switch and router security [7:56721]

2002-11-01 Thread Wilson, Christian
I have recently implemented the following switches and routers: 4006 6509 3640 2600 My dillema is how to secure remote administration. I have not been able to find any documentation supporting SSH on the 4006's. I have found docs on SSH for the 6509, but only in hybrid mode, and I am running na

Re: switch and router security [7:56721]

2002-11-01 Thread Router Man
For basic user login authentication I would suggest Tacacs+ . Its very easy to setup and has some nice features such as encryption of the username/password and keeping a log of each user's executed commands. You can manually configure username/passwords or use a unix passwd file. Please note that

Re: switch and router security [7:56721]

2002-11-02 Thread Wow
It may not be practical due to the physical location of the equipment but you might also set up a terminal server. you can ssh to the terminal server and rev telnet to the device on the console port of the device. then disable access to the vty lines completely on each device. ""Wilson, Christi

Re: switch and router security [7:56721]

2002-11-02 Thread Bruno Fernandes
Don't forget Kerberos. Regards, BF ""Wilson, Christian"" wrote in message news:... > I have recently implemented the following switches and routers: > > 4006 > 6509 > 3640 > 2600 > > My dillema is how to secure remote administration. I have not been > able to find any documentation supportin

Re: switch and router security [7:56721]

2002-11-02 Thread Andrew Dorsett
On Fri, 1 Nov 2002, Wilson, Christian wrote: > My dillema is how to secure remote administration. I have not been able to > find any documentation supporting SSH on the 4006's. I have found docs on > SSH for the 6509, but only in hybrid mode, and I am running native. I have > found a sketchy do

Re: switch and router security [7:56721]

2002-11-02 Thread Andrew Dorsett
On Sat, 2 Nov 2002, Router Man wrote: > > Does RADIUS, S/Key, and TACACS+ encrpt the data between my PC and the > > router, or does it just encrypt the login iformation between the router > and > > the ACS server? I need to protect my sessions end to end. Any advise A few other things. Just so