These topics contain operational recommendations that you are advised to implement. The operational procedures in use on the network contribute as much to security as the configuration of the underlying devices. Although most of this document is devoted to the secure configuration of a Cisco IOS device, configurations alone do not completely secure a network. Secure network operations is a substantial topic. Where possible and appropriate, this document contains recommendations that, if implemented, help secure a network.
However, in cases where it does not, the feature is explained in such a way that you can evaluate whether additional attention to the feature is required. The coverage of security features in this document often provides enough detail for you to configure the feature. The data plane does not include traffic that is sent to the local Cisco IOS device. Data Plane - The data plane forwards data through a network device.The control plane consists of applications and protocols between network devices, which includes the Border Gateway Protocol (BGP), as well as the Interior Gateway Protocols (IGPs) such as the Enhanced Interior Gateway Routing Protocol (EIGRP) and Open Shortest Path First (OSPF). Control Plane - The control plane of a network device processes the traffic that is paramount to maintain the functionality of the network infrastructure.Management Plane - The management plane manages traffic that is sent to the Cisco IOS device and is made up of applications and protocols such as Secure Shell (SSH) and Simple Network Management Protocol (SNMP).The three functional planes of a network, the management plane, control plane, and data plane, each provide different functionality that needs to be protected. If your network is live, make sure that you understand the potential impact of any command. All of the devices used in this document started with a cleared (default) configuration. The information in this document was created from the devices in a specific lab environment.
This document is not restricted to specific software and hardware versions. There are no specific requirements for this document. Structured around the three planes into which functions of a network device can be categorized, this document provides an overview of each included feature and references to related documentation. This document describes the information to help you secure your Cisco IOS ® system devices, which increases the overall security of your network.