1-41
Cisco SDM Express
OL-7141-04
Chapter1 Cisco SDM Express
Supplementary Help
The configuration that will be delivered to the router is as follows:
security passwords min-length <6>
Set Authentication Failure Rate to Less Than 3 Retries
Cisco SDM Express configures your router to lock access after 3 un successful
login attempts whenever possible. One method of cracking passwords, called the
“dictionary” attack, is to use software that attempts to log in using every word in
a dictionary. This configuration causes access to the router to be locked for a
period of 15 seconds after 3 unsuccessful login attempts, disabling the dictionary
method of attack. In addition to locking access to the router, this configuration
causes a log message to be generated after 3 unsuccessful login attempts, warning
the administrator of the unsuccessful login attempts.
The configuration that will be delivered to the router to lock router access after 3
unsuccessful login attempts is as follows:
security authentication failure rate <3>
Set Banner
CiscoSDM Express configures a text banner whenever possible. In some
jurisdictions, civil and/or criminal prosecution of users who break into your
systems is made much easier if you provide a banner informing un authorized
users that their use is in fact unauthorized. In other jurisdictions, you may be
forbidden to monitor the activities of even unauthorized users unless you have
taken steps to notify them of your intent to do so. The text banner is one met hod
of performing this notification.
The configuration that will be delivered to the router to create a text banner is as
follows, replacing <company name>, <administrator email address>, and
<administrator phone number> with the appropriate values that you enter into
Cisco SDM Express:
banner ~
Authorized access only
This system is the property of
<company name>
Enterprise.
Disconnect IMMEDIATELY as you are not an authorized user!
Contact
<administrator email address>
<administrator phone number>
.
~