【文章內容簡介】
no ip unreachableRouter(configif) no ip redirectRouter(configif) no ip maskreplyRouter(configif) endRouterCD016禁止NTP服務Router show ip interface briefInterface IPAddress OK? Method Status ProtocolEthernet0/0 YES NVRAM up upEthernet1/0 YES NVRAM up upRouter config tEnter configuration mands, one per line. End with CNTL/Z.Router(config) interface eth 0/0Router(configif) ntp disableRouter(configif) exitRouter(config) interface eth 1/0Router(configif) ntp disableRouter(configif) endRouter Security Configuration GuideRouterCD017SNMP服務的設置Router show runningconfig | include snmpBuilding configuration...snmpserver munity public ROsnmpserver munity admin RWRouterRouter config tEnter configuration mands, one per line. End with CNTL/Z.清除舊的團體字串Router(config) no snmpserver munity public RORouter(config) no snmpserver munity admin RWRouter(config)使用訪問控制列表Router(config) no accesslist 70Router(config) accesslist 70 deny anyRouter(config) snmpserver munity MoreHardPublic Ro 70Router(config)禁用陷阱和系統(tǒng)關閉特性Router(config) no snmpserver enable trapsRouter(config) no snmpserver systemshutdownRouter(config) no snmpserver trapauthRouter(config)s禁用SNMP服務Router(config) no snmpserverRouter(config) endCD018禁用DNS服務Router config tEnter configuration mands, one per line. End with CNTL/Z.Router(config) no ip domainlookupRouter(config) no ip nameserver Router(config) endCD019啟用IP Unicast ReversePath VerificationRouter config t啟用CEFRouter(Config) ip cef啟用Unicast ReversePath VerificationRouter(Config) interface eth0/1Router(Config) ip verify unicast reversepathCD020設置Console和Buffered Logging設置console logging為level 5 (notify)Router(config) logging console notificationRouter(config) exitRouter config tEnter configuration mands, one per line. End with CNTL/Z在information level設置16K日志緩沖Router(config) logging buffered 16000 information在日志信息中啟用時間標記Router(config) service timestamp log date msec local showtimezoneRouter(config) exitRouter show loggingRouter Security Configuration GuideSyslog logging: enabled (0 messages dropped,1 flushes,0 overruns)Console logging: level critical, 0 messages loggedBuffer logging: level informational, 1 messages loggedTrap logging: level debugging, 332 message lines loggedLogging to , 302 message lines loggedLog Buffer (16000 bytes):Mar 28 11:31:22 EST: %SYS5CONFIG_I: Configured from console byvty0 ()Rou