Home > Networking Tips > Network Engineering > Remote router security checklist
Networking Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK ENGINEERING

Remote router security checklist


Tom Lancaster
01.24.2005
Rating: -3.71- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Most of our network equipment these days is racked and stacked in secure raised-floor datacenters, where we don't have to worry about it that much, but we all have to contend with routers and switches in small offices. Here are a few ideas to head off common security issues:

  • Put a password on the console port. This is often skipped when the device is physically inaccessible to anyone outside the network team, but remote offices are obviously vulnerable to unauthorized console port access. And if they can reach that port and cycle the power, they own the box and the config, and probably your passwords as well.
  • Secure the box in a wall-mount enclosure if possible. Many new devices, including Cisco's 3750 series of switches have a wonderful button on the front that allows you to reset the config to factory default without having to go through the trouble of twiddling bits in the config-register. Nice feature for a datacenter, but you don't want to be recovering from that remotely. The only thing worse is simple theft, where they walk off with the router or switch entirely. Wall-mount enclosures (locked of course) will also solve this problem.
  • If you can't afford or find an actual enclosure, at a minimum, consider a cable lock like the kind commonly used for laptops. Many routers and switches have the little security hole those cable locks fit into. And if they don't, there's usually a vent-hole you can use in a pinch.
  • Log configuration commands to a remote server. Don't trust the local log on the remote router or switch.
  • Remember that a lack of physical security in remote offices means it's much more vulnerable to sniffer or "man-in-the-middle" attacks because the cabling is exposed. Log up/down events on the link between your router and switch in remote offices. You might even want to enable traps for these events to notify your network management system. (Although I'm not sure how useful this will really turn out to be, many new switches are sporting Time-Domain Reflectometers on all the ports and it might be capable of detecting a change in cable length indicative of someone making unauthorized changes. When you initially implement the remote site, consider taking a survey on all the ports and record the cable lengths. Periodically check these numbers again to see if there are any changes.)
  • Disable CDP, disable any unused ports, and if there's only one switch in the office, consider disabling Spanning Tree so it can't be used to reroute traffic.

Obviously, many of these suggestions aren't appropriate for every environment. For example, don't disable CDP if you're doing PoE or voice VLANs. This should get you thinking about some special security issues you might have.


Tom Lancaster, CCIE# 8829 CNX# 1105, is a consultant with 15 years experience in the networking industry, and co-author of several books on networking, most recently, CCSPTM: Secure PIX and Secure VPN Study Guide published by Sybex.


Rate this Tip
To rate tips, you must be a member of SearchNetworking.com.
Register now to start rating these tips. Log in if you are already a member.


Submit a Tip




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Network Engineering
Limit network energy consumption with computer cooling technologies
Understanding remote scripting -- Managing Windows networks using scripts, part 9
Network mapping in Vista for Windows XP
Recovering domain controllers after a server disk failure
Recovering from a server disk failure: The shortcomings of NTBCKUP
Enabling Windows Vista's Network Mapping feature on domain networks
Prevent unauthorized USB devices with software restriction policies, third-party apps
How to subnet: Subnetting calculations and shortcuts
Using Windows Vista group policy to prevent unauthorized USB device use
ISDN implementation: Part 3 -- Cisco router ISDN configuration

Router and Switch Management
How many more users will 802.11n wireless access points support?
How to connect wireless networks for printing capabilities
How can I prevent collisions on my network?
How to upgrade an Input/Output Supervisor (IOS) router
Inter-VLAN routing with a LAN and WAN on a single router
Troubleshooting IP Routing -- 'CCNA Official Exam Certification Library, 3rd Edition,' Chapter 7
How can I load balance between DSLs and LLs?
How can I configure 10 VLANs with 5 unmanaged switches?
Cisco's ISR inches the company toward openness
How do I configure two leased lines in one router?

Network Cable
The difference between half-duplex and full-duplex
What are a TV tower's effects on your network?
What cable do I install for a Nortel wireless access point?
BICSI separation requirements between cross-connect points
What is the length of a ScUTP and TERA cable run?
USB direct cable connection: Cabling tips for network professionals, lesson 10
Parallel direct cable connection: Cabling tips for network professionals, lesson 9
Serial direct cable connection: Cabling tips for network professionals, lesson 8
Direct cable connection: Cabling tips for network professionals, lesson 7
ISDN implementation: Part 3 -- Cisco router ISDN configuration
Network Cable Research

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
32-bit IP addressing  (SearchNetworking.com)
autotrunking  (SearchNetworking.com)
delay-tolerant network  (SearchNetworking.com)
Internet Routing in Space (IRIS)  (SearchNetworking.com)
logical router  (SearchNetworking.com)
routing table  (SearchNetworking.com)
subnet  (SearchNetworking.com)
subnet mask  (SearchNetworking.com)
virtual routing and forwarding  (SearchNetworking.com)
weighted fair queueing  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Networking Solutions for Business
IT Management Solutions and Services Directory.
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts