CINXE.COM
Tactical Resources
<title>Tactical Resources</title> <meta http-equiv="X-UA-Compatible" content="IE=edge,chrome=1" /> <meta name="viewport" content="width=device-width, initial-scale=1, maximum-scale=1, user-scalable=0"/> <meta name="HandheldFriendly" content="true" /> <!--<base href="https://www.cisco.com" />--> <link rel="stylesheet" type="text/css" href="https://www.cisco.com/web/fw/w/cl/cl.min.css" /> <link rel="shortcut icon" href="https://www.cisco.com/favicon.ico" type="image/x-icon" /> <link href="https://sec.cloudapps.cisco.com/security/center/Resources/css/stylesheet.css" type="text/css" rel="stylesheet"> <link href="https://sec.cloudapps.cisco.com/security/center/Resources/css/tacticalResources.css" type="text/css" rel="stylesheet"> <link rel="stylesheet" href="https://sec.cloudapps.cisco.com/security/center/css/csp_relatedlinks.css" type="text/css"></link> <link rel="stylesheet" href="https://sec.cloudapps.cisco.com/security/center/css/csp_local.css" type="text/css" /> <!-- CSS file require to load OVP player in IE and firefox. It has style to load video player without flash player plugin--> <link href="https://www.cisco.com/assets/swa/flash/ovp/res_ovp.css" type="text/css" rel="stylesheet" /> <!-- AVID-5939 fixes : Changed jQuery version from 1.12.1 to 3.5.0 as recommended --> <script src="https://sec.cloudapps.cisco.com/security/center/Resources/js/jquery-3.5.0.js" type="application/javascript"></script> <script src="https://sec.cloudapps.cisco.com/security/center/Resources/js/angular.min.js"></script> <script src="https://sec.cloudapps.cisco.com/security/center/Resources/js/angular-route.min.js"></script> <script src="https://sec.cloudapps.cisco.com/security/center/Resources/js/module/module.js"></script> <script src="Resources/js/controllers/appliedIntelligenceController.js"></script> <!-- js file used to load online video player --> <script type="text/javascript" src="https://sadmin.brightcove.com/js/BrightcoveExperiences.js"></script> <!-- <script src="//www.cisco.com/etc/designs/cdc/clientlibs/responsive/js/web-component-foundation.min.js"></script> <script> cdc.wcAncillaryAssetAllocator.init(['cdc-template'], 'en/us', false, true, false, 'prod', true); </script> --> <script type="module" src="https://www.cisco.com/site/web-components/us/en/cdc-template.js"></script> <script> if (window.cdcext === undefined) { window.cdcext = {}; } cdcext.customEnvironment = 'prod'; cdcext.host = 'Cisco Security Center'; cdcext.locale = 'en-US'; if (window.cdclocale === undefined) { window.cdclocale = {}; } cdclocale.locale = 'en_us'; </script> </head> <body style="overflow-x: hidden; margin: 0%;"> <cdc-template> <div class="wrapper topHeadSection"> <div class="breadCrumbsSection clearfix"> <ul> <a href="http://www.cisco.com">Home</a> / <a href="https://sec.cloudapps.cisco.com/security/center/home.x">Cisco Security</a> </ul> </div> <div class="mainHeadSection clearfix"> <h4> Cisco Security </h4> <h1> Tactical Resources </h1> </div> </div> <div class="wrapper" ng-app="App" ng-cloak ng-controller="whitePapersController as whitePapersTab" > <link href="https://sec.cloudapps.cisco.com/security/center/Resources/css/FeedBack_Style.css" type="text/css" rel="stylesheet"/> <!-- <div id='siofeedback_tab' class='siofeedback_tab_right' tabindex='0'><a href='javascript:openNewWindow();'><div><span></span></div></a></div> --> <div id='ZN_0OjF4gJD0uzMamG'><!--DO NOT REMOVE-CONTENTS PLACED HERE--></div> <script> function openNewWindow(){ //alert('deep'); var a='https://ciscocx.qualtrics.com/jfe/form/SV_0q7r6A02bSNGuk6?Ref='+window.location.href+''; var height='325'; var width='550'; var left='420'; var top='400'; //alert('URL IS '+a) //window.open(a,'_blank','width='+width+',height='+height+',left='+left+',top='+top',scrollbars=yes'); window.open(a,'_blank','width='+width+',height='+height+',left='+left+',top='+top+',scrollbars=yes'); } </script> <script type='text/javascript'> (function(){var g=function(e,h,f,g){ this.get=function(a){for(var a=a+"=",c=document.cookie.split(";"),b=0,e=c.length;b<e;b++){for(var d=c[b];" "==d.charAt(0);)d=d.substring(1,d.length);if(0==d.indexOf(a))return d.substring(a.length,d.length)}return null}; this.set=function(a,c){var b="",b=new Date;b.setTime(b.getTime()+6048E5);b="; expires="+b.toGMTString();document.cookie=a+"="+c+b+"; path=/; "}; this.check=function(){var a=this.get(f);if(a)a=a.split(":");else if(100!