cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1661
Views
0
Helpful
4
Replies

confiuration on Cisco switches before Pentration testing

Noovi
Level 1
Level 1

Hi Team,

 

we are having many cisco swithes including 2960, 3750 , 3650 and 3850 models.

 

can any one help me or suggest what best hardening practices i should configure on switches before Penetration testing.

4 Replies 4

Seb Rupik
VIP Alumni
VIP Alumni

Hi there,

You might want to work your way through this document:

 

https://www.cisco.com/c/en/us/support/docs/ip/access-lists/13608-21.html

 

cheers,

Seb.

Hi ,

 

thanks.

 

but is there any tool or software which can detect wrong configuration if we scan full config.??

 

i heard about nipper tool but not looks like perefect one

Prime Infra have Audit tools

https://www.cisco.com/c/dam/en_us/training-events/product-training/prime-infrastructure-31/ja-audit/PI31_Audit_JobAid.pdf

 

GIT have some Python script to help you (if you understand and hand on some programming)

https://github.com/jonarm/cisco-ios-audit

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Mike.Cifelli
VIP Alumni
VIP Alumni
Check out these two links:

Free CIS benchmarks: https://www.cisecurity.org/benchmark/cisco/
DISA IASE manual STIG checks (what most DoD environments use to harden devices): https://iase.disa.mil/stigs/net_perimeter/Pages/index.aspx

HTH!