01-30-2014 08:34 AM - edited 03-04-2019 10:12 PM
Hi there,
Thanks for reading.
I'm seeing that my edge routers are terminating remote ssh sessions coming from overseas.
There's internal talk of an IPS system this year but no movement (quotes, POs).
What are some of the things you're doing for edge security?
Thanks!
Bob
Solved! Go to Solution.
01-30-2014 08:44 AM
If you're concerned about traffic to your router, you need to look into control plane security (CoPP)
http://www.cisco.com/web/about/security/intelligence/coppwp_gs.html
If you're concerned with traffic going through the router, acls, ZBFW or CBAC can control what goes through it, and you should disable unused services on the router.
You can view what ports are listening with "show control-plane hosts open".
HTH,
John
*** Please rate all useful posts ***
01-30-2014 08:44 AM
If you're concerned about traffic to your router, you need to look into control plane security (CoPP)
http://www.cisco.com/web/about/security/intelligence/coppwp_gs.html
If you're concerned with traffic going through the router, acls, ZBFW or CBAC can control what goes through it, and you should disable unused services on the router.
You can view what ports are listening with "show control-plane hosts open".
HTH,
John
*** Please rate all useful posts ***
01-30-2014 11:55 AM
01-30-2014 10:17 PM
You should take a look at the following link by TeamCymru. Its kind of best operating procedure in many cases.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide