等保测评命令——思科(Cisco)网络设备

admin 2026-09-30 04:55:55 网络安全文章 来源:ZONE.CI 全球网 0 阅读模式

文章总结: 本文整理了思科网络设备在等保测评中的常用检查命令,覆盖身份鉴别、访问控制、安全审计等7个安全控制点。每条命令均包含达标判据与整改建议,并附有一键巡检脚本与高风险核查清单,帮助测评人员高效完成测评工作。文档依据GB/T22239-2019和GB/T28448-2019标准,但强调不同厂商产品版本存在差异,实际测评需以标准原文及测评机构要求为准。 综合评分: 85 文章分类: 安全建设,技术标准,安全工具


等保测评命令——思科(Cisco)网络设备

北京路劲科技有限公司

2026年9月29日 18:45 北京

在小说阅读器读本章

去阅读

在公众号小说中沉浸阅读

本文整理了思科(Cisco)网络设备在等保测评中的常用检查命令,覆盖身份鉴别、访问控制、安全审计、入侵防范、恶意代码防范、可信验证、数据备份与恢复等7个安全控制点。每条命令均包含达标判据与整改建议,并附有一键巡检脚本与高风险核查清单,帮助测评人员高效完成测评工作。

⚠️ 免责声明:本文命令整理依据 GB/T 22239-2019、GB/T 28448-2019 标准,但不同厂商产品版本、配置方式存在差异。文中命令仅供参考,实际测评请以标准原文及测评机构要求为准。执行命令前请确认权限与环境,避免因操作失误导致业务中断。

一、身份鉴别

对应条款 8.1.4.1 / 8.1.2.4

1.1 账户唯一性与密码策略

本地用户账户

show running-config | section username

✓ 达标判据 无冗余/测试账户,每个账户均绑定明确角色

启用密码配置

show running-config | include enable secret

✓ 达标判据 已配置 enable secret(而非明文 enable password)

密码加密

show running-config | include service password-encryption

✓ 达标判据 已启用 service password-encryption,建议配合 AES 加密

密码复杂度策略

show running-config | include password-policy

✓ 达标判据 已启用密码复杂度(小写+大写+数字+特殊字符)

密码历史

show running-config | include password-history

✓ 达标判据 已配置密码历史记忆,避免重复使用旧密码

用户角色

show running-config | section username

✓ 达标判据 按最小权限分配角色(如 view/audit/admin/config)

▸ Cisco IOS/IOS-XE 设备特有配置

# 查看用户名及角色分配show running-config | section username
# 查看启用密码(应为MD5/AES加密显示)show running-config | include enable secret
# 查看密码加密设置show running-config | include service password-encryption show running-config | include password-encryption-algorithm
# 查看密码策略(复杂度、长度、有效期)show running-config | include password-policy show running-config | include password-history show running-config | include username

1.2 登录失败处理与会话超时

VTY线路超时

show line vty

✓ 达标判据 超时时间 ≤ 10分钟(默认600秒)

Console线路超时

show line console

✓ 达标判据 超时时间 ≤ 10分钟

SSH会话超时

show ssh

✓ 达标判据 SSH会话超时已配置,且空闲连接自动断开

登录失败锁定

show running-config | include login failure

✓ 达标判据 已配置登录失败锁定(配合AAA认证)

▸ Cisco IOS/IOS-XE 设备特有配置

# 查看VTY线路超时配置
show line vty
# 查看Console线路配置
show line console
# 查看全局超时设置
show running-config | include session-timeout show running-config | include login timeout
# 查看AAA认证配置(失败处理)
show running-config | include authentication
# 查看当前活跃会话
show users
# 查看线路状态
show line

