Hardening Cisco devices training course description
A hands on course focusing on how to lock down Cisco
IOS routers and switches.
What will you learn
Harden Cisco devices.
Hardening Cisco devices training course details
Who will benefit:
Technical network staff.
Technical security staff.
Prerequisites:
TCP/IP foundation for engineers.
Duration
5 days
Hardening Cisco devices training course content
Introduction
Router security, Switch security, Cisco IOS, IOS versions, Cisco advisories, the management plane, control plane, data plane.
Hands on Checking IOS versions and advisories.
Access control
Infrastructure ACLs, Transit ACLs.
Hands on Restricting access to the device, Filtering data traffic.
Management plane: Securing operations
Passwords, privilege levels, AAA, TACACS+, RADIUS.
Hands on Password management.
Management plane: Other general hardening
Logging best practices, secure protocols, encrypting management sessions, configuration management.
Hands on Hardening the management plane.
Control plane
Disabling reception and transmission of certain messages, Limiting CPU impact of control plane traffic, securing routing protocols.
Hands on Hardening the control plane.
Data plane
Transit ACLs, disabling unused services, disabling unnecessary protocols, anti spoofing, limiting CPU impact of data plane traffic, identifying and tracing traffic, Netflow, VLANs, port security.
Hands on hardening the data plane.