Disable Pad Service; Disable Tcp Small Servers Service - Cisco OL-4015-08 User Manual

Cisco router and security device manager user's guide
Table of Contents

Advertisement

Chapter 16
Security Audit

Disable PAD Service

Disable TCP Small Servers Service

OL-4015-08
The configuration that will be delivered to the router to disable the Finger service
is as follows:
no service finger
This fix can be undone. To learn how, click
Security Audit disables all packet assembler/disassembler (PAD) commands and
connections between PAD devices and access servers whenever possible.
The configuration that will be delivered to the router to disable PAD is as follows:
no service pad
This fix can be undone. To learn how, click
Security Audit disables small services whenever possible. By default, Cisco
devices running Cisco IOS version 11.3 or earlier offer the "small services": echo,
chargen, and discard. (Small services are disabled by default in Cisco IOS
software version 12.0 and later.) These services, especially their User Datagram
Protocol (UDP) versions, are infrequently used for legitimate purposes, but they
can be used to launch DoS and other attacks that would otherwise be prevented by
packet filtering.
For example, an attacker might send a Domain Name System (DNS) packet,
falsifying the source address to be a DNS server that would otherwise be
unreachable, and falsifying the source port to be the DNS service port (port 53).
If such a packet were sent to the router's UDP echo port, the result would be the
router sending a DNS packet to the server in question. No outgoing access list
checks would be applied to this packet, since it would be considered to be locally
generated by the router itself.
Although most abuses of the small services can be avoided or made less dangerous
by anti-spoofing access lists, the services should almost always be disabled in any
router which is part of a firewall or lies in a security-critical part of the network.
Since the services are rarely used, the best policy is usually to disable them on all
routers of any description.
Cisco Router and Security Device Manager Version 2.2 User's Guide
Undoing Security Audit
Undoing Security Audit
Fix It Page
Fixes..
Fixes..
16-7

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sdm 2.2

Table of Contents