Security Sage's Guide to Hardening the Network Infrastructure

Chapter 8: Defending Routers and Switches

Introduction

Even with today s heavy concentration on protecting the internal segments, networking devices rarely get their share of attention. Administrators have been focusing on end-point security, or securing the desktop efforts geared to stop the next SQL Slammer or Blaster worm. Virus scanners, patch management, and vulnerability assessment systems continue to be purchased by IT and security teams to ensure that their internal networks will not be devastated by the next virus or worm outbreak. The IT mindset continues to be that Microsoft products pose the biggest security risk to their enterprise.

While the validity of that last statement will be argued for many years to come, the fact is that while administrators are focusing on securing those vulnerable systems, the devices they use to segment and protect their networks could pose just as serious a risk. Tell us if these statements sound familiar:

  • Don t fix what isn t broken.

  • Our routers and switches are doing their job, no reason to make any changes there.

  • The core router uses a non-Microsoft operating system, so it is secure by default.

  • I ve never had to reboot my router, so it must be doing its job securely, right?

  • There s a new slew of Microsoft patches every month! Thankfully, our routers aren t like that at all!

While it might be true that your network infrastructure has been working flawlessly for many months, it does not necessarily mean that you can neglect those devices. Network devices need just as much attention, if not more, than any Microsoft...

UNLIMITED FREE
ACCESS
TO THE WORLD'S BEST IDEAS

SUBMIT
Already a GlobalSpec user? Log in.

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.

Customize Your GlobalSpec Experience

Category: Wireless Network Components
Finish!
Privacy Policy

This is embarrasing...

An error occurred while processing the form. Please try again in a few minutes.