Network World
Thursday, July 24, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community

Audit and lockdown your Cisco routers quickly using Router and Security Device Manager

90+% of Cisco Router administrators are CLI jockeys, myself included. However, there are several GUI tools that can help you manage and secure your Cisco routers very quickly. The one I want to focus on today is Cisco’s free Security Device Manager (SDM). Like most of Cisco’s device managers it allows you to manage one router at a time. Given some of the recent security news regarding Cisco routers I thought this topic might be timely in helping you lock down your Cisco routers. To quote from the Cisco SDM site, “Cisco Router and Security Device Manager (SDM) is an intuitive, Web-based device management tool supported on Cisco 830 series through Cisco 7301 routers. SDM provides smart wizards and advanced configuration support for LAN and WAN configurations, NAT, Stateful Firewall Policy, Intrusion Prevention, IPSec virtual private network (VPN), Easy VPN Client and Server configurations, Digital Certificates, and Quality of Service (QoS) Policy features. SDM also offers a 1-click router lockdown and an innovative Security Auditing capability to check and recommend changes to router configuration based on ICSA Labs, and Cisco TAC recommendations.”

Two of the SDM security lockdown features that I want to bring to your attention are the Router Security Audit and One-click lockdown wizards. The security audit wizard uses Cisco TAC certified and ICSA best practice rules to audit your router’s current security posture. The SDM audit wizard will:

  • Check the routers running configuration against a list of pre-defined best practice router security settings.
  • List identified problems and provide recommedations for fixing them.
  • Allows the administrator to select which problems they want SDM to fix now. SDM will then guide the user through the process of fixing the problems.

Here is a look at SDM’s home page

To Launch the Security Audit Wizard you click on the Perform Security Audit button



You then tell SDM what interfaces are external and which ones are internal so it knows which security policies checks apply based on an interfaces role.



The Audit wizard then runs through its checks and spits out a report like the one below:



As you can see you have the ability to click the Fix All button or click any of the Fix It check boxes. Any boxes you check will enable SDM to automatically fix them for you or in rare cases it takes you to the exact configuration screen where you can fix them. You can also export this report in HTML format. Click HERE for an example report. This can be filed away for when the auditors come knocking; preferably you’d run the report after you’ve fixed the problems :).

So to fix the problems you can use this wizard or run the other nice tool One-step Lockdown. When you run the One-step lockdown wizard it reconfigures your router to make it more secure. It uses Cisco TAC, NSA, and ICSA Labs recommendations for how to best secure a Cisco IOS router. The first thing you will see is this screen, once you click Deliver it will send the commands to the router.



Now when you run the audit wizard you get a nice report you can download and file away:





SDM offers a nice security dashboard. On the dashboard it lists the top 10 threats seen, these threats are downloaded from the Cisco Security Alert Center website. The SDM dashboard shows you the exact Cisco IOS IPS signature that is needed to alert and/or block these attacks. From here you can simply check the Deploy box next to any of the top 10 attacks and SDM will download and active the IOS IPS signatures on your router. Pretty slick! Be careful with IOS IPS though as it can drastically affect the performance of Cisco routers. But for remote sites with links that are 1 or 2 T1’s it works fine.



SDM also has a nice firewall wizard that will quickly run you through how to setup the basics of an IOS firewall. IOS routers have a very robust, and fast, fully stateful firewall.



The IOS firewall even supports deep packet inspection, otherwise known as an application firewall. It can stop P2P, IM, Web attacks, etc. It has many of the features Cisco’s ASA firewall platforms do.



And if you just can’t get away from the CLI for certain things, SDM can accommodate you there as well. It has a config editor built in where you can type in commands:

SDM can be installed either just on your workstation or it can be installed on the routers flash memory or both. Installing it just on your laptop saves router flash space.

For more information on SDM see below:
http://www.cisco.com/go/sdm

The supported IOS version for 2800 and 3800 ISR routers is 12.4(2)T or newer. For a complete list of hardware and software support, plus the readme for SDM see
here.

To download the latest SDM version go to http://www.cisco.com/cgi-bin/tablebuild.pl/sdm



The opinions and information presented here are my personal views and not those of my employer.

Reply

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Latest software headlines from Network World:

Basic to-do apps for iPhone and iPod touch

Acrobat 9 Pro

Microsoft: Make an Xbox 360 game and get paid

Report: Beware of 'chaos' SharePoint can create

Cast Iron adds data-cleansing to integration appliance

  1   2   3   4   5   6   7   8   9  10  next 

Advertisement: