Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Cisco > ACL for Cat2950 security

Reply
Thread Tools

ACL for Cat2950 security

 
 
Vorta
Guest
Posts: n/a
 
      02-10-2005
Hello:

I'm going to put a Catalyst 2950-24 on, connecting to our provider via
Ethernet. I already programmed an access-list for the vty interfaces,
and an access-list for ip http access, I need it for Cisco Network
Assistant program.

Is there any other access-lists I need to protect the switch itself? I
assigned an IP to it for monitoring purposes, I usually put these
managed switches behind the firewall but this one is going to be
infront of it.

TIA,

J.

 
Reply With Quote
 
 
 
 
Leigh Harrison
Guest
Posts: n/a
 
      02-10-2005
What I have done in the past in these situations is this:-

Have a management vlan on the switch and have the ip for management on
there. The side that faces the internet/untrusted area leave as an
unmanaged vlan so no access can be got to it. It's also a good idea to put
access-classes on the telnet lines, if you've not already.

LH

"Vorta" <> wrote in message
news: oups.com...
> Hello:
>
> I'm going to put a Catalyst 2950-24 on, connecting to our provider via
> Ethernet. I already programmed an access-list for the vty interfaces,
> and an access-list for ip http access, I need it for Cisco Network
> Assistant program.
>
> Is there any other access-lists I need to protect the switch itself? I
> assigned an IP to it for monitoring purposes, I usually put these
> managed switches behind the firewall but this one is going to be
> infront of it.
>
> TIA,
>
> J.
>



 
Reply With Quote
 
 
 
 
Vorta
Guest
Posts: n/a
 
      02-10-2005
Interesting. Pardon my ignorance, but
How would I do what you proposed? right now, everything is on "VLAN1" I
think.

TIA,

John.
Leigh Harrison wrote:
> What I have done in the past in these situations is this:-
>
> Have a management vlan on the switch and have the ip for management

on
> there. The side that faces the internet/untrusted area leave as an
> unmanaged vlan so no access can be got to it. It's also a good idea

to put
> access-classes on the telnet lines, if you've not already.
>
> LH
>
> "Vorta" <> wrote in message
> news: oups.com...
> > Hello:
> >
> > I'm going to put a Catalyst 2950-24 on, connecting to our provider

via
> > Ethernet. I already programmed an access-list for the vty

interfaces,
> > and an access-list for ip http access, I need it for Cisco Network
> > Assistant program.
> >
> > Is there any other access-lists I need to protect the switch

itself? I
> > assigned an IP to it for monitoring purposes, I usually put these
> > managed switches behind the firewall but this one is going to be
> > infront of it.
> >
> > TIA,
> >
> > J.
> >


 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Dhcp Relay Agent And Acl On Sw 3750, DHCP Relay Agent and ACL on Sw 3750 Vimokh Cisco 3 09-06-2006 02:16 AM
Trunking: Aironet 1200 - Cat2950 toddedu@yahoo.com Cisco 7 12-19-2005 02:44 PM
PIX - Can extended ACL's be used as crypto ACL's on a PIX Shad T Cisco 0 06-29-2004 06:27 PM
IT-Security, Security, e-security COMSOLIT Messmer Computer Support 0 09-05-2003 08:34 AM
Re: Cat3500XL .vs. Cat2950 VLan problem sPiDEr Cisco 2 07-14-2003 02:31 AM



Advertisments
 



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57