Disable Ip Redirects; Disable Ip Proxy Arp - Cisco OL-4015-08 User Manual

Cisco router and security device manager user's guide
Table of Contents

Advertisement

Fix It Page

Disable IP Redirects

Disable IP Proxy ARP

Cisco Router and Security Device Manager Version 2.2 User's Guide
16-18
NetFlow identifies flows of network packets based on the source and destination
IP addresses and TCP port numbers. NetFlow then can use just the initial packet
of a flow for comparison to ACLs and for other security checks, rather than having
to use every packet in the network flow. This enhances performance, allowing you
to make use of all of the router security features.
The configuration that will be delivered to the router to enable NetFlow is as
follows:
ip route-cache flow
This fix can be undone. To learn how, click
Security Audit disables Internet Message Control Protocol (ICMP) redirect
messages whenever possible. ICMP supports IP traffic by relaying information
about paths, routes, and network conditions. ICMP redirect messages instruct an
end node to use a specific router as its path to a particular destination. In a
properly functioning IP network, a router will send redirects only to hosts on its
own local subnets, no end node will ever send a redirect, and no redirect will ever
be traversed more than one network hop. However, an attacker may violate these
rules; some attacks are based on this. Disabling ICMP redirects will cause no
operational impact to the network, and it eliminates this possible method of
attack.
The configuration that will be delivered to the router to disable ICMP redirect
messages is as follows:
no ip redirects
Security Audit disables proxy Address Resolution Protocol (ARP) whenever
possible. ARP is used by the network to convert IP addresses into MAC addresses.
Normally ARP is confined to a single LAN, but a router can act as a proxy for
ARP requests, making ARP queries available across multiple LAN segments.
Because it breaks the LAN security barrier, proxy ARP should be used only
between two LANs with an equal security level, and only when necessary.
Chapter 16
Undoing Security Audit
Security Audit
Fixes.
OL-4015-08

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sdm 2.2

Table of Contents