cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
341
Views
0
Helpful
4
Replies

Internet router security

kbrookov
Level 1
Level 1

Hello,

I am looking for a document/link for setting up security on an internet router. What Access lists should be implemented; services denied both inbound and outbound. A common practice type document would be great.

In particular, what are the ramifications for allowing Microsoft networking out? UDP 137, 138 and 139.

Any help is appreciated

4 Replies 4

jmia
Level 7
Level 7

Hi Kirk -

The following document published by National Security Agency (NSA) for Router Security is excellent read and I'm sure will help you with your question, I acctually used it for my CCIE backround reading.

Link: http://www.nsa.gov/snac/index.html

Hope this helps -

bill.zeng
Level 1
Level 1

I recently created a freeware script (available at http://hotunix.com/tools/) for checking Cisco config security:

"CCSAT (Cisco Configuration Security Auditing Tool) is a script to allow automated review of configuration security of large numbers of Cisco routers and switches. The tool is based upon industry best practices including Cisco, NSA and SANS security guides and recommendations. It is flexible and can report details down to individual device interfaces, lines, ACL's, AS's, etc."

Your comments and feedback are highly welcome! :)

mostiguy
Level 6
Level 6

http://www.cisecurity.org/bench_cisco.html

Is a good tool for auditing configurations.

ACLs on routers can be tricky - if it is not a stateful firewall, it is easy to break things. At a minimum though, you can block outbound all traffic with source ip addresses that you don't use.

Those particular MS ports should be blocked in and outbound, but a general rule is that you should block *everything* outbound that is not specifically permitted.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: