cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1983
Views
10
Helpful
3
Replies

c2911 Firewalling and IDS/IPS for PCI DSS compliance

Hi, 

One customer wants to be audited for PCI DSS compliance. They have c2911 routers as WAN routers. 

When they do port scanning, obviously there are some ports open as routers are doing natting. As far as I know, port scanning cannot be prevented with ACLs. We need some firewalling or/and IDS/IPS functionalities on the router to avoid it. 

Can anyone give me hand with this topic? Do I need to upgrade to a higher IOS version? any security licence? 

these are the version details of the routers

Cisco IOS Software, C2900 Software (C2900-UNIVERSALK9-M), Version 15.1(4)M4, RELEASE SOFTWARE (fc1)

Technology Package License Information for Module:'c2900'

-----------------------------------------------------------------
Technology Technology-package Technology-package
Current Type Next reboot
------------------------------------------------------------------
ipbase ipbasek9 Permanent ipbasek9
security None None None
uc None None None
data None None None

 

thanks in advance

1 Accepted Solution

Accepted Solutions

You can't get the same result using reflective ACLs because they leave the ports permanelty open.

 

CBAC and zone based firewall only leave the ports open while they need to be and then close them again.

View solution in original post

3 Replies 3

Philip D'Ath
VIP Alumni
VIP Alumni
You would need to buy a security licence for the routers and then you could implement zone based firewall.

Hello Philip, 

 

Thanks for your quick response. Could we get a similar result regarding port scanning with reflexive ACL?

I know it is not as powerful as CBAC but we might prevent port scanning tools from seeing open ports.

 

thanks

 

You can't get the same result using reflective ACLs because they leave the ports permanelty open.

 

CBAC and zone based firewall only leave the ports open while they need to be and then close them again.

Review Cisco Networking for a $25 gift card