Configure at least 3 external NTP Servers – ntp source-interface Details Accurate time is a critical piece of security infrastructure. Without accurate time on all infrastructure, it is complex or...
Configure BGP Authentication Details BGP is a usually configured as a point-to-point / unicast protocol. Configuring authentication as part of the neighbor configuration...
Configure BGP to Log Neighbor Changes Details Logging changes to the BGP peering relationships is recommended. Any logged changes will in the best case indicate a...
Configure EIGRP Authentication on all EIGRP Routing Devices Details You can configure authentication between neighbors for EIGRP Rationale: You can configure EIGRP authentication for the EIGRP process or...
Configure EIGRP Passive interfaces for interfaces that do not have peers Details EIGRP both listens on and advertises on all interfaces that have IPs in subnets that are defined as ‘networks’...
Configure HSRP protections – hsrp version 2 Details HSRP is a valuable redundancy protocol, but like many protocols discussed in this document can be attacked and compromised....
Configure HSRP protections – interface md5 Details HSRP is a valuable redundancy protocol, but like many protocols discussed in this document can be attacked and compromised....
Configure EIGRP log-adjacency-changes Details Logging changes to the EIGRP peering relationships is recommended. This setting is enabled by default. Rationale: Any logged changes...
Configure Netflow on Strategic Ports Details Netflow allows for detailed logging of transit traffic. For a Layer 3 Netflow configuration, this outlines several values identified...
Configure NTP Authentication Details By default, NTP is a clear text, unauthenticated protocol. However, it can be configured to authenticate time sources. NTP...