Secure Management and Reporting Planning Considerations
This topic explains the factors you must consider when planning the secure management and reporting configuration of network devices. Secure Management and Reporting Planning Considerations Which are the most important logs How are important messages separated from routine notifications How do you prevent tampering with logs How do you make sure time stamps match What log data is needed in criminal investigations How do you deal with the volume of log messages How do you manage all the devices...
Vulnerable Router Services
Disable unnecessary services and interfaces (BOOTP, CDP, FTP, TFTP, NTP, PAD, and TCP UDP minor services) Disable commonly configured management services (SNMP, HTTP, and DNS) Ensure path integrity (ICMP redirects and IP source routing) Disable probes and scans (finger, ICMP unreachables, and ICMP mask replies) Ensure terminal access security (ident and TCP keepalives) Disable gratuitous and proxy ARP Disable IP directed broadcast The services listed in the figure have been chosen for their...
Protocolspecific debug
Use the debug ip inspect EXEC command to display messages about firewall events. debug ip inspect function-trace object-creation object-deletion events timers Displays messages about software functions called by the firewall. Displays messages about created software objects. Object creation corresponds to the beginning of inspected sessions. Displays messages about deleted software objects. Object deletion corresponds to the closing of inspected sessions. Displays messages about software...
- A DMZ is established between security zonesDMZs are buffer networks which are neither inside nor outside
- A maximum of 15 CLI views can exist in addition to the root view
- A state table is maintained with session information ACLs are dynamically created or deleted Cisco IOS Firewall protects against DoS attacks
- AAA Accounting Example
- AAA operations can be offloaded to a Tacacs or Radius server to increase security and scalability
- AAA Protocols Radius and TACACS
- About 1500 for IPS sensors 1200 for Ios Ips
- Access Attacks
- Additional Authentication
- Advanced Firewall Configuration Summary and Deployment
- Advanced Firewall DMZ Service Configuration
- Advanced Firewall DMZ Service Configuration TCP
- Advanced Firewall DMZ Service Configuration UDP
- Advanced Firewall Inspection Parameters
- Advanced Firewall Interface Configuration
- Advanced Firewall Protocols and Applications
- Advanced Firewall Protocols and Applications Cont - 2
- Advanced Firewall Security Policy
- Alert audittrail and timeout are configurable per protocol and override global settings
- Alert is sent to management station
- Alerts and Audit Trails
- ALG Firewall Device
- Allows the attacker to use other attack methods
- Antisniffer Tools
- Application layer attacks have these characteristics
- Applies predefined or custom rules
- Apply an Inspection Rule to an Interface
- Applying ACLs to Router Interfaces
- Applying Authentication Policy to VTY Lines
- Applying Authorization Policy to VTY Lines
- Authentication
- Authorization Example
- Auto Secure can selectively lock down
- Basic Firewall Configuration Summary and Deployment
- Basic Firewall Interface Configuration
- Better than the type 7 encryption found in service passwordencryption command
- Blues Port Scanner and Ethereal
- Caveats
- Change passwords
- Character Mode Login Example
- Cisco Device Hardening
- Cisco IOS Firewall addresses these shortcomings of ACLs
- Cisco IOS Firewall TCP Handling
- Cisco IOS Firewall UDP Handling
- Cisco Ios Ips
- Cisco Ios Ips Alarms
- Cisco Ios Ips can be configured tuned and monitored through the CLI or SDM which offers a wizard for simplified provisioning
- Cisco Ios Ips Configuration Steps
- Cisco IOS Resilient Configuration Feature Verification
- Cisco Log Severity Levels
- Cisco Self Defending Network
- Combining Access Functions
- Configure AAA Login Authentication on Cisco Routers Using CLI
- Configure Basic IPS Settings
- Configure Enhanced IPS Settings
- Configure the Line Level Password
- Configuring a Basic Firewall
- Configuring a Login Authentication Policy
- Configuring Additional NTP Options
- Configuring an EXEC Authorization Policy
- Configuring an SNMP Managed Node
- Configuring an SSH Server for Secure Management and Reporting
- Configuring CLI Views
- Configuring Interfaces on an Advanced Firewall
- Configuring NTP Associations
- Configuring NTP Authentication
- Configuring Superviews
- Configuring Syslog Logging
- Configuring the AAA Server
- Configuring VTY Line Parameters
- Covers the gray area of possibly malicious traffic that IPS did not stop
- Creating a Login Authentication Policy
- Creating an EXEC Authorization Policy
- Creating Security Banner
- Cryptography
- Defining Radius Servers
- Disabling a Signature Group
- Displays inspections interface configurations sessions and statistics
- Displays login parameters and failures
- Distributed DoS Attack Mitigation TRIN00
- Distributed DoS Attacks
- Distributed DoS Example - 2
- DoS and Distributed DoS Attack Mitigation
- DoS Attacks and Mitigation
- DoS prevention
- DoS Tcp Syn Attack Mitigation Blocking External Access
- Editing a Signature
- Enables realtime alerts
- Enabling AAA in SDM
- Encrypting Passwords Using the service passwordencryption Command
- Enforce the use of ACLs
- Evolution of Cisco Self Defending Network
- Example - 2
- Example Three Interface Firewall
- Excluding Addresses from Login Blocking
- Exploit Signatures
- Filtering Network Traffic to Mitigate Threats
- Four steps to mitigate worm attacks
- Global Settings
- Guidelines for Applying Inspection Rules and ACLs to Interfaces
- Hackers implement password attacks using the following
- HIPS does not require special hardware
- Hostbased
- How Cisco IOS Firewall Works
- I f t J J I
- Identifying ACLs
- Identifying Interfaces and Flow Direction
- Implementing AAA
- Implementing NTP Server
- InBand Management Considerations
- Initial Configuration Dialog
- Internet Information Queries
- Introduction to AAA
- Intrusion Detection System
- IP directedbroadcast
- IP Spoofing in DoS and DDoS
- IP Spoofing in DoS and Distributed DoS
- IPS Policies
- IPS Policies Wizard Overview
- Launching the IPS Policies Wizard
- Layered Defense Features
- Log Message Format
- Management Protocol Best Practices
- Management Protocols and Vulnerabilities
- Maninthe Middle Attacks and Their Mitigation
- Microsoft Baseline Security Analyzer
- Mitigating Network Attacks
- Modify parameters
- Module Objectives - 2
- Module Self Check
- Module Self Check Answer
- Multiple DMZs
- Netcat
- Netcat Example
- New sensors can be easily added to new networks
- NIDS and NIPS Deployment
- NTP Configuration Example
- Objectives - 2 3 4 5 6 7 8 9
- Observe and block or alarm if a known malicious event is detected
- One Step Lockdown
- Overview - 2 3 4 5 6
- Packet Filtering Example
- Packet filtering limits traffic into a network based on the destination and source addresses ports and other flags compiled in an ACL
- Packet Sniffers
- Password Attack Example - 2
- Password attack mitigation techniques
- Password Minimum Length Enforcement
- Passwords and AAA
- Port Redirection
- Port Scan and Ping Sweep Mitigation
- Port Scans and Ping Sweeps
- Porttoapplication mapping PAM
- Preparing for Firewall Activity Viewing
- Prior to 1238T you should save the running configuration before running Auto Secure
- Proper configuration of the filtering device is critical
- Provides dynamic peruser authentication and authorization via Tacacs and Radius protocols
- Radius Attributes
- Radius Authentication and Authorization
- Radius Features
- Radius Messages
- References - 2
- Requires a policy database
- Resulting Advanced Firewall ACL Configuration
- Resulting Advanced Firewall Inspection Rule Configuration
- Resulting Advanced Firewall Interface Configuration
- Resulting Basic Firewall ACL Configuration
- Resulting Basic Firewall Inspection Rule Configuration
- Reviewing the Basic Firewall for the Returning Traffic
- RFC 3704 Filtering
- Router Access Modes
- Router Hardening Considerations
- SDM One Step Lockdown Main Window
- SDM Security Audit
- SDM Security Audit Fix the Security Problems
- SDM Security Audit Main Window
- Secure Configuration Files
- Secure Management and Reporting Guidelines
- Secure the forwarding plane
- Securing Management Plane Services
- Securing ROMMON
- Selecting a Signature
- Selecting SDF Location
- Selecting SDF Location Cont
- Setting a Login Delay
- Setting a Login Failure Blocking Period
- Setting Multiple Privilege Levels
- Setting Timeouts
- Signature Examples
- SNMP Security Models and Levels
- SNMPv3 Architecture
- SNMPv3 Configuration Example
- SNMPv3 Features and Benefits
- SNMPv3 Operational Model
- Specifies that privacy should not be expected when using this system
- SSH and Interface Specific Services
- Start and Interface Selection
- Stateful firewalls operate mainly at the connection TCP and UDP layer
- Stateful inspection then remembers certain details or the state of that request
- Stateful Packet Filter Handling of Different Protocols
- Student Guide
- Summary - 2 3
- Summary Cont 4 5 6 7 8 9
- Supported Protocols
- Syslog Implementation Example
- Syslog Systems
- Tacacs Attributes and Features
- Tacacs Authentication
- Tacacs Command Authorization
- Tacacs Network Authorization
- Test and verify
- The aaanew model must be enabled
- The ALG intercepts and establishes connections to the Internet hosts on behalf of the client
- The Anatomy of a Worm Attack
- The following tools are useful when determining general network vulnerabilities
- The no service passwordrecovery command prevents console from accessing ROMMON
- The terminal can be a dumb terminal or a PC with terminal emulation software
- These management protocols can be compromised
- These practices are recommended
- Troubleshoot AAA Authentication Example
- Troubleshoot AAA Login Authentication on Cisco Routers
- Troubleshooting Accounting
- Troubleshooting Cisco IOS Firewall
- Trust Exploitation
- Trust Exploitation Attack Mitigation
- Tune or disable individual signatures
- Types of IDS and IPS Systems
- Types of Network Attacks Cont
- Typically used as IDS not IPS
- Understanding NTP
- Use this command to help troubleshoot AAA authorization problems
- Using Syslog Logging for Network Security
- Using Traffic Filtering with ACLs
- Verifying AAA Login Authentication Commands
- Verifying Cisco IOS Firewall
- Verifying Ios Ips Configuration
- Viewing All SDEE Messages
- Viewing Firewall
- Viewing SDEE Alerts
- Viewing SDEE Status Messages
- Viewing the IPS Policies Wizard Summary
- Views can be grouped to superviews to create large sets of accessible commands and interfaces
- Virus and Trojan Horse Attack Mitigation
- Volume
- Worm Virus and Trojan Horse Attacks and Mitigation
