文档介绍:UNCLASSIFIED
Report Number: C4-054R-00
Router Security
Configuration Guide
Principles and guidance for secure configuration of IP routers,
with detailed instructions for Cisco Systems routers
Router Security Guidance Activity
of the
System work Attack Center (SNAC)
Authors: Updated: November 21, 2001
Vanessa Antoine Version:
Patricia Bosmajian
Daniel Duesterhaus
Michael Dransfield
Brian Eppinger
Jame s Houser
Andrew Kim
Phyllis Lee
David Opitz
Michael Wiacek
Mark Wilson
Neal Ziring
National Security Agency
9800 Savage Rd. Suite 6704
Ft. Meade, MD 20755-6704
******@
UNCLASSIFIED
Router Security Configuration Guide UNCLASSIFIED
Warnings
This document is only a guide to mended security settings for Protocol
(IP) routers, particularly routers running Cisco Systems Operating System
(IOS) versions 11 and 12. It is not meant to replace well-designed policy or sound
judgment. This guide does not address site-specific configuration issues. Care must
be taken when implementing the security steps specified in this guide. Ensure that
all security steps and procedures chosen from this guide are thoroughly tested and
reviewed prior to imposing them on an work.
This document is current as of September, 2001.
Acknowledgements
The authors would like to acknowledge Daniel Duesterhaus, author of the original
NSA “Cisco Router Security Configuration Guide,” and the management and staff of
the Applications and Architectures division for their patience and assistance with the
development of this guide. Special thanks also go to Ray Bongiorni for his quality
assurance and editorial work. Additional contributors to the development effort
include Andrew Dorsett, Jennifer Dorrin, Charles Hall, Scott McKay, and Jeffrey
Thomas.
Trademark Information
Cisco, IOS, and CiscoSecure are registered trademarks of Cisco Systems, Inc. in the
. and