Cisco IOS Configuration analysis

Cisco IOS Configuration analysis

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Cisco IOS Configuration analysis Subba Rao 09-16-2005
Posted by Subba Rao on September 16, 2005, 6:15 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hello,

I have been assigned a task to do a risk assessment for a Cisco router
(7600 family). It has been a while since I played with a Cisco router.
The routers I have configured (about 4 years ago) were much smaller.
The IOS feature set seems to have changed a lot. In any case, this
task has been assigned to me. The problem with this configuration file
that I am analyzing has about 16000 lines of configuration. If you
remove the comments/blank lines, probably 14000 lines. That is a huge
configuration.

Now I have downloaded the Router Analysis Tool (RAT) from cisecurity.org
site and executed it against the configuration file. The output files
are straight forward. Is there any other tool that will do similar
analysis on IOS configuration? That would help me find some of the
common problems identified from both the tools.

Any help is appreciated.

Thank you in advance.

Regards,
--
SR
castellan2004-mail@SPAMBUSTER.yahoo.com
Please remove SPAMBUSTER to reply via email.


Posted by Volker Birk on September 17, 2005, 9:40 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> I have been assigned a task to do a risk assessment for a Cisco router
> (7600 family). It has been a while since I played with a Cisco router.

This is an oxymoron. It will be difficult for you, I think.

> The routers I have configured (about 4 years ago) were much smaller.
> The IOS feature set seems to have changed a lot. In any case, this
> task has been assigned to me. The problem with this configuration file
> that I am analyzing has about 16000 lines of configuration. If you
> remove the comments/blank lines, probably 14000 lines. That is a huge
> configuration.

Yes. What's with the idea to structure and shorten this configuration
first?

> Now I have downloaded the Router Analysis Tool (RAT) from cisecurity.org
> site and executed it against the configuration file. The output files
> are straight forward. Is there any other tool that will do similar
> analysis on IOS configuration?

The best tool I know is called "brain" ;-) The configuration must be
read and reviewed.

> That would help me find some of the
> common problems identified from both the tools.

What problems are you targeting?

Yours,
VB.
--
"Es kann nicht sein, dass die Frustrierten in Rom bestimmen, was in
deutschen Schlafzimmern passiert".
Harald Schmidt zum "Weltjugendtag"


Similar ThreadsPosted
Used Cisco Used Switch Used Cisco Router Used Cisco Switch At LinkWaves Corp August 16, 2006, 3:34 pm
Ciphire - Schneier Analysis February 14, 2005, 12:01 am
Network Security Analysis January 20, 2006, 10:00 am
Changes in setup/configuration for VPN and IPSec?? April 26, 2007, 4:58 am
Forensic Analysis of Facial Features April 12, 2008, 9:14 am
Account data stored in Configuration Mgmt DB January 26, 2005, 6:11 am
Yasca v1.0 Released - New Static Analysis Tool October 6, 2008, 11:00 am
SSRT4726 rev.0 Carrier Grade Invalid LAN Management Configuration April 8, 2004, 6:34 am
ldap error at the time of nagios plugin configuration May 12, 2005, 2:42 am
OSD CIO: Network configuration, scanning softened cyberattack blow March 10, 2008, 5:21 pm

The site map in XML format XML site map

Contact Us | Privacy Policy