1.3 远程管理安全

# 查看SSH服务状态及版本
show ip ssh
# 查看SSH详细配置
show ssh
# 查看SSH密钥信息
show crypto key mypubkey rsa
# 查看Telnet服务状态(应关闭,使用VTY线路禁用)
show running-config | include vty show running-config | section line vty
# 查看HTTP/HTTPS服务(应关闭HTTP,仅保留HTTPS)
show running-config | include ip http show running-config | include http
# 查看SNMP服务(版本及团体字)
show running-config | include snmp-server show snmp-server community show running-config | include snmp-server group
# 查看FTP/TFTP服务
show running-config | include ftp show running-config | include tftp
# 查看当前监听端口
show ip tcp | include LISTEN show tcp brief
# 查看高危服务是否关闭
show running-config | include server enable show running-config | include telnet show running-config | include http

高风险项:Telnet开启(未配置SSH)、SNMP v1/v2c使用默认团体字(public/private)、HTTP明文管理开启、FTP/TFTP明文传输开启,直接判定不符合三级要求。

1.4 双因子认证(高风险项)

测评方法:访谈确认是否采用组合认证技术(如”本地口令 + AAA(RADIUS/TACACS+)/证书认证”)。

▸ 核查命令

# 查看AAA全局配置及认证方案
show aaa show running-config | section aaa
# 查看RADIUS服务器配置
show running-config | include radius-server
# 查看TACACS+服务器配置
show running-config | include tacacs-server
# 查看LDAP认证配置
show running-config | include ldap
# 查看PKI/证书配置(用于802.1X或AAA认证)
show running-config | include crypto pki show crypto pki certificate chain show crypto pki trustpoint
# 查看802.1X认证(接入层端口)
show running-config | include dot1x show dot1x detail show running-config | include 802.1x
# 查看用户认证方法列表
show running-config | include authentication login

二、访问控制

对应条款 8.1.4.2 / 8.1.2.2

2.1 权限管理与角色分离

用户角色分配

show running-config | section username

✓ 达标判据 按运维/审计/配置划分角色,非管理员禁止执行高权限命令

命令级别控制

show running-config | include privilege

✓ 达标判据 关键命令(如configure/reload)授权到L3以上

授权控制

show running-config | include authorization

✓ 达标判据 已启用命令授权,关键操作需二次授权

操作日志

show running-config | include logging host

✓ 达标判据 配置变更操作记录到审计日志

▸ Cisco IOS/IOS-XE 设备特有配置

# 查看用户角色及命令授权
show running-config | section username show running-config | include privilege
# 查看授权策略show running-config | include authorization show running-config | section authorization
# 查看操作日志(配置变更)
show logging | include config show running-config | include archive
# 查看当前会话及权限级别
show users show privilege

2.2 ACL与流量控制

# 查看所有ACL规则
show ip access-list show ip access-list all
# 查看ACL应用在接口情况
show ip access-list summary show running-config | include ip access-group
# 查看接口访问控制
show running-config | section interface show running-config | include access-group
# 查看管理口ACL(限制管理源IP)
show running-control-plane show running-config | include line vty
# 查看VLAN访问控制
show running-config | include vlan show vlan brief
# 查看端口隔离
show running-config | include port-security show port-security show port-security interface
# 查看DHCP Snooping绑定表
show ip dhcp snooping show ip dhcp snooping binding
# 查看IP Source Guard绑定
show ip source bind show running-config | include ip verify source
# 查看动态ARP检测(DAI)
show ip arp inspection show ip arp inspection interface show ip arp inspection statistics
# 查看ND Snooping(IPv6)
show ip nd snooping show ip nd snooping interface show ip nd snooping statistics

三、安全审计

对应条款 8.1.4.3 / 8.1.2.5

3.1 日志服务配置

日志输出(logging)

show running-config | include logging

✓ 达标判据 已启用日志记录(logging buffered / logging console)

日志主机(Syslog)

show running-config | include syslog 或 show logging host

✓ 达标判据 日志外发至远程Syslog服务器

日志级别

show logging

✓ 达标判据 记录信息级别(informational)及以上

日志缓冲

show running-config | include logging buffered

✓ 达标判据 缓冲区保留最近日志,大小适当

配置日志

show running-config | include logging on

✓ 达标判据 配置变更操作被记录到日志

安全日志

show running-config | include logging trap

✓ 达标判据 安全事件(登录失败、攻击等)触发Trap

▸ Cisco IOS/IOS-XE 设备特有配置

# 查看信息中心全局配置
show running-config | include logging show running-config | include logging on
# 查看日志主机(Syslog服务器)配置
show logging host show running-config | include syslog
# 查看日志输出通道及级别
show logging show logging | include facility
# 查看日志缓冲区内容(最近100条)
show log show log | last 100
# 查看Trap告警缓冲区
show logging | include trap
# 查看日志过滤规则
show running-config | include logging filter show running-config | include logging exception

3.2 日志管理与保护

# 查看NTP时间同步(确保日志时间准确)
show ntp status show ntp associations show running-config | include ntp
# 查看日志时间戳配置
show running-config | include timestamp
# 查看调试日志(应关闭)
show running-config | include debug show running-config | include debugging
# 查看安全日志(安全认证/攻击事件)
show logging | include security show logging | include authentication show logging | include ssh
# 查看攻击防范日志
show logging | include attack show logging | include ip unreach show logging | include syslog-connection
# 查看日志保留策略(如支持)
show running-config | include archive log show archive config

四、入侵防范

对应条款 8.1.4.4 / 8.1.2.3

4.1 服务最小化与端口管理

高危端口

show ip tcp | include LISTEN

✓ 达标判据 无Telnet/FTP/TFTP端口监听,仅SSH(22)/HTTPS(443)

服务状态

show running-config | include server enable

✓ 达标判据 仅开启必要服务,HTTP/Telnet/FTP均已关闭

固件版本

show version

✓ 达标判据 为官方最新稳定版本,已修补已知漏洞

未使用端口

show interface status

✓ 达标判据 未使用的端口已shutdown

▸ Cisco IOS/IOS-XE 设备特有配置

# 查看设备版本及补丁
show version show archive config show running-config | include image
# 查看所有已开启服务
show running-config | include server enable show running-config | include telnet show running-config | include http show running-config | include ftp
# 查看TCP/UDP监听端口
show ip tcp | include LISTEN show tcp brief show udp brief
# 查看接口下未使用的端口(应shutdown)
show interface status show interface brief
# 查看环路保护(STP)
show spanning-tree show spanning-tree summary show running-config | include spanning-tree
# 查看LLDP/CDP邻居(排查未授权接入)
show cdp neighbors show lldp neighbors show cdp table

4.2 网络攻击防范

# 查看URPF配置(单播反向路径转发)
show running-config | include ip verify source show running-config | include urpf
# 查看TCP拦截/连接限制
show running-config | include tcp intercept show running-config | include tcp max-syn
# 查看ICMP重定向
show running-config | include icmp redirect
# 查看Smurf/Land/Fraggle攻击防范
show running-config | include smurf show running-config | include fragment show running-config | include tcp
# 查看ARP攻击防范(DAI/DHCP Snooping)
show ip arp inspection show ip dhcp snooping
# 查看ND攻击防范(IPv6)
show ip nd snooping
# 查看DHCP仿冒防范
show ip dhcp snooping show ip dhcp snooping binding
# 查看BPDU保护(防私接交换机)
show spanning-tree bpduguard show running-config | include bpduguard
# 查看端口安全(MAC地址绑定)
show port-security show port-security interface
# 查看CPU防护
show control-plane show running-config | include control-plane show running-config | include service-policer
# 查看广播/组播/未知单播风暴抑制
show running-config | include storm-control show storm-control

五、恶意代码防范

对应条款 8.1.4.5

Cisco IOS/IOS-XE 设备通常无传统杀毒软件,重点检查固件及配置完整性:

固件完整性

show version

✓ 达标判据 IOS版本与官方发布一致,未使用第三方固件

配置一致性

show configuration differences

✓ 达标判据 当前运行配置与保存配置一致

配置备份

show startup-config

✓ 达标判据 启动配置存在且完整

▸ Cisco IOS/IOS-XE 设备特有配置

# 查看当前运行配置
show running-config
# 查看保存配置(下次启动配置)
show startup-config
# 对比当前配置与保存配置是否一致
show configuration differences
# 查看启动文件及存储
show boot show flash dir flash:
# 查看配置文件校验(如支持)
show md5sum flash: show crypto hash md5
# 查看License及功能授权
show license status show license
# 查看系统补丁及版本签名
show version | include "IOS" show archive config

