Hardening Cisco Routers
暫譯: 強化 Cisco 路由器

Thomas Akin

  • 出版商: O'Reilly
  • 售價: $1,120
  • 貴賓價: 9.5$1,064
  • 語言: 英文
  • 頁數: 194
  • 裝訂: Paperback
  • ISBN: 0596001665
  • ISBN-13: 9780596001667
  • 相關分類: Cisco
  • 已過版

買這商品的人也買了...

相關主題

商品描述

As a network administrator, auditor or architect, you know the importance of securing your network and finding security solutions you can implement quickly. This succinct book departs from other security literature by focusing exclusively on ways to secure Cisco routers, rather than the entire network. The rational is simple: If the router protecting a network is exposed to hackers, then so is the network behind it. Hardening Cisco Routers is a reference for protecting the protectors. Included are the following topics:


  • The importance of router security and where routers fit into an overall security plan
  • Different router configurations for various versions of Cisco?s IOS
  • Standard ways to access a Cisco router and the security implications of each
  • Password and privilege levels in Cisco routers
  • Authentication, Authorization, and Accounting (AAA) control
  • Router warning banner use (as recommended by the FBI)
  • Unnecessary protocols and services commonly run on Cisco routers
  • SNMP security
  • Anti-spoofing
  • Protocol security for RIP, OSPF, EIGRP, NTP, and BGP
  • Logging violations
  • Incident response
  • Physical security



Written by Thomas Akin, an experienced Certified Information Systems Security Professional (CISSP) and Certified Cisco Academic Instructor (CCAI), the book is well organized, emphasizing practicality and a hands-on approach. At the end of each chapter, Akin includes a Checklist that summarizes the hardening techniques discussed in the chapter. The Checklists help you double-check the configurations you have been instructed to make, and serve as quick references for future security procedures.

Concise and to the point, Hardening Cisco Routers supplies you with all the tools necessary to turn a potential vulnerability into a strength. In an area that is otherwise poorly documented, this is the one book that will help you make your Cisco routers rock solid.

Table of Contents

Preface

1. Router Security

2. IOS Version Security

3. Basic Access Control

4. Passwords and Privilege Levels

5. AAA Access Control

6. Warning Banners

7. Unnecessary Protocols and Services

8. SNMP Security

9. Secure Routing and Antispoofing

10. NTP

11. Logging

A. Checklist Quick Reference

B. Physical Security

C. Incident Response

D. Configuration Examples

E. Resources

Index

商品描述(中文翻譯)

作為網路管理員、審計員或架構師,您知道保護網路安全和快速找到可實施的安全解決方案的重要性。本書與其他安全文獻不同,專注於如何保護 Cisco 路由器,而不是整個網路。其理由很簡單:如果保護網路的路由器暴露於駭客之下,那麼其後的網路也會受到威脅。《強化 Cisco 路由器》是一本保護保護者的參考書。內容包括以下主題:

- 路由器安全的重要性以及路由器在整體安全計畫中的角色
- 各版本 Cisco IOS 的不同路由器配置
- 訪問 Cisco 路由器的標準方式及其安全影響
- Cisco 路由器中的密碼和特權級別
- 認證、授權和記帳 (AAA) 控制
- 路由器警告橫幅的使用(根據 FBI 的建議)
- Cisco 路由器上常見的多餘協議和服務
- SNMP 安全
- 反欺騙
- RIP、OSPF、EIGRP、NTP 和 BGP 的協議安全
- 日誌違規
- 事件響應
- 物理安全

本書由經驗豐富的認證資訊系統安全專業人員 (CISSP) 和認證 Cisco 學術講師 (CCAI) Thomas Akin 撰寫,組織良好,強調實用性和實作方法。在每章的結尾,Akin 包含了一個檢查清單,總結了該章中討論的強化技術。這些檢查清單幫助您再次檢查所指示的配置,並作為未來安全程序的快速參考。

簡潔明瞭的《強化 Cisco 路由器》為您提供了將潛在漏洞轉化為優勢所需的所有工具。在這個文獻稀少的領域,這是一本能幫助您使 Cisco 路由器堅如磐石的書籍。

目錄

前言

1. 路由器安全
2. IOS 版本安全
3. 基本訪問控制
4. 密碼和特權級別
5. AAA 訪問控制
6. 警告橫幅
7. 多餘的協議和服務
8. SNMP 安全
9. 安全路由和反欺騙
10. NTP
11. 日誌
A. 檢查清單快速參考
B. 物理安全
C. 事件響應
D. 配置範例
E. 資源
索引