Configuring Internal Cisco Router Security
05th November 2005
Author: Chris Bryant
Network security is a hot topic today, and will only increase in importance in the months and years ahead.
While most of the attention is paid to exterior threats, there are some steps you can take to prevent unwanted Cisco router access from within your organization.
Whether you want to limit what certain users can do and run on your routers, or prevent unauthorized users in your company from getting to config mode in the first place, here are four important yet simple steps you can take to do so.
Encrypt the passwords in your running configuration.
This is a basic Cisco router security command that is often overlooked. It doesn’t do you any good to set passwords for your ISDN connection or Telnet connections if anyone who can see your router’s running configuration can see the passwords. By default, these passwords are displayed in your running config in clear text.
One simple command takes care of that. In global configuration mode, run service password-encryption. This command will encrypt all clear text passwords in your running configuration.
Set a console password.
If I walked into your network room right now, could I sit down and start configuring your Cisco routers?
If so, you need to set a console password. This password is a basic yet important step in limiting router access in your network. Go into line configuration mode with the command “line con 0”, and set a password with the password command.
Limit user capabilities with privilege level commands.
Not everyone who has access to your routers should be able to do anything they want. With careful use of privilege levels, you can limit the commands given users can run on your routers.
Privilege levels can be a little clumsy at first, but with practice you’ll be tying your routers down as tight as you like. Visit www.cisco.com/univercd for documentation on configuring privilege levels.
Configure an “enable secret” password.
It’s not uncommon for me to see a router that has an enable mode password set, but it’s in clear text.
By using “enable secret”, the enable mode password will automatically be encrypted. Remember, if you have an enable password and enable secret password set on the same router, the enable secret password takes precedence.
These four basic steps will help prevent unwanted router access from inside your network. If only preventing problems from outside your network was as simple!
Source: http://www.articlealley.com/article_14458_11.html
Chris Bryant, CCIE #12933, is the owner of The Bryant Advantage, home of over 100 free certification exam tutorials, including Cisco CCNA certification test prep articles. His exclusive Cisco CCNA study guide and Cisco CCNA training is also available!
Visit his blog and sign up for Cisco Certification Central, a daily newsletter packed with CCNA, Network+, Security+, A+, and CCNP certification exam practice questions! A free 7-part course, "How To Pass The CCNA", is also available, and you can attend an in-person or online CCNA boot camp with The Bryant Advantage!
http://www.thebryantadvantage.com
Routers Articles
Article Keywords:
Routers |
|
A Quick Note
From The Publisher...
If you like the article above, you may be
interested in the following article which is also related to Routers...
|
Defacto Wireless Distribution, LLC Announces the New AirMatrix High Power Outdoor CPE Featuring Router Functionality and AirMatrixOS Client Software. |
|
The AirMatrix Home 14 HP is the perfect CPE solution. By
utilizing Pacific Wireless's 14 dBi low profile Rootenna and the
router functionality of AirMatrixOS software, AirMatrix has
created a rock solid 250 mW CPE that delivers higher performance
and greater functionality than other CPE solutions.
AirMatrix Home 14 HP is also an incredibly cost-effective
solution. It provides best-effort 11 Mbps fixed wireless
service, bandwidth shaping, DHCP, firewall and an antenna
alignment tool. Featuring Power-over-Ethernet and a fully
integrated outdoor radio unit with antenna, the AirMatrix Home
14 HP practically installs itself! No need for a router to serve
multiple computers, AirMatrix Home 14 HP has full router
functionality and hands out DHCP. The weatherproof high-quality
plastic enclosure and fully weather-tight outdoor Cat5 connector
allows the use of any custom outdoor Ethernet cable length.
AirMatrix OS "wireless (Wi-Fi) router software", is a
Linux-based... |
|
|
|
|

Routers, Computer Networking News |
|
|