Disable Mop Service; Disable Ip Unreachables; Disable Ip Mask Reply - Cisco OL-4015-08 User Manual

Cisco router and security device manager user's guide
Table of Contents

Advertisement

Fix It Page

Disable MOP Service

Disable IP Unreachables

Disable IP Mask Reply

Cisco Router and Security Device Manager Version 2.2 User's Guide
16-20
Security Audit will disable the Maintenance Operations Protocol (MOP) on all
Ethernet interfaces whenever possible. MOP is used to provide configuration
information to the router when communicating with DECNet networks. MOP is
vulnerable to various attacks.
The configuration that will be delivered to the router to disable the MOP service
on Ethernet interfaces is as follows:
no mop enabled
This fix can be undone. To learn how, click
Security Audit disables Internet Message Control Protocol (ICMP) host
unreachable messages whenever possible. ICMP supports IP traffic by relaying
information about paths, routes, and network conditions. ICMP host unreachable
messages are sent out if a router receives a nonbroadcast packet that uses an
unknown protocol, or if the router receives a packet that it is unable to deliver to
the ultimate destination because it knows of no route to the destination address.
These messages can be used by an attacker to gain network mapping information.
The configuration that will be delivered to the router to disable ICMP host
unreachable messages is as follows:
int <all-interfaces>
no ip unreachables
This fix can be undone. To learn how, click
Security Audit disables Internet Message Control Protocol (ICMP) mask reply
messages whenever possible. ICMP supports IP traffic by relaying information
about paths, routes, and network conditions. ICMP mask reply messages are sent
when a network devices must know the subnet mask for a particular subnetwork
Chapter 16
Undoing Security Audit
Undoing Security Audit
Security Audit
Fixes.
Fixes.
OL-4015-08

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sdm 2.2

Table of Contents