index_123
UNCLASSIFIED
Implementing Security on Cisco Routers
Version 1.0g
UNCLASSIFIED
123
Central> show version
IOS(tm) 3600 Software (C3640-I-M), Version 11.3(4)T1, RELEASE (fc1)
Copyright (c) 1986-1998 by cisco Systems, Inc.
.
.
System image file is "flash:c3640-i-mz.113-4.T1", booted via flash
cisco 3640 (R4700) processor with 28672K/4096K bytes of memory.
.
.
8192K bytes of processor board System flash (Read/Write)
.
.
Central>
The underlined portions of the transcript are the software version, router model,
RAM size, and flash memory size, respectively. To compute the total RAM on the
router, simply add the two parts of the RAM size rating: this router has 32MB of
RAM. It is important to know the router model and memory sizes before attempting
to obtain a software upgrade.
Motivations for Updating Router Software
Installing an IOS update entails inconvenience and the risk of disruption of service.
Weigh the benefits of upgrading against the risks before you start. The list below
describes some good reasons for installing an update.
1. To fix known vulnerabilities -
when security vulnerabilities are found in Cisco IOS products, one
solution may be to upgrade to a later edition of the IOS software.
2. To support new features
Cisco has added new operational and security features to each new IOS
release. If you need one or more of these features to support your
network, or to enforce your local security policy, then it makes sense to
upgrade.
3. To improve performance
you might need an upgrade to support new hardware or hardware
features. If the performance benefit is greater than the cost of upgrading,
then do the upgrade.
Software updates entail substantial costs. First, the router must be out of service for
at least a short time during the installation process; depending on router model and
other factors, the minimum downtime will range from about a minute to several
minutes. Second, some features may not work in a newer release; they might be
broken or simply unsupported. It is very important to read the release notes for a new
release carefully before installing it, to ensure that the new software can fully support
the router functions your network needs. Third, a new release may degrade
performance, either by implementing new features or by reducing available free
memory. If the performance of your router is critical, then measure the performance