91超碰碰碰碰久久久久久综合_超碰av人澡人澡人澡人澡人掠_国产黄大片在线观看画质优化_txt小说免费全本

溫馨提示×

溫馨提示×

您好,登錄后才能下訂單哦!

密碼登錄×
登錄注冊×
其他方式登錄
點擊 登錄注冊 即表示同意《億速云用戶服務條款》

Cisco Switches/Router Layer 3 Security

發布時間:2020-06-03 20:41:44 來源:網絡 閱讀:594 作者:hj192837 欄目:移動開發

1. Enable secure Telnet access to a router user interface, and consider using Secure Shell (SSH) instead of Telnet.
2. Enable SNMP security, particularly adding SNMPv3 support.
3. Turn off all unnecessary services on the router platform ( AutoSecure ).
4. Turn on logging to provide an audit trail.
5. Enable routing protocol authentication.
6. Enable the CEF forwarding path to avoid using flow-based paths like fast switching.

7. Using RPF Checks

example:

R1(config)# ip cef
R1(config)# int s0/0
R1(config-if)# ip verify unicast source reachable-via rx allow-default

8. Using ACL to prevent TCP SYN Flood from outside

example:

ip access-list extended prevent-syn
   permit tcp any 10.0.0.0 0.255.255.255 established
   deny tcp any 1.0.0.0 0.255.255.255
   permit (whatever)
!
interface s0/0  # Internet faced port
   ip access-group prevent-syn in

Notes: The above ACL works well when clients outside a network are not allowed to make TCP connections into the network. However, in cases where some inbound TCP connections are allowed, this ACL cannot be used. Another Cisco IOS feature, called TCP intercept, provides an alternative that  allows TCP connections into the network, but monitors those TCP connections for TCP SYN attacks.

example:

ip access-list extended match-tcp-from-internet
   permit tcp any 10.0.0.0 0.255.255.255

ip tcp intercept-list match-tcp-from-internet
ip tcp intercept mode watch
ip tcp intercept watch-timeout 20

9.Cisco IOS Firewall CBAC

example:

ip inspect name CLASSIC_FW icmp timeout 10
ip inspect name CLASSIC_FW tcp timeout 30
ip inspect name CLASSIC_FW udp timeout 30
!
ip access-list extended IOS_FW
   deny ip any any
!
interface Serial0/0  #Internet faced interface
   ip address 192.168.1.3 255.255.255.0
   ip access-group IOS_FW in
   ip inspect CLASSIC_FW out

!

10. Cisco IOS Zone-Based Firewall

example:

Cisco Switches/Router Layer 3 Security

In this example, the network administrators have decided to apply the following policies to traffic from the LAN zone going through the WAN zone:
■ Only traffic from the LAN subnet is allowed.
■ HTTP traffic to corporate web-based intranet servers is allowed.
■ All other HTTP traffic is allowed but policed to 1 Mbps.
■ ICMP is blocked.
■ For all other traffic, the TCP and UDP timeouts must be lowered to 300 seconds.

Follow these steps to configure ZFW:


Step 1: Decide the zones you will need, and create them on the router.

Branch2(config)# zone security LAN
Branch2(config-sec-zone)# description LAN zone
!
Branch2(config)# zone security WAN
Branch2(config-sec-zone)# description WAN zone


Step 2: Decide how traffic should travel between the zones, and create zone-pairs on the router.

Branch2(config)# zone-pair security Internal source LAN destination WAN
Branch2(config)# zone-pair security External source WAN destination LAN


Step 3: Create class maps to identify the inter-zone traffic that must be inspected by the firewall.

Branch2(config)# ip access-list extended LAN-Subnet
Branch2(config-ext-nacl)# permit ip 10.1.1.0 0.0.0.255 any
!
Branch2(config-ext-nacl)# ip access-list extended Web_Servers
Branch2(config-ext-nacl)# permit tcp 10.1.1.0 0.0.0.255 host 10.150.2.1    
Branch2(config-ext-nacl)# permit tcp 10.1.1.0 0.0.0.255 host 10.150.2.2
!
Branch2(config-ext-nacl)# class-map type inspect match-all Corp_Servers
Branch2(config-cmap)# match access-group name Web_Servers
Branch2(config-cmap)# match protocol http
!
Branch2(config-cmap)# class-map type inspect Other_HTTP
Branch2(config-cmap)# match protocol http
Branch2(config-cmap)# match access-group name LAN_Subnet
!
Branch2(config-cmap)# class-map type inspect ICMP
Branch2(config-cmap)# match protocol icmp
!
Branch2(config-cmap)# class-map type inspect Other_Traffic
Branch2(config-cmap)# match access-group name LAN_Subnet

Branch2(config)# parameter-map type inspect Timeouts
Branch2(config-profile)# tcp idle-time 300
Branch2(config-profile)# udp idle-time 300


Step 4: Assign policies to the traffic by creating policy maps and associating class maps with them.

Branch2(config-profile)# policy-map type inspect LAN2WAN
Branch2(config-pmap)# class type inspect Corp_Servers
Branch2(config-pmap-c)# inspect
!
Branch2(config-pmap-c)# class type inspect Other_HTTP
Branch2(config-pmap-c)# inspect
Branch2(config-pmap-c)# police rate 1000000 burst 8000
!
Branch2(config-pmap-c)# class type inspect ICMP
Branch2(config-pmap-c)# drop
!
Branch2(config-pmap-c)# class type inspect Other_Traffic
Branch2(config-pmap-c)# inspect Timeouts


Step 5: Assign the policy maps to the appropriate zone-pair.

Branch2(config)# zone-pair security Internal source LAN destination WAN
Branch2(config-sec-zone-pair)# service-policy type inspect LAN2WAN


Step 6: Assign interfaces to zones. An interface may be assigned to only one security zone.

Branch2(config)# interface fa 0/0
Branch2(config-if)# zone-member security LAN
!
Branch2(config-if)# interface s0/0/0
Branch2(config-if)# zone-member security WAN

 

向AI問一下細節

免責聲明:本站發布的內容(圖片、視頻和文字)以原創、轉載和分享為主,文章觀點不代表本網站立場,如果涉及侵權請聯系站長郵箱:is@yisu.com進行舉報,并提供相關證據,一經查實,將立刻刪除涉嫌侵權內容。

AI

常德市| 阿克陶县| 福安市| 绵竹市| 潢川县| 南通市| 浑源县| 许昌县| 富锦市| 乐业县| 寻甸| 德化县| 黑水县| 温州市| 西宁市| 保德县| 林州市| 资中县| 大关县| 铜梁县| 商丘市| 湘潭市| 清丰县| 上杭县| 阿勒泰市| 精河县| 红原县| 尤溪县| 大田县| 巴青县| 金溪县| 临朐县| 安龙县| 原阳县| 崇信县| 商河县| 贵南县| 长子县| 通山县| 新和县| 娱乐|