=e)"v"==h&&(e=Math.random()>=e/100?0:100),a=[h,e,0],this.set(f,a.join(":"));else return!0;var c=a[1];if(100==c)return!0;switch(a[0]){case "v":return!1;case "r":return c=a[2]%Math.floor(100/c),a[2]++,this.set(f,a.join(":")),!c}return!0}; this.go=function(){if(this.check()){var a=document.createElement("script");a.type="text/javascript";a.src=g;document.body&&document.body.appendChild(a)}}; this.start=function(){var t=this;"complete"!==document.readyState?window.addEventListener?window.addEventListener("load",function(){t.go()},!1):window.attachEvent&&window.attachEvent("onload",function(){t.go()}):t.go()};}; try{(new g(100,"r","QSI_S_ZN_0OjF4gJD0uzMamG","https://zn0ojf4gjd0uzmamg-ciscocx.siteintercept.qualtrics.com/SIE/?Q_ZID=ZN_0OjF4gJD0uzMamG")).start()}catch(i){}})(); </script> <style> #QSIFeedbackButton-btn{ bottom: 39% !important; } #QSIFeedbackButton-btn:active, #QSIFeedbackButton-btn:focus { outline: none !important; } @media only screen and (max-width: 768px){ #QSIFeedbackButton-btn{ display: none !important; } } /* .QSIFeedbackButton div{ color:white !important; background-color: #1a8ce9 !important; } */ </style> <div id="whitePapersDiv" width="100%"> <div id="mobileWhitePapersTitle" width="100%"> <div ng-hide="showWhitePprTabsDwn" id="selectedWhitePaperTabName" ng-click="showAllWhitePprTabTitles();">{{finalTabName}}</div> <div id="mobileWhitePapersOptions" style="display: none;"> <ul style="border-top: 1px solid #cdcdcd;"> <li class="bottomBorder"> <div class="mDrpDwnOptPadingLeft10px" id="whitePprTab_2"> <a href="/security/center/tacticalresources.x#~NetworkDesignConsiderationsforSecurity" style="display: block; height: 45; padding-left: 10px;" name="whitePapersTab-1" ng-click="setSubTabForTR(1);setTabName('Network Design Considerations for Security')"> Network Design Considerations for Security </a> </div> </li> <li class="bottomBorder"> <div class="mDrpDwnOptPadingLeft10px" id="whitePprTab_2"> <a href="/security/center/tacticalresources.x#~RunningaSecureNetwork" style="display: block; height: 45; padding-left: 10px;" name="whitePapersTab-2" ng-click="setSubTabForTR(2);setTabName('Running a Secure Network')"> Running a Secure Network </a> </div> </li> <li class="bottomBorder"> <div class="mDrpDwnOptPadingLeft10px" id="whitePprTab_2"> <a href="/security/center/tacticalresources.x#~RespondingtoaSecurityIncident" style="display: block; height: 45; padding-left: 10px;" name="whitePapersTab-3" ng-click="setSubTabForTR(3);setTabName('Responding to a Security Incident')"> Responding to a Security Incident </a> </div> </li> </ul> </div> <div id="whitePpr-drpdwn-bottom-css"> <a href="javascript:void(0);" ng-click="showAllWhitePprTabTitles();" style="display:block;text-decoration:none;"> <p ng-hide="showWhitePprTabsDwn">˅</p> <p ng-show="showWhitePprTabsDwn">˄</p> </a> <!--<p>{{setBgrForSelctdTab(data.myModel)}}</p>--> </div> </div> <div id="tacticalResources"> <div class="loader" id="loader" > <img src="https://sec.cloudapps.cisco.com/security/center/Resources/images/loader.gif"/></div> <div width="100%" class = "tacticalResourcesSubTabTlsDiv"> <div id="tacticalResourcesSubTabTls"> <ul> <li ng-class="{activeSubTab2:isSubSetForTR(1)}"> <span style="display:none" ng-init="finalTabName='Network Design Considerations for Security'"></span> <a href="/security/center/tacticalresources.x#~NetworkDesignConsiderationsforSecurity" name="trSideTab-1" ng-click="setSubTabForTR(1)"> Network Design Considerations for Security </a> </li> <li ng-class="{activeSubTab:isSubSetForTR(2)}"> <a href="/security/center/tacticalresources.x#~RunningaSecureNetwork" name="trSideTab-2" ng-click="setSubTabForTR(2)"> Running a Secure Network </a> </li> <li ng-class="{activeSubTab:isSubSetForTR(3)}"> <a href="/security/center/tacticalresources.x#~RespondingtoaSecurityIncident" name="trSideTab-3" ng-click="setSubTabForTR(3)"> Responding to a Security Incident </a> </li> </ul> </div> <div id="info-Network Design Considerations for Security" ng-show="isSubSetForTR(1)" style="overflow:hidden;margin-top: 25px;"> <a name="anchor-tab-Network Design Considerations for Security" > </a> <div id="contentDiv"> <a href='https://sec.cloudapps.cisco.com/security/center/resources/framework_segmentation.html' class="erpUrl-show-format"> A