There is a security risk to plug the internet router management on the LAN port?

I have to install an ASR1001 on the internet for my business.  I noticed that the ASR1001 has a dedicated management port and I was wondering if it's a security risk to have this mangment port directly connected to my local network, so that I can mange it from my office.

I want to only run the ASR of this port and I will no management through its public IP address.  Is it possible for a malicious user to compromise the router then have access to the network but this management port?

I'd say it's a reasonable risk.  If you intend not to allow future management of the public side sessions you are a good start, implementation of protection against attacks.  Combine that with a few basic hardening, for example to disable source routing, directed broadcast, ip proxy arp, finger, as well as an ACL on the management interface so that all traffic from an untrusted interface on the router would be unable to receive return traffic.  In addition, the management vlan must be a dedicated vlan.  I would not fall in the same vlan in that your office is located.  Better design would be to fall into a dmz (acl on the router's management interface would be redundant in this case) and to apply the rules of the firewall.  However, if this is not possible, order access to routing on the ASR as well by including only a 32 road to your management station via the management VLAN interface.  Also, remove any redisribution or advertising of this management interface in your routing protocol.

Tags: Cisco Security

Similar Questions

  • Equium M50 will not recognize the LAN port - error: disconnected network cable

    I own a Toshiba Equium M50 and have problems with the Marvell Yukon 88E8036 PCI-E Fast Ethernet Controller.

    I used to connect through a Modem/DSL switch "ADDON" and had no problems. I then replaced the ADDON with an ADSL Modem/Router "NETGEAR" DG834G to win the wireless port, and since that time my machine won't recognise the LAN port. .

    I know that cables are OK I used with other phones and had no problems. I can also plug a PCI card to connect without any problems. It seems to me that if the Marvell Yukon 88E8036 PCI-E Fast Ethernet Controller has a problem with the netgear Modem/Router.

    Anyone out there with a similar experience and some tips/suggestions?

    PLEASE

    Hello

    For me this doesn't show t as a problem of LAN card but your router is a problem.
    Check Device Manager if the network card is correctly recognized. If there is no yellow exclamation point, so all is ok!
    You can try to remove the network adapter from Device Manager and reboot after new install driver LAN again.

    The question has looked after installing or connecting the new Netgear modem router.
    I would recommend to check first the settings or update the firmware on this router.

    I found more useful websites
    http://compnetworking.about.com/od/WindowsNetworking/f/cableunplugged.htm

    http://www.experts-exchange.com/Networking/broadband/DSL_Cable/Q_20381405.html

  • WRT54GP2 cascade successfully, but VOIP does not work via the LAN port

    Hello

    I searched a lot for a solution to my problem, but have found that it is really above my level of understanding. My apologies if this question has been answered before – if she, I can not find or understand.

    I have an existing wired network that is running on a Netgear WPN824v2. This configuration works perfectly.

    I want to add a Linksys WRT54GP2 to this network to act as a Wi - Fi hotspot and the VOIP connection point. I don't want to replace the Netgear with the Linksys, I want the different VOIP in a physical location access point. I would therefore like to them so cascading: Internet-> modem->-> Linksys Netgear. I do not want to bind the Netgear and Linksys Wireless, but instead, use a cable.

    I actually had this works almost perfectly, using the following parameters:

    NETGEAR IP 192.168.1.1 with wireless off

    Linksys IP 192.168.1.254 with disabled DHCP, active wireless.

    In this way, the Internet works, I can open a session the two routers and wireless of Linksys works very well.

    The problem is that VOIP will not work. I think it is because the connection between the two routers is: port LAN Netgear-> port of Linksys LAN.

    I understand VOIP tries to go through the Linksys WAN port, not the LAN port. If I connect LAN Netgear port-> Linksys WAN port, the phone works indeed but I can no longer connect to the Linksys, wireless router and unable to connect more.

    I would like to VOIP and the wireless work at the same time. Is there a way to get the VOIP by the Linksys LAN port instead of the WAN port? Or is there a way to make wireless and router connection work, if the Linksys is connected to the Netgear via its WAN port?

    Thanks in advance!

