
Considerations
Cisco 7100 Series VPN Configuration Guide
2-6
— Normally, you should disable directed broadcasts for all applicable protocols on
your firewall and on all your other routers. For IP, use the no ip directed-broadcast
command. Rarely, some IP networks do require directed broadcasts; if this is the
case, do not disable directed broadcasts.
Directed broadcasts can be misused to multiply the power of denial-of-service
attacks, because every denial-of-service packet sent is broadcast to every host on a
subnet. Furthermore, some hosts have other intrinsic security risks present when
handling broadcasts.
— Configure the no proxy-arp command to prevent internal addresses from being
revealed. (This is important to do if you do not already have NAT configured to
prevent internal addresses from being revealed).
— Whenever possible, keep the firewall in a secured (locked) room.
• VPN Management—Implement one or more of the following applications on your
Cisco 7100 series router for centralized, end-to-end management of both the services
(for example, QoS and security features) and hardware (for example, device
configuration and performance) across your VPN:
— CiscoWorks 2000 and CiscoView enable management of device security and
configuration, and performance monitoring.
— CiscoWorks 2000 Access Control List Manager enables management of access
control lists.
— Cisco QoS Policy Manager enables management of advanced bandwidth policies.
— Cisco Internetwork Performance Monitor 2.0 enables monitoring of service-level
agreements across the service provider network.
To access the documentation for the above applications on CCO, follow this path:
Service and Support: Technical Documents: Documentation Home Page: Cisco
Product Documentation: Network Management
To access the documentation for the above applications on the Documentation
CD-ROM, follow this path:
Documentation CD Home Page: Cisco Product Documentation: Network
Management
Comentarios a estos manuales