六、可信验证

对应条款 8.1.4.6 · 网络设备可选

启动文件校验

show boot

✓ 达标判据 启动文件完整,启动顺序合理

配置归档

show archive config

✓ 达标判据 配置变更可追溯,存在版本记录

固件签名

show version

✓ 达标判据 官方发布版本,未使用非官方固件

安全密钥

show crypto key mypubkey rsa

✓ 达标判据 存在有效的加密密钥对

▸ Cisco IOS/IOS-XE 设备特有配置

# 查看启动文件路径及名称
show boot
# 查看BootROM版本
show version | include "Boot"
# 查看系统软件版本及补丁
show version show archive config
# 查看安全密钥(RSA/DSA)
show crypto key mypubkey rsa show crypto key mypubkey dsa show running-config | include crypto key
# 查看配置回滚点
show archive config
# 查看系统健康状态
show processes cpu show processes memory show environment show controllers

七、数据备份与恢复

对应条款 8.1.4.9

配置备份

show startup-config

✓ 达标判据 配置已保存(startup-config存在)

自动备份

show running-config | include archive

✓ 达标判据 存在自动归档配置

启动文件备份

show boot

✓ 达标判据 主备启动文件均存在

▸ Cisco IOS/IOS-XE 设备特有配置

# 查看启动配置文件
show boot show running-config | include boot
# 查看配置自动备份
show running-config | include archive show archive config
# 查看TFTP/FTP/SFTP备份配置
show running-config | include tftp show running-config | include ftp show running-config | include sftp
# 查看NQA/Track/BFD等可靠性配置
show running-config | include track show running-config | include bfd
# 查看VRRP/HSRP热备
show running-config | include hsrp show running-config | include vrrp show hsrp show vrrp
# 查看链路聚合及冗余
show etherchannel summary show etherchannel port-channel show running-config | include channel-group
# 查看设备堆叠/IRF状态(如支持)
show stack show switch show stack-state

一键巡检脚本(Cisco IOS/IOS-XE 设备)

CISCO

===== 1 身份鉴别 =====
show running-config | section username show running-config | include enable secret show running-config | include service password-encryption show running-config | include password-policy show running-config | include password-history show users show line vty show line console show running-config | include authentication show running-config | include radius-server show running-config | include tacacs-server show running-config | include ldap show running-config | include dot1x
===== 2 访问控制 =====
show ip access-list all show running-control-plane show running-config | include access-group show running-config | include port-security show port-security show ip dhcp snooping show ip dhcp snooping binding show ip source bind show ip arp inspection
===== 3 安全审计 =====
show logging show logging host show running-config | include logging show running-config | include syslog show log | last 50 show ntp status show ntp associations show running-config | include debug
===== 4 入侵防范 =====
show version show running-config | include server enable show ip tcp | include LISTEN show interface status show spanning-tree summary show running-config | include urpf show running-config | include tcp intercept show running-config | include bpduguard show port-security interface show control-plane show running-config | include storm-control
===== 5 恶意代码防范 =====
show running-config show startup-config show configuration differences show boot dir flash:
===== 6 可信验证 =====
show boot show version show archive config show crypto key mypubkey rsa show processes cpu show processes memory show environment
===== 7 数据备份 =====
show startup-config show running-config | include archive show archive config show boot show running-config | include hsrp show running-config | include vrrp show etherchannel summary show stack
===== 8 Cisco特有 =====
show running-config | include ip http show running-config | include ip ssh show running-config | include snmp-server show running-config | include crypto pki show running-config | include license

