
Router Security ◾ 323
Trace the route from the inside PC to BB1 (“tracert
164.1.1.2”). This should be successful because the traceroute
reply traffic (time exceeded and port unreachable) is permitted
by the following ACL entry:
Next, trace the route from BB1 to the inside PC (traceroute
184.1.1.2). This should not be allowed because outside UDP
traffic is prohibited by the following ACL entry:
8.5 Chapter Summary
The router on the border of the network represents a vulner-
able entry point to the whole network, and hence its security
is significant. In this chapter, various methods of securing
the router were discussed, including the AAA model