Ccna, Ccent, Ccnp Tutorial on Routers and Routing


by M. Aslam - Date: 2008-11-21 - Word Count: 418 Share This!


Routers are the critical part of all the networks and can be both security aid and security vulnerability. A router basically has more network interfaces through which network traffic is forwarded. Or it might be blocked. The router decides when to forward packets between the networks based on internal routing table.


The routing table can also be static. That means where each route is explicitly defined or dynamic where the router learns new routes by the use the routing protocols.



A router also supports access control lists that specify which packets to allow or blocked. Every packet going through a router will be checked against the ACL to see if the packet is allowed to be forwarded. Lots of current routers offer security capabilities along with their routing functionality. Segmenting the network using routers limits the amount of the data flowing through segments. It also applies to broadcast traffic.



Routers also allow technicians to explicitly deny a few packets the ability to be forwarded between segments. Using just the internal security features of some,


routers can prevent users through internal network from using the Telnet to access external systems. Telnet are always a security risk as the passwords and all communications are transmitted in cleartext. Because of this, it's best not to create Telnet sessions between the internal network and an external network. Without a firewall, the rule can be put in place within the router to drop packets attempting to connect to port 23 on any external systems. After all of this is done by properly con- figuring the ACLs for the router. Spoofed packets are packets that contain the IP address in the header that are not the actual IP address of the


originating the computer. Routers combat this by giving the technicians the ability to drop packets which are coming through the interface from the wrong subnet. . If the packet comes in from the router's external interface by using an IP address from the network on the router's internal interface, the router can be instructed to drop the packet and not forward it. There are two types of access lists available to filter traffic on Cisco routers. One of them is a standard access list. It allows technicians to filter traffic from specific addresses or subnet ranges. Cisco also provides extended access lists, which allow technicians to filter based on a variety of criteria. This access list allows technicians to use source addresses, destination addresses, and specific network services as the basis of filtering rules.


Related Tags: ccna, router, routers, routing, ccent, ccna tutorial, ccent tutorial


Learn about CCNA Exam , Vista 64 bit and download vista service pack 1 .

Your Article Search Directory : Find in Articles

© The article above is copyrighted by it's author. You're allowed to distribute this work according to the Creative Commons Attribution-NoDerivs license.
 

Recent articles in this category:



Most viewed articles in this category: