tailieunhanh - cisco press router security strategies phần 6

số cổng mới. Nếu quản lý dựa trên web là không cần thiết, hãy chắc chắn để vô hiệu hóa các máy chủ HTTP tiêu chuẩn bằng cách sử dụng không có lệnh ip máy chủ http trong IOS chế độ cấu hình toàn cầu nếu nó đã được kích hoạt. IOS cũng hỗ trợ HTTPS, như được mô tả trong trước đó phần truy cập từ xa ga Security ". | 314 Chapter 6 IP Management Plane Security new port number. If web-based administration is not required be sure to disable the standard HTTP server using the no ip http server command in IOS global configuration mode if it has previously been enabled. IOS also supports HTTPS as described in the earlier Remote Terminal Access Security section. Maintenance Operation Protocol MOP MOP is enabled on Ethernet interfaces and disabled on all other interface types by default within IOS. To disable MOP use the no mop enabled IOS command within interface configuration mode. The no mop enabled command is widely available within IOS. Network Time Protocol NTP To disable the NTP server use the no ntp command in IOS global configuration mode. NTP is enabled by default within Cisco IOS. The ntp disable IOS command may be used to disable NTP processing on specific interfaces such as external interfaces. NTP is very effective and widely deployed for correlating network events including security incidents. NTP is discussed further in the Network Telemetry Security section below and should be disabled only if it is not specifically used. Packet assembler disassembler PAD All PAD commands associated with assembly and disassembly of data packets between an packet switching network and a group of terminal connections are enabled by default within IOS. To disable PAD services use the no service pad IOS command in global configuration mode. The no service pad command is widely available within IOS. Small TCP servers Within IOS Software Releases prior to the TCP servers for Echo Discard Chargen and Daytime services were enabled by default. To disable these services use the no service tcp-small-servers command in IOS global configuration mode. When the minor TCP servers are disabled access to the Echo Discard Chargen and Daytime ports causes the IOS router to discard the initial incoming packet TCP SYN request and send a TCP RST packet to the source. Within IOS Software Releases .

TỪ KHÓA LIÊN QUAN
TÀI LIỆU MỚI ĐĂNG
41    195    5    07-01-2025
28    165    1    07-01-2025
65    146    1    07-01-2025
5    137    0    07-01-2025
26    147    2    07-01-2025
2    148    1    07-01-2025
18    133    0    07-01-2025