Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Disabled by defult

Status
Not open for further replies.
Feb 22, 2009
60
MX
Hello everybody, got a list of services that are recomended to set off in Cisco's routers and swtiches:

ip redirects
ip source-route
ip direct-broadcast
cdp run
bootp-server
dhcp-server
ip domain-lookup
proxy-arp
http server
finger
tcp-small-servers
ucp-small-servers
identd

Verifying the IOS manuals for 12.2 and 12.3, found that:

identd
small-servers
finger
direct-broadcast

are disable by default.

I couldn't get the same clarification for: http server, proxy-arp, domain-lookup, dhcp-server, bootp-server, cdp run, source-route and ip redirects, can I considere them enabled if the negation of the command is not shown in the configuration?

 
Yes. Those are all enabled by default. The tcp-small-servers and udp-small-servers are in fact ALSO enabled by default---you MUST disable these.

/

tim@tim-laptop ~ $ sudo apt-get install windows
Reading package lists... Done
Building dependency tree
Reading state information... Done
E: Couldn't find package windows...Thank Goodness!
 
Hello
It all depends on the feature set and release.In most cases with a 12.3 others will be turn off.HTTP is almost always disable,to verify do a show run (this is the only mention one that you can see in the conf.Maybe also no ip domain-lookup if it's disable.For CDP,the command is "show cdp".Dhcp-server is normally on by default.Bootp-server, source-route and ip redirects depends on the release.To quickly turn of all these service,try the command below:
Router#auto secure

Regards
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top