<?xml version='1.0' encoding='iso-8859-1' ?><rss version="2.0"><channel><title>Cisco Routers</title><link>http://www.checklist20.com/bestpractices.html</link><description>Routers direct and control much of the data flowing across computer networks. This guide provides technical guidance intended to help IT auditors, network administrators and security officers improve the security and implement best practices of Cisco Routers.</description><item><title>Monitor Cisco Security Advisories and Responses</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=272&amp;tn=Monitor Cisco Security Advisories and Responses</link><description>The Cisco Product Security Incident Response Team (PSIRT) creates and maintains publications, commonly referred to as PSIRT Advisories, for security-related issues in Cisco products. Subscribe to&amp;nbsp;Cisco Security Advisory RSS feeds at http:ewsr ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=272&amp;tn=Monitor Cisco Security Advisories and Responses'>View More</a>]]></description></item><item><title>Develop Network Security Policy</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=301&amp;tn=Develop Network Security Policy</link><description> ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=301&amp;tn=Develop Network Security Policy'>View More</a>]]></description></item><item><title>Implement Password Management Controls</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=278&amp;tn=Implement Password Management Controls</link><description>As a security best practice, passwords must be managed with a TACACS+ or RADIUS authentication server. However, note that a locally configured password for privileged access is still be needed in the event of failure of the TACACS+ or RADIUS servi ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=278&amp;tn=Implement Password Management Controls'>View More</a>]]></description></item><item><title>Centralize Log Collection and Monitoring</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=274&amp;tn=Centralize Log Collection and Monitoring</link><description>In order to track existing, emerging, and historic events related to security incidents, a unified strategy is required for event logging and correlation. This unified approach must leverage logging from all network devices and use pre-packaged an ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=274&amp;tn=Centralize Log Collection and Monitoring'>View More</a>]]></description></item><item><title>Leverage Authentication, Authorization, and Accounting</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=273&amp;tn=Leverage Authentication, Authorization, and Accounting</link><description>The Authentication, Authorization, and Accounting (AAA) framework is vital to securing network devices. The AAA framework provides authentication of management sessions and can also limit users to specific, administrator-defined commands and log a ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=273&amp;tn=Leverage Authentication, Authorization, and Accounting'>View More</a>]]></description></item><item><title>Access Control with MAC</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=335&amp;tn=Access Control with MAC</link><description>MAC access control lists or extended lists can be applied on IP network with the use of this command in interface configuration mode:Cat6K-IOS(config-if)#mac packet-classify ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=335&amp;tn=Access Control with MAC'>View More</a>]]></description></item><item><title>Access Control with PACLs</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=334&amp;tn=Access Control with PACLs</link><description>PACLs can only be applied to the inbound direction on Layer 2 physical interfaces of a switch. Similar to VLAN maps, PACLs provide access control on non-routed or Layer 2 traffic. The syntax for creating PACLs, which take precedence over VLAN maps ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=334&amp;tn=Access Control with PACLs'>View More</a>]]></description></item><item><title>Access Control with VLAN Maps</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=333&amp;tn=Access Control with VLAN Maps</link><description>VACLs, or VLAN maps that apply to all packets that enter the VLAN, provide the capability to enforce access control on intra-VLAN traffic. This is not possible using ACLs on routed interfaces. For example, a VLAN map may be used in order to preven ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=333&amp;tn=Access Control with VLAN Maps'>View More</a>]]></description></item><item><title>Classification ACLs</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=332&amp;tn=Classification ACLs</link><description>Classification ACLs provide visibility into traffic that traverses an interface. Classification ACLs do not alter the security policy of a network and are typically constructed to classify individual protocols, source addresses, or destinations. F ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=332&amp;tn=Classification ACLs'>View More</a>]]></description></item><item><title>Anti-Spoofing ACLs</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=331&amp;tn=Anti-Spoofing ACLs</link><description>Manually configured ACLs can provide static anti-spoofing protection against attacks that utilize known unused and untrusted address space. Commonly, these anti-spoofing ACLs are applied to ingress traffic at network boundaries as a component of a ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=331&amp;tn=Anti-Spoofing ACLs'>View More</a>]]></description></item><item><title>Dynamic ARP Inspection</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=330&amp;tn=Dynamic ARP Inspection</link><description>Dynamic ARP Inspection (DAI) can be utilized to mitigate ARP poisoning attacks on local