Router Service Hardening: Turning Off What You Never Needed
Harden a Cisco router by disabling unused services, proven with a real before-and-after Nmap scan taking Telnet from open to closed, plus syslog design.
Harden a Cisco router by disabling unused services, proven with a real before-and-after Nmap scan taking Telnet from open to closed, plus syslog design.
Configure authenticated NTP on Cisco IOS XE, why IOS flags MD5 as weak, and how ntp authenticate and trusted-key stop a rogue server moving your clock.
Build RFC 2827 (BCP 38) anti-spoofing with an ingress ACL and uRPF strict mode, tested with real spoofed packets and live Cisco ACL log evidence.
CoPP is one aggregate policer; CPPr subdivides the control plane and adds port-filtering. A decision guide backed by a real CoPP police capture.
CPPr subdivides the control plane into host, transit and cef-exception subinterfaces and adds port-filtering, next to real CoPP police captures from CML.
Zone-Based Firewall, ASA, and FTD solve different jobs. This comparison uses real command output captured from all three platforms to show you which Cisco firewall belongs where, not which one is best.
Flat ZBF policies do not scale. This post shows how nested class-maps let you reuse protocol groups across policies and combine match-all conditions with match-any protocols to build layered, maintainable firewall policy.
Your ZBF matches protocol http, but the app on TCP 8080 will not pass because the inspector cannot see it. Port-maps teach the IOS XE protocol inspector about non-standard ports. Real cat8000v output shows the failure and the fix.
The Zone-Based Firewall is the stateful firewall inside Cisco IOS XE. This anchor guide covers zones, zone-pairs, the class-map and policy-map model, and the default-drop trap that locks engineers out of their own routers.
OSPF and IS-IS send every flow down the shortest path while parallel links sit idle. MPLS-TE is how you steer traffic onto the paths you choose. This post covers the problem, the components, and why segment routing is changing how it is done.
Cisco removed Clientless SSL VPN (WebVPN) from the ASA in 9.17. Real 9.24 CLI proof, and the Secure Client remote-access VPN that replaced it.
Enable ASDM on a Cisco ASA 9.24, hit the image-not-set gotcha, and get the honest 2026 verdict on the Java GUI versus the CLI.