Section 8.0: Advanced Security (7 points)

8.1. ROMMON Security (3 points)

  1. Disable password recovery on R1 to prevent a person with physical access to the router(s) from viewing the configuration file and setting the configuration register to ignore the startup configuration.

8.2. Access Control (2 points)

  1. Configure PIX to reset denied TCP packets that terminate at the PIX's least-secure interface.

  2. Note that by default, these packets are silently discarded.

8.3. Access Restriction (2 points)

  1. Configure access restriction on R3 in VLAN4.

  2. R3 should be able to Telnet R2 but not vice versa.

  3. All other routers should be able to Telnet to R3.

Get CCIE Security Practice Labs now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.