Auto Secure Question

Unanswered Question
Apr 18th, 2008

I am reading a Cisco Press book on Securing Perimiter Routers.

"Cisco Router Firewall Security" R.Deal @2005

It gives an example of Auto Secure with a couple of humongous ACL's.

One for example is for all Private Ip Source Addresses RFC 1918 blocked from the outside. Another is an IANA list. When I run auto secure on my new 2811 with advanced IP services it doesn not generate these long long ACL's. What has happened and is Auto Secure really a valid tool today???

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 3 (1 ratings)
Loading.
ROBERTO TACCON Sat, 04/19/2008 - 11:21

The auto secure feature it's a valid 'security configuration check method' but not updated.

As the iana list change its' better to configure the router like @:

http://www.cymru.com/Documents/secure-ios-template.html

Check also the following docs:

http://www.cisco.com/en/US/netsol/ns696/networking_solutions_white_papers_list.html

in particular:

http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6642/prod_white_paper09186a00801dbf61_ns696_Networking_Solutions_White_Paper.html

HTH

Actions

This Discussion