Leaflet

Corporate Headquarters:
Copyright © 2004 Cisco Systems, Inc. All rights reserved.
Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-1706 USA
Infrastructure Protection on Cisco Catalyst 6500
and 4500 Series Switches
A key element in an organization's overall security posture is the security of the network infrastructure.
The network infrastructure is the foundation built with routers, switches, and other equipment that
provide the fundamental network services that keep a network running. The infrastructure is often the
target of denial of service (DoS) and other attacks that can directly or indirectly disrupt the network
operation. In order to ensure the availability of the network, it is critical to implement the security tools
and best practices that help protect each network element, and the infrastructure as a whole.
This document describes the tools that are currently available to protect Cisco Catalyst 6500 and 4500
Series switches from direct attacks. These tools can also help prevent accidental misconfiguration, which
could present a risk to the infrastructure. This document also provides deployment guidelines to help
implement these tools as an integrated security solution, rather than as isolated elements.
The first portion of this document provides an overview of the basic tools and technologies that are
available on Catalyst switches for network device hardening. Subsequent sections provide a closer look
at more advanced features that require additional explanation. Later sections provide deployment
guidelines that describe how to implement these features in an integrated way, followed by additional
reference information.
Contents
Basic Tools and Techniques for Device Hardening 5
Disabling Unneeded Services 5
Controlling Switch Access 6
Access Control Lists 7
Router ACL 8
VLAN ACL(VACL) 8
Configuring VACLs in Catalyst OS 9
Configuring VACLs in Cisco IOS 10
Port ACL (PACL) 12
Configuring PACLs in Catalyst OS 13

Summary of content (112 pages)