Home > Securing Cisco routers
Book Chapter:
EMAIL THIS LICENSING & REPRINTS

Securing Cisco routers

16 Dec 2003 | Que

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

This excerpt is from Chapter 3, Securing Cisco Routers, from the book CCSP Secur Exam 2 written by Raman Sud and Ken Edelman, and published by Que. Download the entire chapter for free here.

Assessing the Risk

The most important thing you need to understand is the risks involved in setting up networks via insecure installations. Insecure installation of network devices such as routers and switches would be classified as installs that can be attacked physically or via a configuration weakness.

Let us give you an example: Keeping your network devices under lock and key would prevent meditated physical attacks on the devices. It all depends on the type of environment you work in. Risk can be classified as low or high. High risk is associated with mission-critical devices, and these devices, in most cases, are your backbone routers and distribution layer switches.

Various Physical Threats and Mitigation
Physical threats have four parts:

  • Hardware threats -- All threats that are associated with physical damage to the routers and switches are classified as hardware threats. You can mitigate hardware threats by providing controlled access to the facilities. You limit access to only network-related personnel into the main distribution facility (MDF), intermediate distribution facility (IDF), and network operations center (NOC). You can provide security by ensuring that there is no access to the facility via the ceiling, raised floors, AC ducts, or windows. You can also mitigate hardware threats by using security cameras and by logging entry attempts.
  • Environmental threats -- Threats associated with climatic conditions are environmental threats. To mitigate environmental threats, you need to ensure that there is adequate ventilation in the facility and that the temperature and humidity levels are maintained in accordance with the specifications defined in the equipment documentation. Once these parameters are in place, ensure that you have the ability to remotely manage and monitor temperature and humidity controls. Also make sure that the facility is free from electrostatic discharge (ESD) and magnetic interference.
  • Electrical threats -- Brown-outs, spikes, inadequate power supply, noise and power loss are typical examples of electrical threats. We highly recommend that your mission-critical devices are hooked up to an uninterruptible power supply (UPS). A UPS provides line conditioning and protects your network devices against irregularities in your power distribution system. Ensure that you have redundant power supplies in your network devices (if they support them) or some hot spares at the facility. This measure reduces the amount of downtime on your network. A generator can be an alternate source for power in case of a power outage if your environment is mission critical.
  • Maintenance threats -- Poor cabling, faulty labeling and electronic devices without adequate ESD deterrents are classified as maintenance threats. Make sure that the equipment cabling is labeled properly and that a proper labeling convention is followed. This measure helps in tracing cables in the facility and aids in quick troubleshooting as well. Ensure that cables have smooth bends when you go around the corner. You want no kinks on the cable, so you can guarantee the smooth flow of data.

    Download the rest of this chapter for free here.
    Read more chapter excerpts and book reviews.



    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Network Routers and Switches
    DNS rebinding defenses still necessary, thanks to Web 2.0
    Is it possible to allow select access to IP addresses using Windows Server 2003?
    Embedding security has drawbacks says TippingPoint chief architect
    Nipper audits routers, reveals insecure settings
    New virtual switch integrates with multiple security vendors
    Should a firewall ever be placed before the router?
    Cisco plugs serious UCM flaw
    How to prevent hackers from accessing your router security password
    Cisco injects role-based access control into the network
    Cisco releases updates for multiple flaws

    Information Security Training
    Gary McGraw on secure software development
    University gets security funding for data transfer research
    CISOs adapt as compliance requires strategic thinking
    Information security book excerpts and reviews
    What are the security job prospects for someone without a certification?
    Will a Security+ certification be useful for aspiring security analysts?
    Industry experience vs. security certification credentials
    How can I get my CISSP certification?
    SANS: New exam program about more secure code
    CISOs mastering 'softer' skills

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Cisco Certified Security Professional (CCSP)  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary


  • TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts