Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Disabled by defult

Status
Not open for further replies.
Feb 22, 2009
60
0
0
MX
Hello everybody, got a list of services that are recomended to set off in Cisco's routers and swtiches:

ip redirects
ip source-route
ip direct-broadcast
cdp run
bootp-server
dhcp-server
ip domain-lookup
proxy-arp
http server
finger
tcp-small-servers
ucp-small-servers
identd

Verifying the IOS manuals for 12.2 and 12.3, found that:

identd
small-servers
finger
direct-broadcast

are disable by default.

I couldn't get the same clarification for: http server, proxy-arp, domain-lookup, dhcp-server, bootp-server, cdp run, source-route and ip redirects, can I considere them enabled if the negation of the command is not shown in the configuration?

 
Yes. Those are all enabled by default. The tcp-small-servers and udp-small-servers are in fact ALSO enabled by default---you MUST disable these.

/

tim@tim-laptop ~ $ sudo apt-get install windows
Reading package lists... Done
Building dependency tree
Reading state information... Done
E: Couldn't find package windows...Thank Goodness!
 
Hello
It all depends on the feature set and release.In most cases with a 12.3 others will be turn off.HTTP is almost always disable,to verify do a show run (this is the only mention one that you can see in the conf.Maybe also no ip domain-lookup if it's disable.For CDP,the command is "show cdp".Dhcp-server is normally on by default.Bootp-server, source-route and ip redirects depends on the release.To quickly turn of all these service,try the command below:
Router#auto secure

Regards
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top