Skip to main content

Hardening Network Infrastructure

Code: TBD · Credits: 4 · Hours: 60 · Type: ELECTIVE

The default configuration of a router, switch, or wireless controller is rarely the safe one. This elective covers concrete, vendor-aware hardening practices for the device, management plane, control plane, and routing fabric — and how to keep that hardening from drifting over time.

Key topics

  • Device baselines: AAA, RBAC, banners, NTP, syslog, hardware integrity.
  • Management plane: out-of-band, secure protocols (SSHv2, NETCONF over TLS, gNMI).
  • Control-plane policing, CoPP, BGP TTL security, RPKI / ROAs.
  • Segmentation: VRFs, VLAN design, microsegmentation, zero-trust networking.
  • Configuration audit (Cisco SAFE, CIS Benchmarks), drift detection, NCM tooling.
  • Wireless hardening: rogue detection, RF planning, controller security.
  • Resilience: hardware redundancy, BFD, graceful restart, evacuation drills.

Learning outcomes

By the end of this subject, a student should be able to:

  • Apply a CIS Benchmark or vendor baseline and produce an evidence audit.
  • Diagnose and remediate a control-plane DoS condition.
  • Roll out RPKI ROAs for a small ISP / enterprise prefix portfolio.
  • Build a configuration-drift detection workflow that scales beyond 50 devices.

Further reading

  • CIS Benchmarks (Cisco IOS, Junos, Arista EOS).
  • NSA / CISA, Network Infrastructure Security Guide (2022).
  • Cisco SAFE Reference Guide.
  • RFC 7454, BGP Operations and Security.

Chapter notes

Detailed chapter-by-chapter notes for this subject are still being written. The topic outline above mirrors the published syllabus. If you'd like to help draft a chapter, see the contributing guide.

· min read