    -Jono

    When you wired your VOIP phone directly to the Netgear router you can in fact calls?

    If your Netgear router connect to the Linksys router to the WAN port, it will not work. As you already disable DHCP on your Linksys router and you will not have access to your Linksys router. This type of configuration has some other parameters.

    Connect the Netgear router to router Linksys on the WAN Port, then connect your computer to the router on the LAN Port Linksys. To connect to the Linksys router using default IP: 192.168.1.1 and change the LAN IP of the router Linksys 192.168.2.1 and DHCP must be activate and click on save settings. Once the parameters are now save your network power cycle and all your computers should be able to go online.

  • Satellite U200 - cannot get the LAN port to work

    Hello

    I hope someone can help. I reloaded a new version of windows on my laptop, I don't have the recovery disk but downloaded all the drivers from this site. However, I can not the LAN port to work. I tried several times to install the driver but no luck. In the Device Manager, it says device cannot start for the Intel 82559 fast Ethernet LAN on motherboard.

    Can someone please offer some advice? I am a person of correct PC then understand the concepts and can get around the windows.
    Thank you

    Satellite U200 what model do you have? The number of other Sat U200-xxx would be very useful to know which LAN chip was equipped with your laptop.

    But generally, you can find all the drivers on the European driver Toshiba page.
    Check the model number and serial (bottom) and choose the correct LAn driver Toshiba page.

    Notes; Win XP should be updated to the last State. I mean that you need SP2 and the additional fixes to ensure that everything would be fine.

    Good luck

  • Shockwave flash 16.0.0.235 installed, there is a security risk, cannot update

    There is an obsolete page on the Adobe Flash website blocked by Firefox 35.0.1 under Windows 7. Version 16.0.0.235 of Flash is labeled a security risk, "Always enable" is grayed out. I was on the Plugins page, and there I clicked on the update now linktext. I have been informed that all the old versions of Flash in the range of version 11 are blocked. Anywhere where go to from there. (My screenshot has a piece off the coast the Plugins page over top of the resulting page when I clicked the links provided).

    Obsolete page being blocked has been received and I was able to run through the download process, but in the end, I got an error.
    I tried several times to download install_flashplayer16x32_mssd_aaa_aih.exe, that downloads OK, and when I run it it downloads and installs Adobe Flash, then said: finishing and "There was a mistake."

    Flash software Glary Utilities Update update Internet Explorer, says nothing about Firefox, now I know why. It is a mess.

    I opened firefox Pei and went into the new profile Virgin I had created sometimes back. He was happily running a fully compatible version of Flash 11 (I bet that wouldn't last long because my browser's biting me in the end and disables it).

    Firefox Pei and I created a new profile today. It has this crippled version 16.0.0.235 Flash.

    It seems that Mozilla has an obsolete page telling me that all the old versions in the range of version 11 are blocked. No word on the newer versions.

    From what I've read, others are in what concerns other browsers and come with a bad Flash, too. I don't have Firefox (well, Internet Exploder, which I cut like a piece of trash since they came out with IE 7).

    Any advice? Thank you.

    This is over my head. I called the big players to help you.

  • Satellite 1800-100: a kind of metal in the LAN port

    I have an old S1800-100 (about 4-5 years), there is a kind of metal in the front where I (would) attach my ethernet cable. It is a problem since I finally had time to DSL. I'm sure this is a silly question, but it does not mean that I do not have a card? What should I do? Buy a card and install or buy a new computer?

    / Catharina

    Hello

    Network port on this unit is not available. You can use the LAN PCMCIA card. I'm sure that this card is not expensive. Check it out at your local retailer.

    Good bye

  • HPPavilion for computer laptop 15-ab516TX: cable Ethernet stuck in the LAN port

    Hello

    Ethernet cable is stuck in my laptop's LAN port.

    He won't get out if I pull/push it.

    I plugged in for the first time in my brand new laptop and don't want to brake it.

    Please help and solutions.

    Should I take my laptop to hp service center.

    Will you please answer soon because I can't travel with hangging cable.

    Help!

    Solved!
    Use a screwdriver and slowly 2 x take the cable into the port of the back of the laptop.
    In this way...
    Safe also take the cable without damaging the laptop components.

  • WRT54GL cannot transmit from inside the LAN port?

    Hello

    I have a Server servers running several (HTTP, SVN, FTP,...) inside my network.

    I used to have a SMC router in the past, and of course I had to use port forwarding.

    This is why I realized that when we "talk" to the server, I can 'talk' to the router that will forward requests to the right compurer, based on the NAT table. If, for example, that if I move the SVN server, I don't have to change the path to the repository, change the NAT entry is OK in this case.

    If this is not understandable, here 's another report.

    However, I discovered that even if my new WRT54GL seems to be much more advanced, it cannot do this. Requests made to the router from within the local network are not transferred to the right place.

    Is there a way to accomplish what we need, or at least a road map? It's sad that the SMC products otherwise is not very reliable can do...

    Kind regards

    Matej

    Well, I have it solved.

    I tried to convey the SVN, HTTP, FTP, and SSH.

    However, it was not working when the server IP assigned by DHCP.

    When I set up (the server within the LAN) to use the static IP address, not only that port forwarding began to make sense, but I have seen web pages by typing my public IP address in the browser on a computer inside the LAN.

    What surprised me, is that it only worked when the server had assigned auto private IP address. I know that these addresses change so it would not very long work, but it did not work even before that t has changed...

  • Trying to connect a computer to the lan port Aiport Express "auto assigned IP address"

    I am trying to connect a computer to the lan on my Airport Express port. In preferences, it says "status: connected, Ethernet has an assigned IP address and won't be able to connect to the internet." Any suggestions?

    An "auto assigned" IP address indicates that your computer could not find or negotiate with a DHCP server to obtain an IP address appropriate for network access.

    It should be more on your network to provide assistance if you need it. For example, is the terminal of AirPort Express the only router in the current configuration of your network? What exact model do? What is the brand and model of your modem Internet?

  • Fluke 8845 A does not meet the LAN port

    I downloaded Fluke 884 X installed and installed driver.  The 8845A is connected to an internal LAN network.   Manually set the IP address, subform on the instrument.  Used the Measurement & Automation Explorer to search for the device.  Autodiscover does not work, but a manual entry of the raw socket.  Could validate the connection of the device.

    However, when I place a simple VI - say to run, well, whatever it is - initialize, system, etc., it seems I get a time-out error.  (I'm tired of sitting in the corner).  In any case, is someone tried the LAN connection?  Since I am new to LabView, maybe I missed something?

    Thanks in advance.

    I don't think that the DMM 8845/8846 is compliant VXI - 11, while the instrument of Agilent is compatible, you can check if the moat has an update of the firmware.

  • More than two devices to connect to the LAN ports and none can see Internet

    If I connect another router to my Netgear and use this another router by connecting four or five devices, all can see the internet and work very well. But if I remove this another router and connect these four devices to one of the ports on my Netgear modem/router, these devices each receive its own IP address (as expected), but NONE of THEM can access the internet.

    No idea why?

    Everything works fine. Note, please, that the Netgear modem/router has always worked well - the problem was with the flaky DNS server addresses provided by Comcst.

  • When it is connected to the LAN, FF cannot find servers; no problem with the wi - fi

    26.0 Firefox running on a Windows 8.1 System. The thing I meet is this: I have no problem loading of pages and surfing when I am connected to my wi - fi network (I have a double function modem that wireless and LAN at the same time). However, whenever I plug the LAN cable, I get the error message that Firefox can't find the server. In this case if I disconnect the wireless at the same time. BUT, if I continually press the button [start] or simply tap the icon reload the page in the address bar, will eventually load, usually after a few failed attempts. However, the page loads usually only partially in a first time, apparently without advanced HTML formatting. But, after clicking on reload again one or two times, the page loads normally. Unknown, is that the behavior is not consistent - some pages of charge very well. But I can't for the life of understand me a boss.

    I've tried troubleshooting by disabling NoScript, but it doesn't seem to make a difference.  It's almost as if the wait time for a response from the server is so minimal when connected to LAN that the server has no chance of loading the first time.  Does that make any sense?  If so, how can I go about fixing the issue?
    

