Cisco CISCO876-SEC-I-K9 Configuration Guide - Page 118

Configuring Cisco IOS Firewall IDS, Configuring VPNs

Page 118 highlights

Configuring Cisco IOS Firewall IDS Chapter 12 Configuring Security Features Configuring Cisco IOS Firewall IDS Cisco IOS Firewall Intrusion Detection System (IDS) technology enhances perimeter firewall protection by taking appropriate action on packets and flows that violate the security policy or represent malicious network activity. Cisco IOS Firewall IDS identifies 59 of the most common attacks using "signatures" to detect patterns of misuse in network traffic. It acts as an in-line intrusion detection sensor, watching packets and sessions as they flow through the router, scanning each to match any of the IDS signatures. When it detects suspicious activity, it responds before network security can be compromised, logs the event, and, depending on configuration, sends an alarm, drops suspicious packets, or resets the TCP connection. For additional information about configuring Cisco IOS Firewall IDS, see the "Configuring Cisco IOS Firewall Intrusion Detection System" section of the Cisco IOS Release 12.3 Security Configuration Guide. Configuring VPNs A virtual private network (VPN) connection provides a secure connection between two networks over a public network such as the Internet. Cisco 850 and Cisco 870 series access routers support site-to-site VPNs using IP security (IPSec) tunnels and generic routing encapsulation (GRE). Permanent VPN connections between two peers, or dynamic VPNs using EZVPN or DMVPN which create and tear down VPN connections as needed, can be configured. Chapter 6, "Configuring a VPN Using Easy VPN and an IPSec Tunnel," and Chapter 7, "Configuring VPNs Using an IPSec Tunnel and Generic Routing Encapsulation," show examples of how to configure your router with these features. For more information about IPSec and GRE configuration, see the "Configuring IPSec Network Security" chapter of the Cisco IOS Release 12.3 Security Configuration Guide. For information about additional VPN configurations supported by Cisco 850 and Cisco 870 series access routers, see the following feature documents: • EZVPN Server-Cisco 870 series routers can be configured to act as EZVPN servers, letting authorized EZVPN clients establish dynamic VPN tunnels to the connected network. • Dynamic Multipoint VPN (DMVPN)-The DMVPN feature creates VPN tunnels between multiple routers in a multipoint configuration as needed, simplifying the configuration and eliminating the need for permanent, point-to-point VPN tunnels. 12-4 Cisco 850 Series and Cisco 870 Series Access Routers Software Configuration Guide OL-5332-01

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196

12-4
Cisco 850 Series and Cisco 870 Series Access Routers Software Configuration Guide
OL-5332-01
Chapter 12
Configuring Security Features
Configuring Cisco IOS Firewall IDS
Configuring Cisco IOS Firewall IDS
Cisco IOS Firewall Intrusion Detection System (IDS) technology enhances perimeter firewall protection
by taking appropriate action on packets and flows that violate the security policy or represent malicious
network activity.
Cisco IOS Firewall IDS identifies 59 of the most common attacks using “signatures” to detect patterns
of misuse in network traffic. It acts as an in-line intrusion detection sensor, watching packets and
sessions as they flow through the router, scanning each to match any of the IDS signatures. When it
detects suspicious activity, it responds before network security can be compromised, logs the event, and,
depending on configuration, sends an alarm, drops suspicious packets, or resets the TCP connection.
For additional information about configuring Cisco IOS Firewall IDS, see the “
Configuring Cisco IOS
Firewall Intrusion Detection System
” section of the
Cisco IOS Release 12.3 Security Configuration
Guide
.
Configuring VPNs
A virtual private network (VPN) connection provides a secure connection between two networks over a
public network such as the Internet. Cisco 850 and Cisco 870 series access routers support site-to-site
VPNs using IP security (IPSec) tunnels and generic routing encapsulation (GRE). Permanent VPN
connections between two peers, or dynamic VPNs using EZVPN or DMVPN which create and tear down
VPN connections as needed, can be configured.
Chapter 6, “Configuring a VPN Using Easy VPN and
an IPSec Tunnel,”
and
Chapter 7, “Configuring VPNs Using an IPSec Tunnel and Generic Routing
Encapsulation,”
show examples of how to configure your router with these features. For more
information about IPSec and GRE configuration, see the “
Configuring IPSec Network Security
” chapter
of the
Cisco IOS Release 12.3 Security Configuration Guide
.
For information about additional VPN configurations supported by Cisco 850 and Cisco 870 series
access routers, see the following feature documents:
EZVPN Server
—Cisco 870 series routers can be configured to act as EZVPN servers, letting
authorized EZVPN clients establish dynamic VPN tunnels to the connected network.
Dynamic Multipoint VPN (DMVPN)
—The DMVPN feature creates VPN tunnels between multiple
routers in a multipoint configuration as needed, simplifying the configuration and eliminating the
need for permanent, point-to-point VPN tunnels.