Monday, October 26, 2009

Random Security Measures

security password min-length [0-16] \\sets a minimum password length for all future passwords
no service password-recovers \\very dangerous...you cant recover passwords or ios's after this point
security authentication failure rate [#] log \\locks user out for x seconds if failed login x times
login block-for [seconds] attemps [#] within [seconds] \\blocks a user for x seconds after x attempts within x seconds...
login quiet-mode access-class [name] \\if login is blocked...this sets an acl that still allows groups of users access
login delay [#] \\sets a delay after a failed login
login on-failure log \\logs login failures after # attempts
show login

motd options ( $(line)  $(domain)   $(hostname) )

ENABLING VIEWS
aaa new-model \\enable aaa
enable view (enter secret password at prompt)
parser view [name]
secret [password]
(configure options)

secure boot-image \\locks ios image
secure boot-config \\locks config file
no secure [option] \\requires console access

reload in [minutes]  \\good if entering say access lists on a remote router
reload cancel

ACL TYPES
standard
extended
dynamic
established
time-based
context based

cool command of the day
ip access-list resequence [name/num] [start num] [variance]

time-range [name]
absolute/periodic

Sunday, October 25, 2009

P2P IPSEC CLI Config & Automatic Device Lockdown Methods

Did the point to point ipsec cli config tonight.  I covered it in another post, but had some trouble tonight right off of the bat.  I think it was because I manually deleted yesterdays config instead of wiping my routers clean.  Something must have messed up todays config...but I wr erased, reloaded, and re-configd' and all was well in the world of ipsec tunnels.

I also watched the nuggets regarding cisco's auto secure, sdm one-touch, and step-by-step security audits.  Now, I had known about the sdm's functionality, but the auto secure is pretty neat as well.  Basically just type:
# auto secure
and follow the prompts.  Pretty good stuff!

Saturday, October 24, 2009

GRE Tunnel....Experimenting with different routing instances






This was my diagram.  I started by assigning ip addresses to all links, and loopbacks on the spoke routers.  I ran eigrp as 1 over all the connected links, and did not advertise the loopbacks.  Then configured the GRE tunnels as follows (I give you one...the other is a mirror):

int tunnel 0
tunnel source serial 0/0
tunnel destination 192.168.23.3
ip address 172.16.13.1 255.255.255.0

After configuring the other side I tested with pings to the other tunnel interface....success.

Then I configured eigrp as 2, and advertised those loopbacks, and the tunnel interfaces (which happened to all be covered by the network statement 172.16.0.0).  A show ip eigrp neighbors 2 confirmed the adjancency, and a show ip route eigrp 2 confirmed the updated routes.  I can see how this could be useful over a public link, and especially encrypted within an IPSEC tunnel.

I also did the P2P IPSEC SDM config tonight.  Not as much fun as the CLI....not at all.  But the SPAN setup was cool, and capturing...actually seeing the encrypted data was really neat.