Configuring Internal Cisco Router Security - myoddPc

Computer Information - myOddPc

Configuring Internal Cisco Router Security

Network security is a hot topic today, and will only increase in importance in the months and years ahead.While most of the attention is paid to exterior threats, there are some steps you can take to prevent unwanted Cisco router access from within your organization.Whether you want to limit what certain users can do and run on your routers, or prevent unauthorized users in your company from getting to config mode in the first place, here are four important yet simple steps you can take to do so.Encrypt the passwords in your running configuration.This is a basic Cisco router security command that is often overlooked. It doesn’t do you any good to set passwords for your ISDN connection or Telnet connections if anyone who can see your router’s running configuration can see the passwords. By default, these passwords are displayed in your running config in clear text.One simple command takes care of that. In global configuration mode, run service password-encryption. This command will encrypt all clear text passwords in your running configuration.Set a console password.If I walked into your network room right now, could I sit down and start configuring your Cisco routers?If so, you need to set a console password. This password is a basic yet important step in limiting router access in your network. Go into line configuration mode with the command “line con 0”, and set a password with the password command.Limit user capabilities with privilege level commands.Not everyone who has access to your routers should be able to do anything they want. With careful use of privilege levels, you can limit the commands given users can run on your routers.Privilege levels can be a little clumsy at first, but with practice you’ll be tying your routers down as tight as you like. Visit www.cisco.com/univercd for documentation on configuring privilege levels.Configure an “enable secret” password.It’s not uncommon for me to see a router that has an enable mode password set, but it’s in clear text.By using “enable secret”, the enable mode password will automatically be encrypted. Remember, if you have an enable password and enable secret password set on the same router, the enable secret password takes precedence.These four basic steps will help prevent unwanted router access from inside your network. If only preventing problems from outside your network was as simple!Chris Bryant, CCIE (TM) #12933, has been active in the Cisco certification community for years. He has written several books that have helped CCNA candidates around the world achieve the coveted CCNA certification, including several concentrating on binary math conversions and subnetting questions that the average CCNA candidate will need to answer on their CCNA exams.He is the owner of The Bryant Advantage (http://www.thebryantadvantage.com) where he teaches affordable world-class CCNA courses via the Internet, and sells his popular Cisco certification books. He’s proud to have helped CCNA candidates around the world achieve their career goals. Mr. Bryant’s books and courses are sold on his site, on eBay, and on several other major Cisco certification sites.

Chris Bryant

Sony PSP - Not Just For Games

Zen and the Art of Buying Computer Parts
The Ugly Face Of Technology
Wind Turbine Lights to Protect Birds
Robotic Manufacturing Lighting
Is that software really free?
Tips on Finding the Best CD Duplication Services
Making the Most of Digital Camera Memory Cards
Microsoft Dynamics GP & CRM in Transportation & Logistics
Computer Dos and Donts
Sony PSP - Not Just For Games

SyncUp – A File/Folder Synchronizer For Windows

Basic Tips and tricks for Windows XP
Buying the Perfect Computer – The FIRST Time
Dirty Little Computer Viruses and How To Protect Yourself
10 Secrets to a Healthy Computer and a Happier You
8 Simple Ways to Defend Against Evil Doers Both Online and Off
Microsoft CRM Programming Secrets – Tips For Developers
Microsoft Great Plains Integration with Legacy Systems – Overview For Developer
Microsoft RMS – Great Plains Integration – Overview For IT Specialist
Removing Incoming Email in MS Exchange, C# Example
SyncUp – A File/Folder Synchronizer For Windows

Articles by the same author

Cisco CCNA Certification:

Becoming A Truly Valuable CCNA.

Cisco Certification:

Five Things To Do DURING Your CCNA Exam

Cisco CCNA Cerfication:

Should You Take The One-Exam or Two-Exam Approach?

Cisco Certification:

How To Become A Truly Valuable CCNA

Cisco Certification:

The Joy Of Hex

Cisco Certification:

What To Do DURING Your Exam!

Cisco Certification:

Introduction To ISDN, Part I

Configuring Internal Cisco Router Security
Introduction To ISDN, Part II
Cisco Certification: Introduction To ISDN, Part III
Cisco Certification:

Introduction To ISDN, Part IV

Cisco Certification:

Introduction To ISDN, Part V

Cisco Certification:

Building Your Own Home Lab, Part I

Cisco Certification:

Building Your Home Lab, Part II

Cisco Certification:

Taking Your First Certification Exam

Learning To Navigate Ciscos Online Documentation
Cisco Certification:

What To Expect On Exam Day

Cisco Certification:

A Survival Guide To The Cisco Cable Jungle

Introduction To ISDN, Part III: PAP
How To Become A True CCNA
Cisco CCNA Certification:

Why You NEED Hands-On Practice !

Cisco CCNP Certification: Introduction To BGP
Cisco CCNA Certification: Five Things To Do DURING The Exam
The Hidden Value Of Computer Certifcations
Cisco Certification: The OSI Model Isnt Just For Exams Anymore!
Cisco Certification: The OSI Model, Part I
Cisco CCNA Certification:

The Hidden Details Of Telnet

Cisco CCNA Certification:

Passwords, Passwords, Passwords!

Cisco Certification:

Suggested Toplogies For Your Home CCNA / CCNP Lab

Cisco CCNA Certification:

An Illustrated Guide To Ethernet CSMA/CD

Cisco Certification:

The Definitive Guide To ARP, IARP, RARP, and Proxy ARP

Cisco CCNA Candidate FAQ
Cisco CCNA / CCNP Certification:

OSPF ASBRs Explained And Illustrated

Cisco Certification:

Dont Delay Those CCNA Studies!

Cisco Certification: The Most Important Cisco Study Youll Ever Do
MCSE? CCNA? How To Choose The Best Computer Certification For You
Cisco CCNA / CCNP Home Lab Setup Tutorial:

How To Buy & Build A Frame Relay Switch

Cisco Routing:

ip Default-network Vs. Default Static Routes

Cisco CCNA / CCNP Home Lab Tutorial:

Buying And Configuring An Access Server

Cisco Routing For The CCNA And CCNP: Administrative Distance
Computer Certification:

Keeping Your Cool On Exam Day

Disclaimer

Please note that this website is for information only. Whilst every care has been taken to provide accurate information you should always seek the advice of a professional before attempting any repairs or making any purchase(s).
You need to take special care to ensure that the information given applies your system.

Mortgages
Mortgages information help and advice from the experts at Moneyweb.

Loans
Finance options from Get Finance - the loan company.
marker About Us | Site Map | Privacy Policy | Contact Us | ©2005-2006