Framework to Protect Data Through Segmentation </a> <br /> <a href='http://www.cisco.com/web/about/security/intelligence/security-for-ip-addr.html' class="erpUrl-show-format"> A Security-Oriented Approach to IP Addressing </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/firewall_best_practices' class="erpUrl-show-format"> Cisco Firewall Best Practices Guide </a> <br /> <a href='http://www.cisco.com/c/en/us/support/docs/security-vpn/secure-shell-ssh/4145-ssh.html' class="erpUrl-show-format"> Configuring Secure Shell on Routers and Switches Running Cisco IOS </a> <br /> <a href='https://cscrdr.cloudapps.cisco.com/cscrdr/security/center/files/intelligence/Linux_Hardening_Recommendations.pdf' class="erpUrl-show-format"> Linux Hardening Recommendations for Cisco Products </a> <br /> <a href='http://www.cisco.com/web/about/security/intelligence/securing-voip.html' class="erpUrl-show-format"> Securing Internet Telephony </a> <br /> <a href='http://www.cisco.com/en/US/tech/tk648/tk361/technologies_white_paper09186a00801a1a55.shtml' class="erpUrl-show-format"> Protecting Your Core: Infrastructure Protection Access Control Lists </a> <br /> <a href='http://www.cisco.com/web/about/security/intelligence/blackhole.pdf' class="erpUrl-show-format"> Remotely Triggered Black Hole Filtering - Destination Based and Source Based </a> <br /> <a href='http://www.cisco.com/web/about/security/intelligence/ipv6_rtbh.html' class="erpUrl-show-format"> Remotely Triggered Black Hole Filtering in IPv6 for Cisco IOS, Cisco IOS XE, and Cisco IOS XR Software </a> <br /> </div> </div> <div id="info-Running a Secure Network" ng-show="isSubSetForTR(2)" style="overflow:hidden;margin-top: 25px;"> <a name="anchor-tab-Running a Secure Network" > </a> <div id="contentDiv"> <a href='https://sec.cloudapps.cisco.com/security/center/resources/IOS_XE_hardening' class="erpUrl-show-format"> Cisco IOS XE Software Hardening Guide </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/securing_nx_os.html' class="erpUrl-show-format"> Cisco NX-OS Software Hardening Guide </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/iocs.html' class="erpUrl-show-format"> Cisco Security Indicators of Compromise Reference Guide </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/understanding-terminology.html' class="erpUrl-show-format"> Understanding Terminology in Cisco Security Advisories </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/ucs_hardening.html' class="erpUrl-show-format"> Cisco UCS Hardening Guide </a> <br /> <a href='http://www.cisco.com/en/US/tech/tk648/tk361/technologies_tech_note09186a0080120f48.shtml' class="erpUrl-show-format"> Cisco Guide to Harden Cisco IOS Devices </a> <br /> <a href='http://www.cisco.com/c/en/us/about/security-center/risk-triage-whitepaper.html' class="erpUrl-show-format"> Risk Triage and Prototyping in Information Security Engagements </a> <br /> <a href='http://www.cisco.com/web/about/security/intelligence/identify-incidents-via-syslog.html' class="erpUrl-show-format"> Identifying Incidents Using Firewall and IOS Router Syslog Events </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/network_integrity_monitoring.html' class="erpUrl-show-format"> Telemetry-Based Infrastructure Device Integrity Monitoring </a> <br /> <a href='http://www.cisco.com/web/about/security/intelligence/identification-ios.html' class="erpUrl-show-format"> Identifying the Effectiveness of Security Mitigations Using Cisco IOS Software </a> <br /> </div> </div> <div id="info-Responding to a Security Incident" ng-show="isSubSetForTR(3)" style="overflow:hidden;margin-top: 25px;"> <a name="anchor-tab-Responding to a Security Incident" > </a> <div id="contentDiv"> <a href='https://sec.cloudapps.cisco.com/security/center/resources/forensic_guides/fmc_forensic_investigation.html' class="erpUrl-show-format"> Assessing the Integrity of Cisco Firepower Management Center Software </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/ir_escalation_guidance' class="erpUrl-show-format"> Incident Response Escalation Guidance </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/forensic_guides/asa_forensic_investigation.html' class="erpUrl-show-format"> Cisco ASA Forensic Investigation Procedures for First Responders </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/forensic_guides/firepower1000_2100_forensic_investigation.html' class="erpUrl-show-format"> Cisco Firepower 1000/2100 Series Forensic Data Collection Procedures </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/forensic_guides/firepower2100_forensic_investigation.html' class="erpUrl-show-format"> Cisco Firepower 2100 Series Forensic Data Collection Procedures </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/forensic_guides/firepower4100_9300_forensic_investigation.html' class="erpUrl-show-format"> Cisco Firepower 4100/9300 Series Appliances Forensic Data Collection Procedures </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/forensic_guides/ftd_forensic_investigation.html' class="erpUrl-show-format"> Cisco Firepower Threat Defense Forensic Data Collection Procedures </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/forensic_guides/iosaccesspoint_forensic_investigation' class="erpUrl-show-format"> Cisco IOS Access Point Software Forensic Data Collection Procedures </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/forensic_guides/ios_forensic_investigation.html' class="erpUrl-show-format"> Cisco IOS Software Forensic Data Collection Procedures </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/forensic_guides/iosxe_forensic_guide.html' class="erpUrl-show-format"> Cisco IOS XE Software Forensic Data Collection Procedures </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/forensic_guides/ios_xr_forensic_investigation.html' class="erpUrl-show-format"> Cisco IOS XR Software Forensic Data Collection Procedures </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/forensic_guides/nx-os_forensic_investigation.html' class="erpUrl-show-format"> Cisco NX-OS Software Forensic Data Collection Procedures </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/forensic_guides/staros_forensic_investigation.html' class="erpUrl-show-format"> Cisco StarOS Software Forensic Data Collection Procedures </a> <br /> <a href='http://www.cisco.com/c/en/us/about/security-center/vulnerability-risk-triage.html' class="erpUrl-show-format"> Risk Triage for Security Vulnerability Announcements </a> <br /> <a href='http://www.cisco.com/web/about/security/intelligence/Integrity_Verification_Services_AAG.pdf' class="erpUrl-show-format"> Cisco Integrity Verification Services </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/integrity_assurance.html' class="erpUrl-show-format"> Cisco IOS Software Integrity Assurance </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/ios_xe_integrity_assurance.html' class="erpUrl-show-format"> Cisco IOS XE Software Integrity Assurance </a> <br /> <a href='https://sec.cloudapps.cisco.com/security/center/resources/asa_integrity_assurance.html' class="erpUrl-show-format"> ASA Integrity Assurance </a> <br /> </div> </div> </div> </div> </div> <div class="main-section-bottom"> <div class="bottom-content"> <h3>Tools</h3> <ul> <li><a href="/security/center/softwarechecker.x">Cisco Software Checker</a></li> <li><a href="/security/center/cvr">Cisco Vulnerability Repository</a></li> <li><a href="https://bst.cloudapps.cisco.com/bugsearch/">Bug Search</a></li> <li><a href="https://developer.cisco.com/psirt/">Cisco PSIRT openVuln API</a></li> <li><a href="/security/center/cvrfListing.x">CVRF Repository</a></li> <li><a href="https://community.cisco.com/t5/services-blogs/update-regarding-oval-definitions-by-cisco/ba-p/3661030">OVAL Repository</a></li> </ul> </div> <div class="bottom-content" > <h3>Actions</h3> <ul> <li><a href="https://software.cisco.com/download/home">Download Cisco Software</a></li> <li><a href="https://snort.org">Download Snort Rules</a></li> <li><a href="https://mycase.cloudapps.cisco.com/case">Open or Query a TAC Case</a></li> </ul> </div> <div class="bottom-content" > <h3>Related Links</h3> <ul> <li><a href="/security/center/erp.x?i=52">Cisco Event Responses</a></li> <li><a href="/security/center/securityResources.x">Cisco Policies and Processes</a></li> <li><a href="https://blogs.cisco.com/security">Cisco Security Blog</a></li> <li><a href="https://www.cisco.com/site/us/en/products/security/index.html">Security Solutions</a></li> </ul> </div> </div> </div> </cdc-template> <!-- GDPR cookie integration --> <script type="text/javascript" src="//www.cisco.com/c/dam/cdc/t/ctm.js"></script> </body> </html>