Table Of Contents

About the Presenter
About the Presentation
Fundamental Security
Management Security
Login Methods
Restricting Management Access
Management Security Tiers
Login Security
Configuring a Banner
Enhanced Password Security
Password Restriction
Password Encryption
Service Password-Encryption
SHA/MD5 Password Protection
Password Cracking
Access Control Server (ACS) Integration
One Time Passwords (OTP)
Password Security Tiers
Session Limits
Login Security Tiers
Functionality Based User Security
Command Based User Security
Role Based Access Control
Remote Command Authorization
User Security Tiers
Configuration Backup and Rollback
Network Accounting
Configuration Change Security Tiers
Control Plane Policing (CPP)
Control Plane Protection Example
Control Plane Security Tiers
Access Groups and ACLs
Datapath Security Tiers
Tracking Source of DoS attacks
DoS Attack Mitigation
SYN Flood Attack Mitigation using TCP Intercept
IP Fragmentation Attacks
IP Fragmentation Attack Mitigation
Spoofing Attacks
IPv6 Address Scope
Stateless DHCP (SLAAC)
Summary of Security Best Practices
Complete Your Online Session Evaluation
Type 4 versus Type 5 vulnerability
Example on login blocking and timeouts
Changing Privilege Levels of Commands
ACS Command Authorization
IOS Resiliency
Control Plane Protection (CoPPr)
Infrastructure Security
IPv6 Link Local Only Example
Zone Based Firewall
TCP Intercept
ZBFW configuration example
Spoofing Attack Mitigation
uRPF Advanced Features
Fundamental IOS Security Features

Fundamental IOS Security Features

