Chapter1 Cisco SDM Express
Supplementary Help
1-32
Cisco SDM Express
OL-7141-04
You can undo this fix using the CiscoSD M Security Audit feature. To learn how,
see the Securi ty Audit online h elp in Cisco SDM. For more information, click
CiscoRouter and Security Device Manager.
Enable Netflow Switching
Cisco SDM Express enables Netflow switching whenever possible. Netflow
switching is a Cisco IOS feature that enhances routing performance while using
Access Control Lists (ACLs) and other features that create and enhance network
security. Netflow identifies flows of network packets based on the source and
destination IP addresses and TCP port numbers. Netflow then can use just the
initial packet of a flow for comparison to ACLs and for other security checks,
rather than having to use every packet in the network flow. This enhances
performance, allowing you to make use of all of the router security features.
The configuration that will be delivered to the router to enable Netflow is as
follows:
ip route-cache flow
You can undo this fix using the CiscoSD M Security Audit feature. To learn how,
see the Securi ty Audit online h elp in Cisco SDM. For more information, click
CiscoRouter and Security Device Manager.
Enable TCP Keepalives for Inbound Telnet Sessions
Cisco SDM Express enables TCP keepalive messages for both inbound and
outbound Telnet sessions whenever possible. Enabling TCP keepalives causes the
router to generate periodic keepalive messages, letting it detect a nd drop broken
Telnet connections.
The configuration that will be delivered to the router to enable TCP keepalives for
inbound Telnet sessions is as follows:
service tcp-keepalives-in
You can undo this fix using the CiscoSD M Security Audit feature. To learn how,
see the Securi ty Audit online h elp in Cisco SDM. For more information, click
CiscoRouter and Security Device Manager.