E click next to view a summary of the problems that

This preview shows page 17 - 20 out of 44 pages.

e. Click Next to view a summary of the problems that will be fixed. Click Finish and deliver the commands to the router. Task 8: Configure a CBAC Firewall on R1 (Chapter 4) Step 1: Use the Cisco IOS AutoSecure feature to enable a CBAC firewall on R1.
a. To configure only the Context Based Access Control (CBAC) firewall on R1, use the auto secure command and specify the firewall option. Respond as shown in the following AutoSecure output to the AutoSecure questions and prompts. The responses are in bold. R1# auto secure firewall --- AutoSecure Configuration --- *** AutoSecure configuration enhances the security of the router, but it will not make it absolutely resistant to all security attacks *** AutoSecure will modify the configuration of your device. All configuration changes will be shown. For a detailed explanation of how the configuration changes enhance security and any possible side effects, please refer to Cisco.com for Autosecure documentation. At any prompt you may enter '?' for help. Use ctrl-c to abort this session at any prompt. Gathering information about the router for AutoSecure Is this router connected to internet? [no]: yes Enter the number of interfaces facing the internet [1]: 1 Interface IP-Address OK? Method Status Protocol FastEthernet0/0 unassigned YES unset administratively down down FastEthernet0/1 192.168.1.1 YES manual up up Serial0/0/0 10.1.1.1 YES SLARP up up Serial0/0/1 unassigned YES unset administratively down down Enter the interface name that is facing the internet: serial0/0/0 Configure CBAC Firewall feature? [yes/no]: yes This is the configuration generated: ip inspect audit-trail ip inspect dns-timeout 7 ip inspect tcp idle-time 14400 ip inspect udp idle-time 1800 ip inspect name autosec_inspect cuseeme timeout 3600 ip inspect name autosec_inspect ftp timeout 3600 ip inspect name autosec_inspect http timeout 3600 ip inspect name autosec_inspect rcmd timeout 3600 ip inspect name autosec_inspect realaudio timeout 3600 ip inspect name autosec_inspect smtp timeout 3600 ip inspect name autosec_inspect tftp timeout 30 ip inspect name autosec_inspect udp timeout 15 ip inspect name autosec_inspect tcp timeout 3600 ip access-list extended autosec_firewall_acl permit udp any any eq bootpc deny ip any any interface Serial0/0/0 ip inspect autosec_inspect out ip access-group autosec_firewall_acl in !
end Apply this configuration to running-config? [yes]: yes Applying the config generated to running-config R1# Feb 12 18:34:58.040: %AUTOSEC-5-ENABLED: AutoSecure is configured on the device

  • Left Quote Icon

    Student Picture

  • Left Quote Icon

    Student Picture

  • Left Quote Icon

    Student Picture