Chapter 2: Cisco Network Security Elements


When we talk about Cisco network security elements, we are usually considering PIX firewalls, virtual private network (VPN) concentrators , and intrusion detection system (IDS) appliances. However, every Cisco router and switch has a wealth of useful security features even if no specialized (for example, Context Based Access Control [CBAC] supporting) IOS/CatOS version is employed. In many cases, when properly configured, these features can offer a sufficient level of protection for your network without having to buy costly specialized security appliances.

This chapter outlines common security features of Cisco networking devices and provides recommendations on IOS and CatOS version selection for your networking and security needs.

