【文章內(nèi)容簡介】
no ip unreachableRouter(configif) no ip redirectRouter(configif) no ip maskreplyRouter(configif) endRouterCD016禁止NTP服務(wù)Router show ip interface briefInterface IPAddress OK? Method Status ProtocolEthernet0/0 YES NVRAM up upEthernet1/0 YES NVRAM up upRouter config tEnter configuration mands, one per line. End with CNTL/Z.Router(config) interface eth 0/0Router(configif) ntp disableRouter(configif) exitRouter(config) interface eth 1/0Router(configif) ntp disableRouter(configif) endRouter Security Configuration GuideRouterCD017SNMP服務(wù)的設(shè)置Router show runningconfig | include snmpBuilding configuration...snmpserver munity public ROsnmpserver munity admin RWRouterRouter config tEnter configuration mands, one per line. End with CNTL/Z.清除舊的團(tuán)體字串Router(config) no snmpserver munity public RORouter(config) no snmpserver munity admin RWRouter(config)使用訪問控制列表Router(config) no accesslist 70Router(config) accesslist 70 deny anyRouter(config) snmpserver munity MoreHardPublic Ro 70Router(config)禁用陷阱和系統(tǒng)關(guān)閉特性Router(config) no snmpserver enable trapsRouter(config) no snmpserver systemshutdownRouter(config) no snmpserver trapauthRouter(config)s禁用SNMP服務(wù)Router(config) no snmpserverRouter(config) endCD018禁用DNS服務(wù)Router config tEnter configuration mands, one per line. End with CNTL/Z.Router(config) no ip domainlookupRouter(config) no ip nameserver Router(config) endCD019啟用IP Unicast ReversePath VerificationRouter config t啟用CEFRouter(Config) ip cef啟用Unicast ReversePath VerificationRouter(Config) interface eth0/1Router(Config) ip verify unicast reversepathCD020設(shè)置Console和Buffered Logging設(shè)置console logging為level 5 (notify)Router(config) logging console notificationRouter(config) exitRouter config tEnter configuration mands, one per line. End with CNTL/Z在information level設(shè)置16K日志緩沖Router(config) logging buffered 16000 information在日志信息中啟用時間標(biāo)記Router(config) service timestamp log date msec local showtimezoneRouter(config) exitRouter show loggingRouter Security Configuration GuideSyslog logging: enabled (0 messages dropped,1 flushes,0 overruns)Console logging: level critical, 0 messages loggedBuffer logging: level informational, 1 messages loggedTrap logging: level debugging, 332 message lines loggedLogging to , 302 message lines loggedLog Buffer (16000 bytes):Mar 28 11:31:22 EST: %SYS5CONFIG_I: Configured from console byvty0 ()Rou