Cisco.Press.Router.Security.Strategies.Jan.2008.pdf

(5197 KB) Pobierz
648831016 UNPDF
648831016.009.png
Router Security Strategies
Securing IP Network Traffic Planes
Gregg Schudel, CCIE No. 9591
David J. Smith, CCIE No. 1986
Cisco Press
Cisco Press
800 East 96th Street
Indianapolis, Indiana 46240 USA
648831016.010.png
ii
Router Security Strategies:
Securing IP Network Traffic Planes
Gregg Schudel, CCIE No. 9591
David J. Smith, CCIE No. 1986
Copyright © 2008 Cisco Systems, Inc.
Cisco Press logo is a trademark of Cisco Systems, Inc.
Published by:
Cisco Press
800 East 96th Street
Indianapolis, IN 46240 USA
All rights reserved. No part of this book may be reproduced or transmitted in any form or by any means, electronic
or mechanical, including photocopying, recording, or by any information storage and retrieval system, without writ-
ten permission from the publisher, except for the inclusion of brief quotations in a review.
Printed in the United States of America
First Printing December 2007
Library of Congress Cataloging-in-Publication Data:
Schudel, Gregg.
Router security strategies : securing IP network traffic planes /
Gregg Schudel, David J. Smith.
p. cm.
ISBN 978-1-58705-336-8 (pbk.)
1. Routers (Computer networks)—Security measures. 2. Computer networks—Security measures.
3. TCP/IP (Computer network protocol)—Security measures. I. Smith, David J., CCIE. II. Title.
TK5105.543.S38 2007
005.8—dc22
2007042606
ISBN-13: 978-1-58705-336-8
ISBN-10: 1-58705-336-5
Warning and Disclaimer
This book is designed to provide information about strategies for securing IP network traffic planes. Every effort
has been made to make this book as complete and as accurate as possible, but no warranty or fitness is implied.
The information is provided on an “as is” basis. The authors, Cisco Press, and Cisco Systems, Inc. shall have neither
liability nor responsibility to any person or entity with respect to any loss or damages arising from the information
contained in this book or from the use of the discs or programs that may accompany it.
The opinions expressed in this book belong to the authors and are not necessarily those of Cisco Systems, Inc.
iii
Trademark Acknowledgments
All terms mentioned in this book that are known to be trademarks or service marks have been appropriately capital-
ized. Cisco Press or Cisco Systems, Inc., cannot attest to the accuracy of this information. Use of a term in this book
should not be regarded as affecting the validity of any trademark or service mark.
Feedback Information
At Cisco Press, our goal is to create in-depth technical books of the highest quality and value. Each book is crafted
with care and precision, undergoing rigorous development that involves the unique expertise of members from the
professional technical community.
Readers’ feedback is a natural continuation of this process. If you have any comments regarding how we could
improve the quality of this book, or otherwise alter it to better suit your needs, you can contact us through e-mail at
feedback@ciscopress.com. Please make sure to include the book title and ISBN in your message.
We greatly appreciate your assistance.
Corporate and Government Sales
The publisher offers excellent discounts on this book when ordered in quantity for bulk purchases or special sales,
which may include electronic versions and/or custom covers and content particular to your business, training goals,
marketing focus, and branding interests. For more information, please contact:
U.S. Corporate and Government Sales 1-800-382-3419 corpsales@pearsontechgroup.com
For sales outside the United States please contact: International Sales international@pearsoned.com
Publisher
Paul Boger
Associate Publisher
Dave Dusthimer
Cisco Representative
Anthony Wolfenden
Cisco Press Program Manager
Jeff Brady
Executive Editor
Brett Bartow
Managing Editor
Patrick Kanouse
Development Editor
Eric Stewart
Project Editor
San Dee Phillips/Jennifer Gallant
Copy Editor
Bill McManus
Technical Editors
Marcelo Silva, Vaughn Suazo
Editorial Assistant
Vanessa Evans
Book Designer
Louisa Adair
Composition
ICC Macmillan Inc.
Indexer
WordWise Publishing Services, LLC
Proofreader
Molly Proue
648831016.011.png 648831016.012.png 648831016.001.png 648831016.002.png 648831016.003.png 648831016.004.png 648831016.005.png 648831016.006.png 648831016.007.png 648831016.008.png
iv
About the Authors
Gregg Schudel, CCIE No. 9591 (Security), joined Cisco in 2000 as a consulting system engineer sup-
porting the U.S. Service Provider Organization. Gregg focuses on IP core network and services security
architectures and technology for inter-exchange carriers, web services providers, and mobile providers.
Gregg is also part of a team of Corporate and Field resources focused on driving Cisco Service Provider
Security Strategy. Prior to joining Cisco, Gregg worked for many years with BBN Technologies, where
he supported network security research and development, most notably in conjunction with DARPA and
other federal agencies involved in security research.
Gregg holds an MS in engineering from George Washington University, and a BS in engineering from
Florida Institute of Technology. Gregg can be contacted through e-mail at gschudel@cisco.com.
David J. Smith, CCIE No. 1986 (Routing and Switching), joined Cisco in 1995 and is a
consulting system engineer supporting the Service Provider Organization. Since 1999 David has
focused on service provider IP core and edge architectures, including IP routing, MPLS technologies,
QoS, infrastructure security, and network telemetry. Between 1995 and 1999, David supported
enterprise customers designing campus and global WANs. Prior to joining Cisco, David worked at
Bellcore developing systems software and experimental ATM switches.
David holds an MS in information networking from Carnegie Mellon University, and a BS in computer
engineering from Lehigh University. David can be contacted through e-mail at dasmith@cisco.com.
Zgłoś jeśli naruszono regulamin