CCNA Security Certification Exam Tutorial
Using SDM To Perform A Security Audit
By Chris Bryant, CCIE #12933
In the first two sections of this CCNA Security Exam tutorial, we used the Security Device Manager (SDM) to put a Cisco router into one-step lockdown.
The one-step lockdown is effective, but a pretty drastic step as well. You may want to take an incremental approach to securing your router. The Security Audit feature in SDM gives us this option.
To give the Security Audit feature something to audit, I've removed the lockdown configuration from the router.
Here's the Security Audit Wizard launch button:
SDM then presents us with a summary of the Security Audit feature.
After the audit runs, we're presented with a long list of potential security issues, along with passed or not passed.



The next screen gives us the option to fix the not passed issues on a per-issue basis, or to undo the passed issues.

Selecting Fix the Security problems presents us with a list of those perceived problems, and the option to fix them. There is a Fix All option, but you can fix each individually as well.

After selecting Fix All and clicking Next, I am indeed "prompted for more information to fix certain settings", as the above window mentioned. I now have to set an enable password and a login banner.

After this screen, I was prompted to configure the IOS Firewall. We'll save that for a future tutorial.
Finally, we arrive at the Summary window. Here's just a part of that window: 
Clicking Finish delivers the config, and we're done!

We can also put the router into lockdown at the command line, and we'll take a look at that in a future installment of this CCNA Security Exam tutorial series!
You can also learn how to configure lockdown from the CLI - along with hundreds of other skills you'll need to pass the CCNA Security exam - with my CCNA Security Exam Study Package!
Don't Forget...To become CCNA Security certified, you've got to first be a CCNA.

Be sure to bookmark this page - I'll continue to post CCNA Security tutorials, videos, and practice exam question sets for you on this page. You'll also find free tutorials, articles, and practice exams on the CCNA Voice exam and CCNA Wireless exam pages as well!
To your success,
Chris Bryant
CCIE #12933
chris@thebryantadvantage.com
|