-
CIS_Cisco_IOS_15_Benchmark_v4.0.0.pdf下载
资源介绍
Cisco IOS 15.xx 的安全加固。
Table of Contents
Table of Contents .................................................................................................................................................. 2
Overview .................................................................................................................................................................. 7
Intended Audience ........................................................................................................................................... 7
Consensus Guidance ........................................................................................................................................ 7
Typographical Conventions ......................................................................................................................... 8
Scoring Information ........................................................................................................................................ 8
Profile Definitions ............................................................................................................................................ 9
Acknowledgements ...................................................................................................................................... 10
Recommendations ............................................................................................................................................. 11
1 Management Plane .................................................................................................................................... 11
1.1 Local Authentication, Authorization and Accounting (AAA) Rules ............................... 11
1.1.1 Enable 'aaa new-model' (Scored) ....................................................................................... 12
1.1.2 Enable 'aaa authentication login' (Scored) ..................................................................... 14
1.1.3 Enable 'aaa authentication enable default' (Scored) .................................................. 16
1.1.4 Set 'login authentication for 'line con 0' (Scored) ........................................................ 17
1.1.5 Set 'login authentication for 'line tty' (Scored) ............................................................. 19
1.1.6 Set 'login authentication for 'line vty' (Scored) ............................................................ 21
1.1.7 Set 'aaa accounting' to log all privileged use commands using 'commands 15' (Scored) ................................................................................................................................................... 23
1.1.8 Set 'aaa accounting connection' (Scored) ........................................................................ 24
1.1.9 Set 'aaa accounting exec' (Scored) ..................................................................................... 26
1.1.10 Set 'aaa accounting network' (Scored) .......................................................................... 28
1.1.11 Set 'aaa accounting system' (Scored) ............................................................................. 30
1.2 Access Rules ........................................................................................................................................ 31
1.2.1 Set 'privilege 1' for local users (Scored) .......................................................................... 32
1.2.2 Set 'transport input ssh' for 'line vty' connections (Scored) .................................... 33
1.2.3 Set 'no exec' for 'line aux 0' (Scored) ................................................................................ 34
1.2.4 Create 'access-list' for use with 'line vty' (Not Scored) .............................................. 36
1.2.5 Set 'access-class' for 'line vty' (Scored) ............................................................................ 38