Here is the current configuration I want to use for my 2621 router as a firewall. Please make any suggestions that will help me use this router as a good firewall against incoming traffic. I have not named the router or set any of the passwords yet. I will before I go live with it.
~Is there anyway log log the traffic the router is allowing and dropping?
sho run
Building configuration...
Current configuration : 1446 bytes
version 12.3
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
hostname XXXXXXXX
boot system flash
no aaa new-model
ip subnet-zero
no ip source-route
ip cef
no ip bootp server
ip audit po max-events 100
interface FastEthernet0/0
ip address
ip access-group 102 in
no ip unreachables
speed 100
interface Serial0/0
no ip address
interface FastEthernet0/1
no ip address
duplex auto
speed auto
ip http server
ip classless
access-list 102 deny icmp any any
access-list 102 deny tcp any any eq ftp
access-list 102 deny tcp any any eq ftp-data
access-list 102 deny tcp any any eq telnet
access-list 102 deny tcp any any eq 22
access-list 102 deny tcp any any eq pop3
access-list 102 deny tcp any any eq 143
access-list 102 deny udp any any eq tftp
access-list 102 permit icmp any any source-quench
access-list 102 permit icmp any any time-exceeded
access-list 102 permit icmp any any packet-too-big
access-list 102 permit icmp any any echo-reply
access-list 102 deny icmp any any fragments
access-list 102 deny icmp any any echo
access-list 102 permit tcp any any established
access-list 102 permit tcp any any
access-list 102 permit ip any any
access-list 102 deny tcp any any eq smtp
line con 0
line aux 0
line vty 0 4
System image file is "flash:c2600-io3-mz.123-19.bin"
with 36864K/4096K bytes of memory.
M860 processor: part number 0, mask 49
Bridging software.
X.25 software, Version 3.0.0.
2 FastEthernet/IEEE 802.3 interface(s)
1 Serial network interface(s)
32K bytes of non-volatile configuration memory.
16384K bytes of processor board System flash (Read/Write)
Configuration register is 0x2102
~Is there anyway log log the traffic the router is allowing and dropping?
sho run
Building configuration...
Current configuration : 1446 bytes
version 12.3
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
hostname XXXXXXXX
boot system flash
no aaa new-model
ip subnet-zero
no ip source-route
ip cef
no ip bootp server
ip audit po max-events 100
interface FastEthernet0/0
ip address
ip access-group 102 in
no ip unreachables
speed 100
interface Serial0/0
no ip address
interface FastEthernet0/1
no ip address
duplex auto
speed auto
ip http server
ip classless
access-list 102 deny icmp any any
access-list 102 deny tcp any any eq ftp
access-list 102 deny tcp any any eq ftp-data
access-list 102 deny tcp any any eq telnet
access-list 102 deny tcp any any eq 22
access-list 102 deny tcp any any eq pop3
access-list 102 deny tcp any any eq 143
access-list 102 deny udp any any eq tftp
access-list 102 permit icmp any any source-quench
access-list 102 permit icmp any any time-exceeded
access-list 102 permit icmp any any packet-too-big
access-list 102 permit icmp any any echo-reply
access-list 102 deny icmp any any fragments
access-list 102 deny icmp any any echo
access-list 102 permit tcp any any established
access-list 102 permit tcp any any
access-list 102 permit ip any any
access-list 102 deny tcp any any eq smtp
line con 0
line aux 0
line vty 0 4
System image file is "flash:c2600-io3-mz.123-19.bin"
with 36864K/4096K bytes of memory.
M860 processor: part number 0, mask 49
Bridging software.
X.25 software, Version 3.0.0.
2 FastEthernet/IEEE 802.3 interface(s)
1 Serial network interface(s)
32K bytes of non-volatile configuration memory.
16384K bytes of processor board System flash (Read/Write)
Configuration register is 0x2102