0% found this document useful (0 votes)
61 views

Network Lockdown Security Lock Down

The document discusses using Cisco's Auto-Secure wizard and SDM security audit to lock down a network. The wizard disables unnecessary services, enables services like CEF and filtering, and sets a banner. It prevents SYN attacks and disables additional services. Newer IOS versions have added features and the document notes the difference between copy run start and config replace nvram commands.

Uploaded by

Abhishek Kunal
Copyright
© Attribution Non-Commercial (BY-NC)
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
61 views

Network Lockdown Security Lock Down

The document discusses using Cisco's Auto-Secure wizard and SDM security audit to lock down a network. The wizard disables unnecessary services, enables services like CEF and filtering, and sets a banner. It prevents SYN attacks and disables additional services. Newer IOS versions have added features and the document notes the difference between copy run start and config replace nvram commands.

Uploaded by

Abhishek Kunal
Copyright
© Attribution Non-Commercial (BY-NC)
Available Formats
Download as PDF, TXT or read online on Scribd
You are on page 1/ 11

NETWORK LOCKDOWN

CISCO AUTO-SECURE AND SDM SECURITY AUDIT

SERVICES ARE DISABLED

After wizard
BANNER for the motd is to be set. The SECRET password should be strong (minm 6 character.

WIZARD
After the it ask for LOCAL DATABASE. LOGIN: PASSWORD: (minm 6 character) After then more number of services will be disabled. And some services like CEF will be enabled. And Filtering method will also be enabled: autosec_iana_reserved_block_filtering autosec_private_block autosec_complete_block

These Ranges Cant be Used

SYN Attack Prevention


This Wizard prevent tcp syn attack. And Creates autosec_tcp_intercept_list. And Then Disables many other Services.

New Features
New features has been implemented into newer IOS versions.(CHECK IT OUT!!!). And to bring back old run-config 1. IN OLD IOS: R#reload 2. IN NEW IOS:R# config replace nvram:

(Difference between copy run start & config replace nvram: ? )

You might also like