Hardening Network Infrastructure
Code: TBD · Credits: 4 · Hours: 60 · Type: ELECTIVE
The default configuration of a router, switch, or wireless controller is rarely the safe one. This elective covers concrete, vendor-aware hardening practices for the device, management plane, control plane, and routing fabric — and how to keep that hardening from drifting over time.
Key topics
- Device baselines: AAA, RBAC, banners, NTP, syslog, hardware integrity.
- Management plane: out-of-band, secure protocols (SSHv2, NETCONF over TLS, gNMI).
- Control-plane policing, CoPP, BGP TTL security, RPKI / ROAs.
- Segmentation: VRFs, VLAN design, microsegmentation, zero-trust networking.
- Configuration audit (Cisco SAFE, CIS Benchmarks), drift detection, NCM tooling.
- Wireless hardening: rogue detection, RF planning, controller security.
- Resilience: hardware redundancy, BFD, graceful restart, evacuation drills.
Learning outcomes
By the end of this subject, a student should be able to:
- Apply a CIS Benchmark or vendor baseline and produce an evidence audit.
- Diagnose and remediate a control-plane DoS condition.
- Roll out RPKI ROAs for a small ISP / enterprise prefix portfolio.
- Build a configuration-drift detection workflow that scales beyond 50 devices.
Further reading
- CIS Benchmarks (Cisco IOS, Junos, Arista EOS).
- NSA / CISA, Network Infrastructure Security Guide (2022).
- Cisco SAFE Reference Guide.
- RFC 7454, BGP Operations and Security.
Chapter notes
Detailed chapter-by-chapter notes for this subject are still being written. The topic outline above mirrors the published syllabus. If you'd like to help draft a chapter, see the contributing guide.
· min read