高风险项重点核查清单

01Telnet服务开启

验证命令  show running-config | section line vty

不合规判定  VTY线路未禁用Telnet或未配置SSH

整改建议  line vty 0 15 → transport input ssh → exit

02SNMP使用默认团体字

验证命令  show snmp-server community

不合规判定  团体字为 public 或 private

整改建议  no snmp-server community public RO → 使用 snmp-server group

03HTTP明文管理开启

验证命令  show running-config | include ip http

不合规判定  ip http server 已启用

整改建议  no ip http server → ip http secure-server

04无密码复杂度策略

验证命令  show running-config | include password-policy

不合规判定  未配置密码复杂度、长度、有效期

整改建议  配置 password-policy + username 策略

05无日志外发

验证命令  show logging host

不合规判定  日志未外发至远程Syslog服务器

整改建议  logging host

06无NTP时间同步

验证命令  show ntp status

不合规判定  未配置NTP服务器,时间不同步

整改建议  ntp server

07高危服务开启(FTP/TFTP)

验证命令  show running-config | include ftp

不合规判定  FTP/TFTP服务开启

整改建议  no ip ftp → 如需文件传输,配置SFTP

08未保存配置

验证命令  show configuration differences

不合规判定  运行配置与保存配置不一致

整改建议  copy running-config startup-config

09STP未启用

验证命令  show spanning-tree summary

不合规判定  STP全局未启用,存在环路风险

整改建议  spanning-tree mode rapid-pvst

10端口安全未启用

验证命令  show port-security

不合规判定  接入端口未启用端口安全

整改建议  interface → port-security

11调试模式开启

验证命令  show running-config | include debug

不合规判定  存在 debug all 或类似命令

整改建议  undebug all

12未使用SHA2密钥

验证命令  show crypto key mypubkey rsa

不合规判定  SSH密钥位数不足(<2048位)

整改建议  crypto key generate rsa general-purpose modulus 2048

13密码未加密

验证命令  show running-config | include service password-encryption

不合规判定  未启用 service password-encryption

整改建议  service password-encryption

14未关闭HTTP服务器

验证命令  show running-config | include ip http

不合规判定  ip http server 未禁用

整改建议  no ip http server

15登录无超时

验证命令  show line vty

不合规判定  VTY超时时间 > 10分钟

整改建议  line vty 0 15 → exec-timeout 10 0

Cisco IOS/IOS-XE 设备 vs 标准Linux服务器对比

| 对比项 | 标准Linux服务器 | Cisco IOS/IOS-XE 设备 | | — | — | — | | 操作系统/内核 | Linux内核 | Cisco IOS/IOS-XE | | 命令行类型 | bash/shell | Cisco IOS CLI(show命令体系) | | 用户管理 | /etc/passwd、useradd、PAM | username 、AAA框架 | | 密码策略 | PAM模块(pam_pwquality) | password-policy(内置) | | 访问控制 | iptables/SELinux | 标准ACL(Standard/Extended) | | 日志管理 | syslog/rsyslog/journald | logging/show log | | 远程管理 | SSH/SSH端口22 | SSH(ip ssh)/SSH端口22 | | 固件更新 | apt/yum/dnf | copy tftp flash: / 自动升级 | | 等保重点 | 主机安全策略 | 网络设备安全策略(CLI命令) |

测评执行要点

  1. 权限要求

• 需具备 Privileged EXEC Mode(enable模式) 权限执行 show 命令

• 查看 show running-config 需要 L1(enabled)权限

• 部分命令(如 show privilege)仅需 L0(用户模式)即可执行

• 进入 enable 模式:enable

  1. 现场核查重点

• 管理面暴露:核查是否仅通过SSH访问,VTY线路是否已禁用Telnet

• SNMP安全:核查是否使用v3且启用认证加密,v1/v2c是否已禁用

• 配置一致性:核查 show running-config 与 show startup-config 是否一致

• 固件版本:核查是否为官方最新补丁版本,是否存在已知CVE漏洞

• 日志完整性:核查日志是否外发至集中日志服务器,NTP是否已同步

• 密码策略:核查 enable secret 是否使用加密,service password-encryption 是否启用

  1. 不同产品差异

• IOS vs IOS-XE:IOS-XE 支持更多高级特性(如 show archive、ip verify source、control-plane);IOS 设备部分命令不支持

