Best practices: Review shows switches complying for secure management - Network World

Skip Links

DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

LANs & WANs

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library.  Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.

Additional Resources

RSS

FEATURED WHITEPAPERS

Core PCI Requirements for Windows and Active Directory NetPro

The Payment Card Industry Data Security Standard (PCI DSS) is a set of industry regulations imposed by the major credit card companies to ensure the safety, security, and integrity of cardholder data. Any business that processes, stores, and transmits cardholder account data must comply with this complex new standard, and must be able to demonstrate that compliance through automated and manual audits of their systems. This white paper looks at the key challenges and requirements of PCI DSS as it relates to Microsoft Windows and Active Directory, and shows you how a third-party software solution can help with PCI compliance.

RSS

FEATURED REPORTS

Executive Guide: Storage Heats Up HP

Get the latest on storage technologies that allow IT professionals to better cope with new IT demands. Learn how storage technologies can help you successfully tackle e-Discover, regulatory compliance, green data center initiatives and the data explosion. Get all the details now.

RSS

FEATURED WEBCASTS

Reduce Complexity and Cost - Windows Server Consolidation with Virtualization from Novell Novell

There are many compelling reasons for virtualizing Windows and Linux applications. Virtualization improves server utilization by allowing you to run multiple workloads on a single physical server. It reduces the number of physical servers you have to maintain, while allowing you to use less physical space and power while still improving scalability. All of these capabilities translate directly into lower costs, less complexity, and greater flexibility in your mixed IT environment. Register below to learn more and be entered to win an Archos 605 Portable Media Player.

Clear Choice Test 10G access switches
Introduction | Scorecard | Breaking standards |
How we did it | Test archive | Slideshow | Podcast
Inside this test package
Tests by topic

Most switches help in complying with secure management best practices

By David Newman, Network World Lab Alliance , Network World , 03/24/2008
  • Social Web 
  • Email 
  • Feedback 
  • Close
Clear Choice Test

In assessing switch management and security, we sought to answer three questions: Did devices follow current best practices by default? Could users configure switches to follow these best practices? And could switches be wiped clean of any sensitive information before being taken out of deployment?

The "wipe clean" question stems from regulatory requirements in a growing number of industries. For example, NIST, the U.S. government's standards body, and the credit card industry's Payment Card Industry Data Security Standard (PCI DSS) both require the deletion of any personally identifiable information before disposal.

We assessed reset capabilities by deleting the startup configuration file of each switch after putting it through performance and security tests. For all but the Alcatel-Lucent, Extreme and HP switches, that was enough to wipe the systems clean. HP's ProCurve switch stores passwords separately in flash memory, but these can be deleted through use of front-panel buttons. The procedure is documented, and HP also says it's moving toward inclusion of encrypted passwords in the switch configuration file.

The Alcatel-Lucent and Extreme switches both retain passwords even after a factory reset. In addition, Extreme's Summit X450 also retains the private SSH key, which could allow an attacker to pose as an authorized device even after the switch has been retired.

We also determined which management methods were enabled by default, and which would need to be enabled or disabled by network managers (see Management and Security Methods table).

These best practices include disabling insecure management methods such as telnet (supported out of the box over IPv4 by all switches by default), Web and SSHv1. Best practices mean accessing the switch only through secure means such as SSHv2 and/or Secure-HTTP and also logging switch events to a syslog server (a requirement under many enterprise security policies).

Cisco's Catalyst 3750E adhered the closest to security best practices. However, it supports telnet by default, as do all other switches. Also, when enabling SSH the Catalyst supports the insecure Version 1 of that protocol (although SSHv1 can be disabled via an additional command).

1 | 2 | 3 |  Next >
Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.
First Name
Last Name
E-mail
Zip Code
IT Buyer's Guides

View All Buyer's Guides