• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

Can this be stopped?

I'm trying to encourage him to go and get some education, whether it's a course, an O'Reilly book, or whatever. He doesn't have a grasp of the fundamentals, but he thinks he does, and he's trying to figure out what exact "thing" he needs to do to patch up this problem.

I'm trying to make him understand that a decent grasp of networking fundamentals is what he needs, not a command to make a Cisco router do... something, but he's not quite sure what.


I do not have alot of experience with professional grade router no, but i do know what should be done with a network, just havent had to implement it, not my job in the past, your honesty is appreciated and i am getting some books already on their way :)

I am not one to just do something half assed, i am very much the type, if your going to do it, do it right and do it right the first time,, or dont bother at all, so when this is done, it will be done properly.

This is a reason i have yet to touch the router, i want to be confident when i do i know enough to get done what needs to get done.

This t1 also isnt a "mission" critical connection, it could have down time, but prefered not too (we have our buisness cable line and i can also move the http to our ISP racks if needed which i am already in control of and configured)
 
My thoughts exactly.


OP...
From the options given- it seems like these are some of them you have.

  • Lock down access to changing IP addresses.
    As said- for right now today- this may be your fastest fix. But the problem is still there. Nobody should be able to run those IP addresses on your network. Simply locking down the access on those boxes doesn't solve the problem. Thus- it turns to a router-configuration solution.
  • Configure the router.
    Only "true" way to fix the issue. Routers don't give a crap about OS- so fix the problem here- you fix it everywhere for good.
  • Run everything through ISA on a SBS.
    This is pretty much the same as configuring the router- only your SBS box would become your router...

For now, i think i am going to go the ISA route, i am very familiar with ISA 2004 / 2007 and have implemented them in the past, not for work specifically but i do know ISA well enough to make it more then effective.

Once the books arrive i have on the way (grabbed some e-books for now) then i will head on to conquer the cisco 1701, this way i know i can do it right, along with the help from here :D

All the advice is great and this is semi new to me, in that i am now the one in charge of doing this, instead of giving others advice to do it, and them just ignoring me because they didnt know better and wouldnt admit it and just do a half assed job which got us to where we are now!
 
I'm trying to encourage him to go and get some education, whether it's a course, an O'Reilly book, or whatever. He doesn't have a grasp of the fundamentals, but he thinks he does, and he's trying to figure out what exact "thing" he needs to do to patch up this problem.

I'm trying to make him understand that a decent grasp of networking fundamentals is what he needs, not a command to make a Cisco router do... something, but he's not quite sure what.

Well to be honest, its not what he has asked for help on and I don't think the high and mighty lectures are going to help him at all. He knows there is a problem, he knows he maybe a bit out of his depth and all he wants is help on his solution. I get really pissed off with the way people are looked down on on this forum. Maybe some companies don't have the time or resources that you have or maybe he is learning as he goes along?

I just think there is a bit of snobbery and that's not what this place should be about.
 
One last thought; to get started, and begin learning things, you may want to install SDM (Secure Device Manager) on your 1700 (which is supported).

SDM will give you a hand-holding GUI to setup a firewall that would prevent your problem from occurring. http://www.cisco.com/en/US/products/sw/secursw/ps5318/index.html

It will also suggest "best practices" and offer security options such as One-Step-Lockdown.

For the non-CLI initiated, it would probably be a good management tool for you.

Otherwise, brush up on Cisco Router firewalling: http://www.cisco.com/univercd/cc/td...120newft/120t/120t5/iosfw2/iosfw2_2.htm#22529
 
One last thought; to get started, and begin learning things, you may want to install SDM (Secure Device Manager) on your 1700 (which is supported).

SDM will give you a hand-holding GUI to setup a firewall that would prevent your problem from occurring. http://www.cisco.com/en/US/products/sw/secursw/ps5318/index.html

It will also suggest "best practices" and offer security options such as One-Step-Lockdown.

For the non-CLI initiated, it would probably be a good management tool for you.

Otherwise, brush up on Cisco Router firewalling: http://www.cisco.com/univercd/cc/td...120newft/120t/120t5/iosfw2/iosfw2_2.htm#22529
Do NOT touch that SDM with a 10 foot pole. In fact, don't touch it with a 10 mile one, either.
Complete. Utter. Garbage.
 
I've never used it, but everyone I've ever met who manages Cisco routers has a very dim view of it.
 
I've never used it, but everyone I've ever met who manages Cisco routers has a very dim view of it.
It does have it uses, some were gone over quickly on the first page in this thread. Backing up, simple tasks and such are OK and do-able on it. As far as configuring and getting down and dirty on troubleshooting etc., it's junk.
 
I've never used it, but everyone I've ever met who manages Cisco routers has a very dim view of it.

SDM was designed for people who do not know CLI, which makes it an appropriate suggestion.

I manage Cisco routers, and I don't use it (though I did have to train on it / know it for the CCNP certs). The CLI is much more powerful, however, you need to know what you are doing.

For this office, SDM is probably their best bet to get started. It will also allow them to learn how CLI works by analyzing the configs after they are built.

Lastly, SDM will beat the pants off of making a VPN / Crypto MAP verses CLI any day.
 
note taken, shall try the SDM, was an original consideration but didnt seemed favored by people.
 
It does have it uses, some were gone over quickly on the first page in this thread. Backing up, simple tasks and such are OK and do-able on it. As far as configuring and getting down and dirty on troubleshooting etc., it's junk.
I think I said this once already (I might be the one you are mentioning?)

At any rate- saving off the configs cleanly, VIEWING/READING configurations is nice (graphical organization is nice to see how it is done). But as said- configuring with SDM is a PITA.
It strips out all ACLs when you change something. Which kills the connection (And when running real-time apps over it- a bad deal).
CLI does not.

My advise is learn CLI once and for all.

CLI- you know EXACTLY what you are doing and changing. Some of the automated configuration features in SDM leave old crap behind when removing them.

Several things I've found wrong with it. Only thing I use it for now is saving off configurations.
 
Back
Top