Advanced Networking Services

 

SAFE Corporate Internet Module

Configuration Guide:

 

Catalyst Switch

 

 

June 9, 2004

 

Dwight Kinney & Greg Wallin

Network Consulting Engineer

 

 

 

 


 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Copyright (c) 2001 Cisco Systems, Inc. All rights reserved.

 

ALL CONTENTS IN THIS DOCUMENT ARE PROTECTED BY COPYRIGHT EXCEPT AS SPECIFICALLY PERMITTED HEREIN, NO PORTION OF THE INFORMATION IN THIS DOCUMENT MAY BE REPRODUCED IN ANY FORM, OR BY ANY MEANS, WITHOUT PRIOR WRITTEN PERMISSION FROM CISCO.


Table of Contents

 


Scope................................................................................................................................ 4

SAFE Threats Mitigated............................................................................................ 4

Configuration Goals..................................................................................................... 4

Design Diagram............................................................................................................. 5

Assumptions and Limitations................................................................................... 5

Catalyst Switch Configuration Details and Discussion..................................... 6

CDP (Cisco Discovery Protocol)........................................................................................... 6

Access control methods.............................................................................................. 7

Passwords......................................................................................................................... 7

Login Banner.................................................................................................................... 8

Authentication, Authorization, and Accounting................................................. 8

Configuring TACACS+ on the Catalyst Switch................................................. 9

Authentication................................................................................................................... 9

Authorization................................................................................................................... 10

Accounting...................................................................................................................... 10

Additional Configuration needed for Management LAN Connectivity........................................ 11

SNMP............................................................................................................................ 12

Access-lists................................................................................................................... 13

Private VLANs........................................................................................................... 14

NTP............................................................................................................................... 15

Ports............................................................................................................................... 16

Logging........................................................................................................................ 16

SPAN (Switch Port Analyzer)............................................................................... 17

Catalyst 6000 Intrusion Detection System Module....................................... 17

 

 


Scope


The Corporate Internet Module is a component of “Cisco SAFE: A Security Blueprint for Enterprise Networks”. The Corporate Internet Module provides internal users with connectivity to Internet services and Internet users access to information on publicly available corporate servers. The Catalyst Switches depicted in the module are vital aggregations points ensuring connectivity for all devices. Therefore hardening the Catalyst Switches should be a consideration for your overall security policy.

SAFE Threats Mitigated

 

Threat definitions as well as a complete discussion are available in Appendix B: Network Security Primer of “Cisco SAFE: A Security Blueprint for Enterprise Networks”.

 

 

Configuration Goals


Common to all switches

 

Specific to the 6509 switches on the Public Services Segment (PSS)

 


Design Diagram

 

 


Assumptions and Limitations

This configuration contains the Catalyst Switch configuration commands necessary to support the SAFE Corporate Internet Module as shown in the diagram above. Site-specific security policies, attached devices, and required services may require the modification of these configuration statements. The following assumptions and limitations apply: