TCP keepalives) Disable gratuitous and proxy ARP Disable IP directed broadcast The services listed in the figure have been chosen for their...

Protocolspecific debug

Use the debug ip inspect EXEC command to display messages about firewall events. debug ip inspect function-trace object-creation object-deletion events timers Displays messages about software functions called by the firewall. Displays messages about created software objects. Object creation corresponds to the beginning of inspected sessions. Displays messages about deleted software objects. Object deletion corresponds to the closing of inspected sessions. Displays messages about software...