Re: Secure IOS configuration template

From: Rafi Sadowsky (rafi@meron.openu.ac.il)
Date: Thu Aug 17 2000 - 15:49:17 EDT


On Thu, 17 Aug 2000, Deepak Jain wrote:

>
> You probably want to disable "outside" SNMP requests by default
> suggestion. I would also suggest telnet/etc, but that is very much a
> per-network thing.
 I suggest using SSH(V1) instead of telnet to connect securely
it was introduced in 12.0(5)S(Service Provider - IP only image ) or 12.1(3)T
 See
<http://www.cisco.com/univercd/cc/td/doc/product/software/ios120/120newft/120limit/120s/120s5/sshv1.htm>
for details

(TIP - if you don't have a 3DES supporting image - you'll need to compile
the SSH client with "des"
(this is not the default AFAIK as normally 3DES/Blowfish/IDEA are used)

Enjoy
        Rafi

>
> Deepak Jain
> AiNET
>
> On Thu, 17 Aug 2000, Rob Thomas wrote:
>
> > Hello, listfolk.
> >
> > I have recently "released" version 2.0 of my Cisco secure IOS configuration
> > template. I would love to have any feedback, suggestions, and criticisms
> > you might provide. You can find the template here:
> >
> > http://www.enteract.com/~robt/Docs/Articles/secure-ios-template.txt
> >
> > I hope you find it of use.
> >
> > Thanks!
> > Rob.
> > --
> > Rob Thomas
> > http://www.enteract.com/~robt
> >
> >
> >
>
>



This archive was generated by hypermail 2b29 : Sun Aug 04 2002 - 04:12:15 EDT