segments. An ARP poisoning attack is a method in which an attacker sends falsified ARP information to a local segment. This information is designed to corrupt  ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=330&amp;tn=Dynamic ARP Inspection'>View More</a>]]></description></item><item><title>Port Security</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=329&amp;tn=Port Security</link><description>Port Security is used in order to mitigate MAC address spoofing at the access interface. Port Security can use dynamically learned (sticky) MAC addresses to ease in the initial configuration. Once port security has determined a MAC violation, it c ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=329&amp;tn=Port Security'>View More</a>]]></description></item><item><title>IP Source Guard</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=328&amp;tn=IP Source Guard</link><description>IP Source Guard is an effective means of spoofing prevention that can be used if you have control over Layer 2 interfaces. IP Source Guard uses information from DHCP snooping to dynamically configure a port access control list (PACL) on the Layer  ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=328&amp;tn=IP Source Guard'>View More</a>]]></description></item><item><title>Configure Unicast RPF</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=327&amp;tn=Configure Unicast RPF</link><description>Unicast RPF enables a device to verify that the source address of a forwarded packet can be reached through the interface that received the packet. You must not rely on Unicast RPF as the only protection against spoofing. Spoofed packets could ent ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=327&amp;tn=Configure Unicast RPF'>View More</a>]]></description></item><item><title>Disable IP Source Routing</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=326&amp;tn=Disable IP Source Routing</link><description>IP source routing leverages the Loose Source Route and Record Route options in tandem or the Strict Source Route along with the Record Route option to enable the source of the IP datagram to specify the network path a packet takes. This functional ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=326&amp;tn=Disable IP Source Routing'>View More</a>]]></description></item><item><title>IP Options Selective Drop</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=325&amp;tn=IP Options Selective Drop</link><description>There are two security concerns presented by IP options. Traffic that contains IP options must be process-switched by Cisco IOS devices, which can lead to elevated CPU load. IP options also include the functionality to alter the path that traffic  ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=325&amp;tn=IP Options Selective Drop'>View More</a>]]></description></item><item><title>Securing First Hop Redundancy Protocols</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=324&amp;tn=Securing First Hop Redundancy Protocols</link><description>First Hop Redundancy Protocols (FHRPs) provide resiliency and redundancy for devices that are acting as default gateways. This situation and these protocols are commonplace in environments where a pair of Layer 3 devices provides default gateway f ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=324&amp;tn=Securing First Hop Redundancy Protocols'>View More</a>]]></description></item><item><title>Routing Process Resource Consumption</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=323&amp;tn=Routing Process Resource Consumption</link><description>Routing Protocol prefixes are stored by a router in memory, and resource consumption increases with additional prefixes that a router must hold. In order to prevent resource exhaustion, it is important to configure the routing protocol to limit re ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=323&amp;tn=Routing Process Resource Consumption'>View More</a>]]></description></item><item><title>Route Filtering</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=322&amp;tn=Route Filtering</link><description>In order to reduce the possibility of introducing false routing information in the network, route filtering must be used. Unlike the passive-interface router configuration command, routing occurs on interfaces once route filtering is enabled, but  ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=322&amp;tn=Route Filtering'>View More</a>]]></description></item><item><title>Passive-Interface Commands</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=321&amp;tn=Passive-Interface Commands</link><description>Information leaks, or the introduction of false information into an IGP, can be mitigated through use of the passive-interface command that assists in controlling the advertisement of routing information. You are advised not to advertise any infor ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=321&amp;tn=Passive-Interface Commands'>View More</a>]]></description></item><item><title>Routing Protocol Authentication and Verification with Message Digest 5</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=320&amp;tn=Routing Protocol Authentication and Verification with Message Digest 5</link><description>Failure to secure the exchange of routing information allows an attacker to introduce false routing information into the network. By using password authentication with routing protocols between routers, you can aid the security of the network. How ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=320&amp;tn=Routing Protocol Authentication and Verification with Message Digest 5'>View More</a>]]></description></item><item><title>Disable or Limit IP Directed Broadcasts</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=319&amp;tn=Disable or Limit IP Directed Broadcasts</link><description>IP Directed Broadcasts make it possible to send an IP broadcast packet to a remote IP subnet. Once it reaches the remote network, the forwarding IP device sends the packet as a Layer 2 broadcast to all stations on the subnet. This directed broadca ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=319&amp;tn=Disable or Limit IP Directed Broadcasts'>View More</a>]]></description></item><item><title>Filtering BGP Prefixes with Autonomous System Path Access Lists</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=318&amp;tn=Filtering BGP Prefixes with Autonomous System Path Access Lists</link><description>BGP autonomous system (AS) path access lists allows the user to filter received and advertised prefixes based on the AS-path attribute of a prefix. This can be used in conjunction with prefix lists to establish a robust set of filters.This configu ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=318&amp;tn=Filtering BGP Prefixes with Autonomous System Path Access Lists'>View More</a>]]></description></item><item><title>Filtering BGP Prefixes with Prefix Lists</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=317&amp;tn=Filtering BGP Prefixes with Prefix Lists</link><description>Prefix lists allow a network administrator to permit or deny specific prefixes that are sent or received via BGP. Prefix lists should be used where possible to ensure network traffic is sent over the intended paths. Prefix lists should be applied  ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=317&amp;tn=Filtering BGP Prefixes with Prefix Lists'>View More</a>]]></description></item><item><title>Configuring Maximum Prefixes</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=316&amp;tn=Configuring Maximum Prefixes</link><description>BGP prefixes are stored by a router in memory. The more prefixes that a router must hold results in BGP consuming more memory. In some configurations, a subset of all Internet prefixes can be stored, such as in configurations that leverage only a  ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=316&amp;tn=Configuring Maximum Prefixes'>View More</a>]]></description></item><item><title>BGP Peer Authentication with MD5</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=315&amp;tn=BGP Peer Authentication with MD5</link><description>Peer authentication using MD5 creates an MD5 digest of each packet sent as part of a BGP session. Specifically, portions of the IP and TCP headers, TCP payload, and a secret key are used in order to generate the digest.Peer authentication with MD5 ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=315&amp;tn=BGP Peer Authentication with MD5'>View More</a>]]></description></item><item><title>Secure Simple Network Management Protocol(SNMP)</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=314&amp;tn=Secure Simple Network Management Protocol(SNMP)</link><description> ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=314&amp;tn=Secure Simple Network Management Protocol(SNMP)'>View More</a>]]></description></item><item><title>TTL-based Security Protections</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=313&amp;tn=TTL-based Security Protections</link><description>Known as both the Generalized TTL-based Security Mechanism (GTSM) and BGP TTL Security Hack (BTSH), a TTL-based security protection leverages the TTL value of IP packets to ensure that the BGP packets that are received are from a directly connecte ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=313&amp;tn=TTL-based Security Protections'>View More</a>]]></description></item><item><title>Hardware Rate Limiters</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=312&amp;tn=Hardware Rate Limiters</link><description>Hardware rate limiters are referred to as special-case rate limiters because they cover a specific predefined set of IPv4, IPv6, unicast, and multicast DoS scenarios. HWRLs can protect the Cisco IOS device from a variety of attacks that require pa ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=312&amp;tn=Hardware Rate Limiters'>View More</a>]]></description></item><item><title>Control Plane Protection</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=311&amp;tn=Control Plane Protection</link><description>Control Plane Protection (CPPr) can be used in order to restrict or police control plane traffic that is destined to the CPU of the Cisco IOS device. While similar to CoPP, CPPr has the ability to restrict traffic with finer granularity. CPPr divi ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=311&amp;tn=Control Plane Protection'>View More</a>]]></description></item><item><title>Control Plane Policing</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=310&amp;tn=Control Plane Policing</link><description>The Control Plane Policing (CoPP) feature can also be used in order to restrict IP packets that are destined to the infrastructure device. For example, enabling this feature only SSH traffic from trusted hosts is permitted to reach the Cisco IOS d ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=310&amp;tn=Control Plane Policing'>View More</a>]]></description></item><item><title>Configure Receive ACLs(rACL)</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=309&amp;tn=Configure Receive ACLs(rACL)</link><description>The rACL protects the device from harmful traffic before the traffic impacts the route processor. Receive ACLs are designed to only protect the device on which it is configured and transit traffic is not affected by an rACL. As a result, the desti ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=309&amp;tn=Configure Receive ACLs(rACL)'>View More</a>]]></description></item><item><title>Configure trusted time source for network time protocol</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=308&amp;tn=Configure trusted time source for network time protocol</link><description>The Network Time Protocol (NTP) is not an especially dangerous service, but any unneeded service can represent an attack vector. If NTP is used, it is important to explicitly configure a trusted time source and to use proper authentication. Accura ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=308&amp;tn=Configure trusted time source for network time protocol'>View More</a>]]></description></item><item><title>No Proxy ARP</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=307&amp;tn=No Proxy ARP</link><description>Proxy ARP is the technique in which one device, usually a router, answers ARP requests that are intended for another device. By &amp;quot;faking&amp;quot; its identity, the router accepts responsibility for routing packets to the real destination. Proxy ARP can hel ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=307&amp;tn=No Proxy ARP'>View More</a>]]></description></item><item><title>Limit ICMP Unreachables</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=306&amp;tn=Limit ICMP Unreachables</link><description>Filtering with an interface access list elicits the transmission of ICMP unreachable messages back to the source of the filtered traffic. Generating these messages can increase CPU utilization on the device. In Cisco IOS software, ICMP unreachable ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=306&amp;tn=Limit ICMP Unreachables'>View More</a>]]></description></item><item><title>No IP ICMP Redirects</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=305&amp;tn=No IP ICMP Redirects</link><description>An ICMP redirect message can be generated by a router when a packet is received and transmitted on the same interface. In this situation, the router forwards the packet and sends an ICMP redirect message back to the sender of the original packet.  ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=305&amp;tn=No IP ICMP Redirects'>View More</a>]]></description></item><item><title>Configuration Change Notification and Logging </title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=304&amp;tn=Configuration Change Notification and Logging </link><description>The Configuration Change Notification and Logging feature, added in Cisco IOS Software Release 12.3(4)T, makes it possible to log the configuration changes made to a Cisco IOS device. The log is maintained on the Cisco IOS device and contains the  ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=304&amp;tn=Configuration Change Notification and Logging '>View More</a>]]></description></item><item><title>Cisco IOS Software Resilient Configuration</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=303&amp;tn=Cisco IOS Software Resilient Configuration</link><description>The Resilient Configuration feature makes it possible to securely store a copy of the Cisco IOS software image and device configuration that is currently being used by a Cisco IOS device. When this feature is enabled, it is not possible to alter o ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=303&amp;tn=Cisco IOS Software Resilient Configuration'>View More</a>]]></description></item><item><title>Enable exclusive configuration change access mode</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=302&amp;tn=Enable exclusive configuration change access mode</link><description>The Exclusive Configuration Change Access feature ensures that only one administrator makes configuration changes to a Cisco IOS device at a given time. This feature helps eliminate the undesirable impact of simultaneous changes made to related co ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=302&amp;tn=Enable exclusive configuration change access mode'>View More</a>]]></description></item><item><title>Do not include router information in warning banners</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=300&amp;tn=Do not include router information in warning banners</link><description>In some legal jurisdictions it can be impossible to prosecute and illegal to monitor malicious users unless they have been notified that they are not permitted to use the system. One method to provide this notification is to place this information ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=300&amp;tn=Do not include router information in warning banners'>View More</a>]]></description></item><item><title>Control transport for vty and tty Lines</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=299&amp;tn=Control transport for vty and tty Lines</link><description>In an effort to prevent information disclosure or unauthorized access to the data that is transmitted between the administrator and the device, transport input ssh should be used instead of clear-text protocols, such as Telnet and rlogin. The tran ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=299&amp;tn=Control transport for vty and tty Lines'>View More</a>]]></description></item><item><title>Use authentication to control vty and tty lines</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=298&amp;tn=Use authentication to control vty and tty lines</link><description>The simplest form of access control to a vty or tty of a device is through the use of authentication on all lines regardless of the device location within the network. This is critical for vty lines because they are accessible via the network. A t ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=298&amp;tn=Use authentication to control vty and tty lines'>View More</a>]]></description></item><item><title>Secure console port access</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=297&amp;tn=Secure console port access</link><description>Any method used in order to access the console port of a device must be secured in a manner that is equal to the security that is enforced for privileged access to a device. Methods used in order to secure access must include the use of AAA, exec- ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=297&amp;tn=Secure console port access'>View More</a>]]></description></item><item><title>Encrypt management Sessions</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=296&amp;tn=Encrypt management Sessions</link><description>Because information can be disclosed during an interactive management session, this traffic must be encrypted so that a malicious user cannot gain access to the data being transmitted. Encrypting the traffic allows a secure remote access connectio ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=296&amp;tn=Encrypt management Sessions'>View More</a>]]></description></item><item><title>Enable Control Plane Protection(CPPr)</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=295&amp;tn=Enable Control Plane Protection(CPPr)</link><description>Control Plane Protection (CPPr) builds on the functionality of Control Plane Policing in order to restrict and police control plane traffic that is destined to the route processor of the IOS device. CPPr, added in Cisco IOS Software Release 12.4(4 ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=295&amp;tn=Enable Control Plane Protection(CPPr)'>View More</a>]]></description></item><item><title>Enable Management Plane Protection(MPP)</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=294&amp;tn=Enable Management Plane Protection(MPP)</link><description>The feature Management Plane Protection (MPP) allows an administrator to restrict on which interfaces management traffic can be received by a device. This allows the administrator additional control over a device and how the device is accessed. ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=294&amp;tn=Enable Management Plane Protection(MPP)'>View More</a>]]></description></item><item><title>ACL Support for Filtering on TTL Value</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=293&amp;tn=ACL Support for Filtering on TTL Value</link><description>Enable ACL support for filtering IP packets based on the Time to Live (TTL) value. The TTL value of an IP datagram is decremented by each network device as a packet flows from source to destination. Although initial values vary by operating system ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=293&amp;tn=ACL Support for Filtering on TTL Value'>View More</a>]]></description></item><item><title>ACL Support for Filtering IP Options</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=292&amp;tn=ACL Support for Filtering IP Options</link><description>Use of ACLs to filter IP packets based on the IP options that are contained in the packet. IP options present a security challenge for network devices because these options must be processed as exception packets. This requires a level of CPU effor ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=292&amp;tn=ACL Support for Filtering IP Options'>View More</a>]]></description></item><item><title>Filter IP Fragments</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=291&amp;tn=Filter IP Fragments</link><description>The filtering of fragmented IP packets can pose a challenge to security devices. This is because the Layer 4 information that is used in order to filter TCP and UDP packets is only present in the initial fragment. Cisco IOS software uses a specifi ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=291&amp;tn=Filter IP Fragments'>View More</a>]]></description></item><item><title>ICMP Packet Filtering</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=290&amp;tn=ICMP Packet Filtering</link><description>The Internet Control Message Protocol (ICMP) is designed as an IP control protocol. As such, the messages it conveys can have far-reaching ramifications to the TCP and IP protocols in general. While the network troubleshooting tools ping and trace ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=290&amp;tn=ICMP Packet Filtering'>View More</a>]]></description></item><item><title>Configure Infrastructure ACLs(iACL)</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=289&amp;tn=Configure Infrastructure ACLs(iACL)</link><description>Infrastructure access control lists (iACLs) are one of the most critical security controls that can be implemented in networks. Infrastructure ACLs leverage the idea that nearly all network traffic traverses the network and is not destined to the  ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=289&amp;tn=Configure Infrastructure ACLs(iACL)'>View More</a>]]></description></item><item><title>Enhanced Crashinfo File Collection</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=288&amp;tn=Enhanced Crashinfo File Collection</link><description>The Enhanced Crashinfo File Collection feature automatically deletes old crashinfo files. This feature. allows a device to reclaim space to create new crashinfo files when the device crashes. This feature also allows configuration of the number of ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=288&amp;tn=Enhanced Crashinfo File Collection'>View More</a>]]></description></item><item><title>Detect and Correct Redzone Corruption</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=287&amp;tn=Detect and Correct Redzone Corruption</link><description>The Buffer Overflow: Detection and Correction of Redzone Corruption feature can be enabled by on a device in order to detect and correct a memory block overflow and to continue operations.These global configuration commands can be used in order to ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=287&amp;tn=Detect and Correct Redzone Corruption'>View More</a>]]></description></item><item><title>Memory Leak Detector</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=286&amp;tn=Memory Leak Detector</link><description>The Memory Leak Detector