08-20-2012 09:45 PM - edited 03-10-2019 12:19 PM
Hi,
I have 2800 series router which is directly connected to ISP..
How can secure the router from outside access; pls help me on this as I am totally new to the security concepts
Thanks
08-20-2012 09:56 PM
08-20-2012 11:42 PM
Hello Vishal,
Jimmy has provided you a perfect link to start. Certain things which needs to be considered as part of security
1) Disabling HTTP server. Running HTTP server is highly vulnerable to external attacks. Should be DISABLED !!!
2) IP Finger services to be disabled.
3) ACL to block access to router from internet.
4) Configure SSH
5) TCP & UDP small services must be disabled
5) Denying all RFC 1918 addresses from internet (as you dont expect to see a private address from internet which could be a spoofing attack).
6) Have the Control Plane Policing done to avoid DoS attacks against the CPU.
Link provided by Jimmy has all the neccessary details, but i just thought of highlighting some important once.
Thanks
Vivek
*Please rate helpful posts
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide