Section 8.0: Advanced Security (10 points)

8.1. Perimeter Security (2 points)

  1. Configure R4 to block all Java applets within HTTP from the Internet.

8.2. IP Fragmentation (2 points)

  1. Internal networks have had increasing fragmentation issues mostly due to misconfiguration and vulnerabilities in the application servers. Configure PIX not to allow any fragmented packets through. Do not disable the floodguard feature on PIX.

8.3. Traffic Filtering Using Lock-and-Key (3 points)

  1. Configure an access list on the R1 (VLAN-2) interface to deny all traffic except Telnet.

  2. Configure R1 to dynamically open a hole for all traffic in this ACL when R2 authenticates with valid credentials.

  3. Configure AAA on R1 using TACACS+ for authentication. The console should not ...

Get CCIE Security Practice Labs now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.