• 交换机 vs 路由器:交换机使用 show etherchannel、show port-security、show spanning-tree;路由器使用 show ip route、show ip ospf

• IOS vs NX-OS:Cisco NX-OS(用于ACI/Nexus)命令略有差异,如 show feature、show interface brief 等

常用命令速查

系统信息

show version  # 版本信息

show interfaces status  # 接口状态

show environment  # 环境监控(风扇/电源/温度)

show processes cpu  # CPU使用率

show processes memory  # 内存使用率

show clock  # 系统时间

网络状态

show interfaces brief  # 接口状态概览

show ip interface brief  # IP接口状态

show ip route  # 路由表

show arp  # ARP表

show mac address-table  # MAC地址表

show ip tcp  # TCP连接

show udp  # UDP连接

show running-config  # 当前运行配置

安全配置

show running-config  # 当前运行配置

show startup-config  # 保存配置

show ip access-list  # ACL规则

show running-config | include password-policy  # 密码策略

show ip ssh  # SSH状态

show running-config | include snmp-server  # SNMP配置

show running-config | include authentication  # AAA认证

日志审计

show log  # 日志缓冲区

show logging host  # 日志主机

show logging  # 日志通道及级别

show ntp status  # NTP状态

show ntp associations  # NTP会话

可靠性

show spanning-tree  # 生成树

show vrrp  # VRRP热备

show hsrp  # HSRP热备

show etherchannel summary  # 链路聚合

show ntp status  # NTP状态

show archive config  # 配置归档

参考标准

| 标准编号 | 标准名称 | | — | — | | GB/T 22239-2019 | 《信息安全技术 网络安全等级保护基本要求》 | | GB/T 28448-2019 | 《信息安全技术 网络安全等级保护测评要求》 | | GB/T 25070-2019 | 《信息安全技术 网络安全等级保护安全设计技术要求》 |

关注路劲科技,关注网络安全!

END

关于我们:

北京路劲科技有限公司(Beijing Lujin Technology Co. , Ltd.)成立于2019年1月4日,是一家提供全面系统集成与信息安全解决方案的专业IT技术服务公司。公司秉承“为网络安全保驾护航”的企业愿景及“提升国家整体安全”的使命,依据风险评估模型和等级保护标准,采用大数据等技术手段,开展网络安全相关业务。公司致力于为各个行业的业务信息化提供软件和通用解决方案、系统架构,系统管理和数据安全服务、以及IT咨询规划、系统集成与系统服务等专业化服务。公司立足北京,走向全国,始终坚持“换位、细节、感恩”的核心价值观,以“共赢、共享、共成长”的经营理念为出发点,集合了一批敢于创新、充满活力、热衷于为IT行业服务的优秀人才,致力于成为您身边的网络安全专家。

关注路劲科技,关注网络安全!

公司:北京路劲科技有限公司

地址:北京市昌平区南邵镇双营西路78号院2号楼5层504


免责声明:

本文所载程序、技术方法仅面向合法合规的安全研究与教学场景,旨在提升网络安全防护能力,具有明确的技术研究属性。

任何单位或个人未经授权,将本文内容用于攻击、破坏等非法用途的,由此引发的全部法律责任、民事赔偿及连带责任,均由行为人独立承担,本站不承担任何连带责任。

本站内容均为技术交流与知识分享目的发布,若存在版权侵权或其他异议,请通过邮件联系处理,具体联系方式可点击页面上方的联系我。

本文转载自:北京路劲科技有限公司 《等保测评命令——思科(Cisco)网络设备》

智能座舱域控制器 网络安全文章

智能座舱域控制器

文章总结: 本文介绍了智能座舱域控制器的发展背景、构成、实质、硬件架构以及技术趋势,并探讨了相关名词和技术细节。智能座舱域控制器是实现汽车智能化的重要组成部分,
评论:0   参与:  0