feature allows you to detect memory leaks on a device. Memory Leak Detector is able to find leaks in all memory pools, packet buffers, and chunks. Memory leaks are static or dynamic allocations of memory that do not serve  ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=286&amp;tn=Memory Leak Detector'>View More</a>]]></description></item><item><title>Reserve Memory for Console Access</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=285&amp;tn=Reserve Memory for Console Access</link><description>The Reserve Memory for Console Access feature can be used in order to reserve enough memory to ensure console access to a Cisco IOS device for administrative and troubleshooting purposes. This feature is especially beneficial when the device runs  ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=285&amp;tn=Reserve Memory for Console Access'>View More</a>]]></description></item><item><title>CPU Thresholding Notification</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=284&amp;tn=CPU Thresholding Notification</link><description>Introduced in Cisco IOS Software Release 12.3(4)T, the CPU Thresholding Notification feature allows you to detect and be notified when the CPU load on a device crosses a configured threshold. When the threshold is crossed, the device generates and ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=284&amp;tn=CPU Thresholding Notification'>View More</a>]]></description></item><item><title>Memory Threshold Notifications</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=283&amp;tn=Memory Threshold Notifications</link><description>The feature Memory Threshold Notification, added in Cisco IOS Software Release 12.3(4)T, allows you to mitigate low-memory conditions on a device. This feature uses two methods to accomplish this: Memory Threshold Notification and Memory Reservati ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=283&amp;tn=Memory Threshold Notifications'>View More</a>]]></description></item><item><title>Loopback Management Interfaces</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=282&amp;tn=Loopback Management Interfaces</link><description>The management plane of a device is accessed in-band or out-of-band on a physical or logical management interface. Ideally, both in-band and out-of-band management access exists for each network device so that the management plane can be accessed  ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=282&amp;tn=Loopback Management Interfaces'>View More</a>]]></description></item><item><title>Keepalives for TCP Sessions</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=281&amp;tn=Keepalives for TCP Sessions</link><description>The service tcp-keepalive-in and service tcp-keepalive-out global configuration commands enable a device to send TCP keepalives for TCP sessions. This configuration must be used in order to enable TCP keepalives on inbound connections to the devic ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=281&amp;tn=Keepalives for TCP Sessions'>View More</a>]]></description></item><item><title>Set EXEC timeout interval</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=280&amp;tn=Set EXEC timeout interval</link><description>In order to set the interval that the EXEC command interpreter waits for user input before it terminates a session, issue the exec-timeout line configuration command. The exec-timeout command must be used in order to logout sessions on vty or tty  ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=280&amp;tn=Set EXEC timeout interval'>View More</a>]]></description></item><item><title>Disable Unused Services</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=279&amp;tn=Disable Unused Services</link><description>Any unnecessary service must be disabled. These unneeded services, especially those that use UDP (User Datagram Protocol), are infrequently used for legitimate purposes, but can be used in order to launch DoS and other attacks that are otherwise p ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=279&amp;tn=Disable Unused Services'>View More</a>]]></description></item><item><title>Secure and archive configuration settings</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=277&amp;tn=Secure and archive configuration settings</link><description>Configuration management is a process by which configuration changes are proposed, reviewed, approved, and deployed. Within the context of a Cisco IOS device configuration, two additional aspects of configuration management are critical: configura ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=277&amp;tn=Secure and archive configuration settings'>View More</a>]]></description></item><item><title>Enable traffic monitoring using NetFlow</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=276&amp;tn=Enable traffic monitoring using NetFlow</link><description>NetFlow monitors traffic flows in the network. Originally intended to export traffic information to network management applications, NetFlow can also be used in order to show flow information on a router. This capability allows to see what traffic ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=276&amp;tn=Enable traffic monitoring using NetFlow'>View More</a>]]></description></item><item><title>Use Secure Protocols</title><link>http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=275&amp;tn=Use Secure Protocols</link><description>Many protocols are used in order to carry sensitive network management data. Use secure protocols whenever possible. A secure protocol choice includes the use of SSH instead of Telnet so that both authentication data and management information are ... &amp;nbsp;<![CDATA[<a href='http://www.checklist20.com/bestpractices.html#cid=164&amp;cn=Cisco Routers&amp;tid=275&amp;tn=Use Secure Protocols'>View More</a>]]></description></item></channel></rss>
