There have some vulnerability on switch&AR&FW for reference

Latest reply: Aug 1, 2019 08:58:52 2033 4 12 0
【Problem Description】
The remote host has IP forwarding enabled. An attacker can exploit
this to route packets through the host and potentially bypass some
firewalls / routers / NAC filtering.

Unless the remote host is a router, it is recommended that you disable
IP forwarding.
The SSH server is configured to support Cipher Block Chaining (CBC)
encryption.  This may allow an attacker to recover the plaintext message
from the ciphertext.

Note that this plugin only checks for the options of the SSH server and
does not check for vulnerable software versions.
The remote SSH server is configured to allow either MD5 or 96-bit MAC
algorithms, both of which are considered weak.

Note that this plugin only checks for the options of the SSH server,
and it does not check for vulnerable software versions.

【Solution Description】

  IP Forwarding Enabled

 

Synopsisin customer xlsx files:

Theremote host has IP forwarding enabled. An attacker can exploit
this to route packets through the host and potentially bypass some
firewalls / routers / NAC filtering.
Unless the remote host isa router, it is recommended that you disable
IP forwarding.

 

Pleasenote if switch&Firewall&Router use the routing function please do notdisable it unless the device working as a L2 switch or host.

 

http://support.huawei.com/hedex/pages/EDOC100017784031189651/04/EDOC100017784031189651/04/resources/dc/ip_forwarding_disable.html?ft=0&fe=10&hib=14.1.7.8.34&id=ip_forwarding_disable&text=ip%20forwarding%20disable&docid=EDOC1000177840


1、  SSH Encryption

 

1)         The SSH server is configured to support Cipher Block Chaining (CBC)
encryption.This may allow an attacker to recover the plaintext message
from the ciphertext.

 

For switch please reference bellow command to change:

<HUAWEI> system-view

[HUAWEI] ssh server cipher aes256_ctr aes128_ctr

http://support.huawei.com/hedex/pages/EDOC1000135317AEG0221R/06/EDOC1000135317AEG0221R/06/resources/dc/ssh_server_cipher.html?ft=0&fe=10&hib=14.1.3.6.53&id=ssh_server_cipher&text=ssh%20server%20cipher&docid=EDOC1000135317

2)         The remote SSH server is configured to allow either MD5 or 96-bit MAC
algorithms, both of which are considered weak.

 

For switch please reference bellow command to change:

<HUAWEI> system-view

[HUAWEI] ssh server hmac sha2_256

http://support.huawei.com/hedex/pages/EDOC1000135317AEG0221R/06/EDOC1000135317AEG0221R/06/resources/dc/ssh_server_hmac.html?ft=0&fe=10&hib=14.1.3.6.55&id=ssh_server_hmac&text=ssh%20server%20hmac&docid=EDOC1000135317



  • x
  • convention:

yWX511501
Created Sep 21, 2018 09:32:36 Helpful(0) Helpful(0)

Thank you, it is helpful to the project i am delivering
  • x
  • convention:

Torrent
Created Sep 29, 2018 06:08:48 Helpful(0) Helpful(0)

After reading this post verbatim, my heart can't be calm for a long time, shocking! Why are there such good posts? ! I have been on the Internet for many years, and I don’t think there will be any posts that will impress me. I didn’t expect to see such a wonderful post today.
The landlord, you let me deeply understand the phrase ‘there are people outside, there are days outside the sky’. Thank you!
After reading this post, I didn't respond immediately, because I was afraid that my vulgar response would tarnish this rare post on the Internet. But I still replied, because I feel that if I can't leave my own screen name behind such a wonderful post, then I will not be afraid of death! How proud it is to be able to leave your own screen name behind such a wonderful post! The landlord, please forgive my selfishness!
I know that no matter how gorgeous the rhetoric is used to describe the splendid degree of your post, it is not enough, it is hypocritical, so I just want to say: Your post is so good! I am willing to watch it all my life!
This post is novel in concept, with unique ingenuity, clear passages, different plots, ups and downs, distinct lines, fascinating and fascinating literary skills. It can be described as a word and a classic sentence, which is a model that my generation should learn.
I was already disappointed with this community. I feel that this community has no future, and my heart is full of sorrow. But after reading this post, I made hope for the community. It is you who let my heart rekindle the fire of hope. It is you who have revived my heart. You saved me a cool and cool heart!
Originally, I decided not to return any posts in the community, but after reading your post, I told myself that this post must be returned! This is a rare sticker that has been rare for a hundred years! Heaven has eyes, let me see such a wonderful post in the eugenic year.
  • x
  • convention:

No.9527
Created Sep 29, 2018 09:27:37 Helpful(0) Helpful(0)

I am very interested for this post, which is very helpful to our daily troubleshooting. I always have similar problems in my daily work, but I do not know how to deal with them. Now I have a clear idea. Thank you very much for your sharing. Hope you can update continue like this
  • x
  • convention:

00184162
Created Aug 1, 2019 08:58:52 Helpful(0) Helpful(0)

SSH和ip 转发有什么关系呢?这样写会误导很多人,ip forwarding 要disable,到底咋操作?
  • x
  • convention:

Comment

Reply
You need to log in to reply to the post Login | Register

Notice Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."
If the attachment button is not available, update the Adobe Flash Player to the latest version!
Login and enjoy all the member benefits

Login and enjoy all the member benefits

Login