    Thanks for any help you can offer on this (for me, anyway) head-scratcher.

    Maybe another DNS server is used or there is still cached data.

    Have you tried a hard facing to bypass the cache to refresh all files?

    • Hold down the SHIFT key and click the Reload button
    • Press 'Ctrl + F5' or 'Ctrl + Shift + R' (Windows, Linux)
    • Press 'Command + shift + R' (Mac)

    You can also try to switch to work offline/off voltage after changing the network connection.

    If is also possible that your firewall treats the Wi - fi connection other than the connection to the local network.

  • U2412m continues to go to power saving on the Display Port!

    According to the title, the monitor works fine on DVI - D, however, when you use the Display Port, it will never get photo.

    I unplugged all the cables and only connected 1 monitor to my computer. When I plug the Display Port, the monitor recognizes the cable, and he goes to sleep. However, he never wakes up and there are always connected via the Port display power saving mode.

    I have connected my second monitor, and Windows by virtue of the resolution of the screen, I can see the two monitors that on DVI and the other on the display port., but the display port we'll never come back to life.

    My problem is similar to this: http://en.community.dell.com/support-forums/peripherals/f/3529/t/19534915.aspx

    And this: http://en.community.dell.com/support-forums/peripherals/f/3529/p/19444864/20290936.aspx

    People who could not find a solution to this. What is the problem with this monitor and display port?

    The screen does not appear even the POST screen or windows loading

    Hello.

    I bought another DP cable to replace the one I bought on ebay. Well, this one works very well, so it was the cable. Summer reading on the 20 pin and how that creates a problem.

  • Satellite 3000 - X 11 - cannot find the Lan driver

    I have a Satellite 3000 - x 11 laptop which has a local network on the back, but I can't find a driver lan for this anywhere X-(i have reinstalled windows XP, hoping that would find it, but no luck)
    ,

    There is no driver on the surport only a driver to dailup modem. Can someone help me with what he drives me crazy.
    Oh and the same device manager dose not see.
    Thanks in advance :D

    To my knowledge, this Satellite 3000 - X 11 doesn't supports LAN.
    Did you find the LAN port anywhere?

  • Satellite 4100XCDT: how the IRDA port works under DOS

    I have a Toshiba Satellite 4100xcdt. How do I assign a COM port to the IRDA (infrared) port in the BACK so I can use programs such as Winsamp
    http://www.veg.Nildram.co.UK/remote.htm

    The BIOS assigns COM1 and COM2 serial port to the built-in modem. However there is not a single option for the IRDA port not found.

    How can I make the IRDA port works under DOS?

    In my opinion it of not possible to use the IrDA DOS, because drivers must be installed and initialized.
    The IrDA port driver is a common Windows driver and the irda connection works only when windows was loaded

Maybe you are looking for

  • Retrieve album art

    just updated to the new Itunes v 12.4.0.119.  and I can't find the option to retrieve album artwork - when I choose a specific song in my library Any suggestions?

  • IPod Classic 160 GB freezes Itunes when connected

    I plugged my Ipod classic to my laptop to synchronize with Itunes and it went through all the processes as usual except at the end he came with an error message saying that the synchronization has failed. I retried the sync and got the same message.

  • Bad resolution of Qosmio G30 - external display via the HDMI connection-

    Hello! This problem makes me crazy, please help if you can... I just bought a G30-102 and I am trying to use it with an external display via the HDMI connection. The problem I have is that the native resolution of 1920 x 1200 cut the edges of the scr

  • shortcut screen locking with 3rd party keyboard

    I have a HP external keyboard attached to my mac and I was wondering how to lock the screen as you would with Windows (windows + L) or Linux (Crtl + Alt + L) so I can get up and leave my computer. Is it possible to do it without 3rd party software?

  • Replaced motherboard and later unknown device

    Hi guys,. Following a recent motherboard failure, I replaced the motherboard with the same model (ebay). I expected is not working (tattoo questions), but hey it worked very well! Finally almost fine. The material shows a unknown device driver and al