
156 Chapter 5: Security Recommendations
• Provides logging for security
— Enables sequence numbers and timestamps
— Provides a console log
— Sets log buffered size
— Provides an interactive dialogue to configure the logging server ip address.
• Secures access to the router
— Checks for a banner and provides facility to add text to automatically
configure:
— Login and password
—Transport input and output
—Exec-timeout
— Local AAA
— SSH timeout and SSH authentication-retries to minimum number
— Enable only SSH and SCP for access and file transfer to and from the router
— Disables SNMP if not being used
• Secures the forwarding plane
— Enables Cisco Express Forwarding ...