Control 4 – Secure Configurations of Network Devices Such as Firewalls, Routers, and Switches

Control 4 is similar to Control 3 in that it is concerned with maintaining a secure configuration. This time the focus is on network devices.

What is the last thing you did on your network devices? Likely it was add a rule to permit a new traffic flow. When was the last time you made sure the configuration is exactly what you expected?

Where to start?
Several authoritative hardening guides exist and are freely available. Choose one of the below and plan to spend a few hours making sure your network device configurations are secure.

             CheckPoint Firewall Benchmarks
             Cisco Device Benchmarks
             Juniper Device Benchmarks
             Network Device Benchmarks
             Novell Netware Benchmarks
             Wireless Network Devices Benchmarks

What else?

Always maintain an updated network diagram. I know. You still should.

Change control forms should be completed (with appropriate approvals) before logging in to the device.

Speaking of logging in, require two factor authentication for every device login.

Alert all administrators of all attempted logins and rule changes.

Compare the current configuration of your network devices to a known good configuration.

2 thoughts on “Control 4 – Secure Configurations of Network Devices Such as Firewalls, Routers, and Switches

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.