CCNP ISCW Notes1 Apr 2008
Chapter 19: Securing Administrative AccessSecurity MeasuresLogin LimitationsExample base Authentication, Authorization and Accounting (AAA) configuration: Authentication failure logging generates a syslog message after a number of failed attempts within one minute, and prevents future logins for 15 seconds: Login blocking: Failed login delay: Success and failure logging: Quiet mode maps an access class matching origins exempt from these login restrictions: Login restrictions can be viewed with Line ProtectionsAn access-class can be applied to restrict logins to permitted sources: An idle timeout can be enforced: Setting the Minimum Password Lengths
Password Encryption
BannersA message of the day (MOTD) banner can be defined to advertise policy:
Custom Privilege LevelsThere are 16 privilege levels (0 through 15). Level 0 is user mode, level 15 is privileged mode, and levels 1 through 14 are customizable.
Role-based CLIRole-based CLI allows for users to belong to multiple views rather than a privilege level. Superviews link individual views:
Mitigating Physical AccessPassword recovery can be disabled to prevent someone with physical access to a device from rebooting into ROMMON:
|
Navigation
Armory
Online Toolbox
|
One of the best summary I have seen. It make life easier and time well spent. Good job. Gerard
nice work