欧美一区二区三区老妇人-欧美做爰猛烈大尺度电-99久久夜色精品国产亚洲a-亚洲福利视频一区二区

CiscoSwitches/RouterLayer3Security-創(chuàng)新互聯(lián)

1. Enable secure Telnet access to a router user interface, and consider using Secure Shell (SSH) instead of Telnet.
2. Enable SNMP security, particularly adding SNMPv3 support.
3. Turn off all unnecessary services on the router platform ( AutoSecure ).
4. Turn on logging to provide an audit trail.
5. Enable routing protocol authentication.
6. Enable the CEF forwarding path to avoid using flow-based paths like fast switching.

成都創(chuàng)新互聯(lián)長(zhǎng)期為上千家客戶提供的網(wǎng)站建設(shè)服務(wù),團(tuán)隊(duì)從業(yè)經(jīng)驗(yàn)10年,關(guān)注不同地域、不同群體,并針對(duì)不同對(duì)象提供差異化的產(chǎn)品和服務(wù);打造開(kāi)放共贏平臺(tái),與合作伙伴共同營(yíng)造健康的互聯(lián)網(wǎng)生態(tài)環(huán)境。為金湖企業(yè)提供專(zhuān)業(yè)的成都做網(wǎng)站、成都網(wǎng)站設(shè)計(jì)、成都外貿(mào)網(wǎng)站建設(shè)金湖網(wǎng)站改版等技術(shù)服務(wù)。擁有十年豐富建站經(jīng)驗(yàn)和眾多成功案例,為您定制開(kāi)發(fā)。

7. Using RPF Checks

example:

R1(config)# ip cef
R1(config)# int s0/0
R1(config-if)# ip verify unicast source reachable-via rx allow-default

8. Using ACL to prevent TCP SYN Flood from outside

example:

ip access-list extended prevent-syn
  permit tcp any 10.0.0.0 0.255.255.255 established
  deny tcp any 1.0.0.0 0.255.255.255
  permit (whatever)
!
interface s0/0 # Internet faced port
  ip access-group prevent-syn in

Notes: The above ACL works well when clients outside a network are not allowed to make TCP connections into the network. However, in cases where some inbound TCP connections are allowed, this ACL cannot be used. Another Cisco IOS feature, called TCP intercept, provides an alternative that allows TCP connections into the network, but monitors those TCP connections for TCP SYN attacks.

example:

ip access-list extended match-tcp-from-internet
  permit tcp any 10.0.0.0 0.255.255.255

ip tcp intercept-list match-tcp-from-internet
ip tcp intercept mode watch
ip tcp intercept watch-timeout 20

9.Cisco IOS Firewall CBAC

example:

ip inspect name CLASSIC_FW icmp timeout 10
ip inspect name CLASSIC_FW tcp timeout 30
ip inspect name CLASSIC_FW udp timeout 30
!
ip access-list extended IOS_FW
  deny ip any any
!
interface Serial0/0 #Internet faced interface
  ip address 192.168.1.3 255.255.255.0
  ip access-group IOS_FW in
  ip inspect CLASSIC_FW out

!

10. Cisco IOS Zone-Based Firewall

example:

Cisco Switches/Router Layer 3 Security

In this example, the network administrators have decided to apply the following policies to traffic from the LAN zone going through the WAN zone:
■ Only traffic from the LAN subnet is allowed.
■ HTTP traffic to corporate web-based intranet servers is allowed.
■ All other HTTP traffic is allowed but policed to 1 Mbps.
■ ICMP is blocked.
■ For all other traffic, the TCP and UDP timeouts must be lowered to 300 seconds.

Follow these steps to configure ZFW:

Step 1: Decide the zones you will need, and create them on the router.

Branch2(config)# zone security LAN
Branch2(config-sec-zone)# description LAN zone
!
Branch2(config)# zone security WAN
Branch2(config-sec-zone)# description WAN zone

Step 2: Decide how traffic should travel between the zones, and create zone-pairs on the router.

Branch2(config)# zone-pair security Internal source LAN destination WAN
Branch2(config)# zone-pair security External source WAN destination LAN

Step 3: Create class maps to identify the inter-zone traffic that must be inspected by the firewall.

Branch2(config)# ip access-list extended LAN-Subnet
Branch2(config-ext-nacl)# permit ip 10.1.1.0 0.0.0.255 any
!
Branch2(config-ext-nacl)# ip access-list extended Web_Servers
Branch2(config-ext-nacl)# permit tcp 10.1.1.0 0.0.0.255 host 10.150.2.1
Branch2(config-ext-nacl)# permit tcp 10.1.1.0 0.0.0.255 host 10.150.2.2
!
Branch2(config-ext-nacl)# class-map type inspect match-all Corp_Servers
Branch2(config-cmap)# match access-group name Web_Servers
Branch2(config-cmap)# match protocol http
!
Branch2(config-cmap)# class-map type inspect Other_HTTP
Branch2(config-cmap)# match protocol http
Branch2(config-cmap)# match access-group name LAN_Subnet
!
Branch2(config-cmap)# class-map type inspect ICMP
Branch2(config-cmap)# match protocol icmp
!
Branch2(config-cmap)# class-map type inspect Other_Traffic
Branch2(config-cmap)# match access-group name LAN_Subnet

Branch2(config)# parameter-map type inspect Timeouts
Branch2(config-profile)# tcp idle-time 300
Branch2(config-profile)# udp idle-time 300

Step 4: Assign policies to the traffic by creating policy maps and associating class maps with them.

Branch2(config-profile)# policy-map type inspect LAN2WAN
Branch2(config-pmap)# class type inspect Corp_Servers
Branch2(config-pmap-c)# inspect
!
Branch2(config-pmap-c)# class type inspect Other_HTTP
Branch2(config-pmap-c)# inspect
Branch2(config-pmap-c)# police rate 1000000 burst 8000
!
Branch2(config-pmap-c)# class type inspect ICMP
Branch2(config-pmap-c)# drop
!
Branch2(config-pmap-c)# class type inspect Other_Traffic
Branch2(config-pmap-c)# inspect Timeouts

Step 5: Assign the policy maps to the appropriate zone-pair.

Branch2(config)# zone-pair security Internal source LAN destination WAN
Branch2(config-sec-zone-pair)# service-policy type inspect LAN2WAN

Step 6: Assign interfaces to zones. An interface may be assigned to only one security zone.

Branch2(config)# interface fa 0/0
Branch2(config-if)# zone-member security LAN
!
Branch2(config-if)# interface s0/0/0
Branch2(config-if)# zone-member security WAN

另外有需要云服務(wù)器可以了解下創(chuàng)新互聯(lián)scvps.cn,海內(nèi)外云服務(wù)器15元起步,三天無(wú)理由+7*72小時(shí)售后在線,公司持有idc許可證,提供“云服務(wù)器、裸金屬服務(wù)器、高防服務(wù)器、香港服務(wù)器、美國(guó)服務(wù)器、虛擬主機(jī)、免備案服務(wù)器”等云主機(jī)租用服務(wù)以及企業(yè)上云的綜合解決方案,具有“安全穩(wěn)定、簡(jiǎn)單易用、服務(wù)可用性高、性價(jià)比高”等特點(diǎn)與優(yōu)勢(shì),專(zhuān)為企業(yè)上云打造定制,能夠滿足用戶豐富、多元化的應(yīng)用場(chǎng)景需求。

網(wǎng)頁(yè)名稱:CiscoSwitches/RouterLayer3Security-創(chuàng)新互聯(lián)
網(wǎng)站地址:http://www.chinadenli.net/article2/dcdjoc.html

成都網(wǎng)站建設(shè)公司_創(chuàng)新互聯(lián),為您提供外貿(mào)網(wǎng)站建設(shè)品牌網(wǎng)站設(shè)計(jì)定制網(wǎng)站網(wǎng)站排名商城網(wǎng)站微信小程序

廣告

聲明:本網(wǎng)站發(fā)布的內(nèi)容(圖片、視頻和文字)以用戶投稿、用戶轉(zhuǎn)載內(nèi)容為主,如果涉及侵權(quán)請(qǐng)盡快告知,我們將會(huì)在第一時(shí)間刪除。文章觀點(diǎn)不代表本網(wǎng)站立場(chǎng),如需處理請(qǐng)聯(lián)系客服。電話:028-86922220;郵箱:631063699@qq.com。內(nèi)容未經(jīng)允許不得轉(zhuǎn)載,或轉(zhuǎn)載時(shí)需注明來(lái)源: 創(chuàng)新互聯(lián)

網(wǎng)站優(yōu)化排名