Home > Securing Cisco routers
Book Chapter:
EMAIL THIS

Securing Cisco routers

16 Dec 2003 | Que

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

This excerpt is from Chapter 3, Securing Cisco Routers, from the book CCSP Secur Exam 2 written by Raman Sud and Ken Edelman, and published by Que. Download the entire chapter for free here.

Assessing the Risk

The most important thing you need to understand is the risks involved in setting up networks via insecure installations. Insecure installation of network devices such as routers and switches would be classified as installs that can be attacked physically or via a configuration weakness.

Let us give you an example: Keeping your network devices under lock and key would prevent meditated physical attacks on the devices. It all depends on the type of environment you work in. Risk can be classified as low or high. High risk is associated with mission-critical devices, and these devices, in most cases, are your backbone routers and distribution layer switches.

Various Physical Threats and Mitigation
Physical threats have four parts:

  • Hardware threats -- All threats that are associated with physical damage to the routers and switches are classified as hardware threats. You can mitigate hardware threats by providing controlled access to the facilities. You limit access to only network-related personnel into the main distribution facility (MDF), intermediate distribution facility (IDF), and network operations center (NOC). You can provide security by ensuring that there is no access to the facility via the ceiling, raised floors, AC ducts, or windows. You can also mitigate hardware threats by using security cameras and by logging entry attempts.
  • Environmental threats -- Threats associated with climatic conditions are environmental threats. To mitigate environmental threats, you need to ensure that there is adequate ventilation in the facility and that the temperature and humidity levels are maintained in accordance with the specifications defined in the equipment documentation. Once these parameters are in place, ensure that you have the ability to remotely manage and monitor temperature and humidity controls. Also make sure that the facility is free from electrostatic discharge (ESD) and magnetic interference.
  • Electrical threats -- Brown-outs, spikes, inadequate power supply, noise and power loss are typical examples of electrical threats. We highly recommend that your mission-critical devices are hooked up to an uninterruptible power supply (UPS). A UPS provides line conditioning and protects your network devices against irregularities in your power distribution system. Ensure that you have redundant power supplies in your network devices (if they support them) or some hot spares at the facility. This measure reduces the amount of downtime on your network. A generator can be an alternate source for power in case of a power outage if your environment is mission critical.
  • Maintenance threats -- Poor cabling, faulty labeling and electronic devices without adequate ESD deterrents are classified as maintenance threats. Make sure that the equipment cabling is labeled properly and that a proper labeling convention is followed. This measure helps in tracing cables in the facility and aids in quick troubleshooting as well. Ensure that cables have smooth bends when you go around the corner. You want no kinks on the cable, so you can guarantee the smooth flow of data.

    Download the rest of this chapter for free here.
    Read more chapter excerpts and book reviews.



    BROWSE BY TAG
    Network Security: Tools, Products, Software,   Network Firewalls, Routers and Switches,   Enterprise Network Security,   Information Security Jobs and Training,   Information Security Careers, Training and Certifications,   VIEW ALL TAGS

    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



    RELATED CONTENT
    Network Firewalls, Routers and Switches
    Best Network Firewall Products
    What is the difference between static and dynamic network validation?
    Screencast: Smoothwall offers firewall defense in lean times
    New Cisco IOS bugs pose tempting targets, says Black Hat researcher
    How to implement virtual firewalls in a complex network infrastructure
    How to manage network bandwidth with distributed ISP bandwidth
    Firewall rule management best practices
    Should enterprises be running multiple firewalls?
    What are the disadvantages of proxy-based firewalls?
    IT pros find corporate firewall rules tough to navigate

    Information Security Jobs and Training
    Despite recession, information security certification pay continues to climb
    Bruce Schneier on outsourcing, awareness training
    Creating a personal brand in information security
    Feds push cybersecurity jobs, PCI DSS changes ahead.
    Feds announce 1,000 new security jobs
    Some IT security certifications are overvalued, analyst says
    How to prepare for an information security job interview
    Security industry remains resilient to tough economy
    Top social networking sites to boost your information security career
    Q2 2009 data shows IT security certification pay still climbing

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    bastion host  (SearchSecurity.com)
    firewall  (SearchSecurity.com)
    Firewall Builder  (SearchSecurity.com)
    screened subnet  (SearchSecurity.com)
    virus  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary




  • Search Additional Security Research and Solutions
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts