文章总结: 本文整理了思科网络设备在等保测评中的常用检查命令,覆盖身份鉴别、访问控制、安全审计等7个安全控制点。每条命令均包含达标判据与整改建议,并附有一键巡检脚本与高风险核查清单,帮助测评人员高效完成测评工作。文档依据GB/T22239-2019和GB/T28448-2019标准,但强调不同厂商产品版本存在差异,实际测评需以标准原文及测评机构要求为准。 综合评分: 85 文章分类: 安全建设,技术标准,安全工具
等保测评命令——思科(Cisco)网络设备
北京路劲科技有限公司
2026年9月29日 18:45 北京
在小说阅读器读本章
去阅读
在公众号小说中沉浸阅读
本文整理了思科(Cisco)网络设备在等保测评中的常用检查命令,覆盖身份鉴别、访问控制、安全审计、入侵防范、恶意代码防范、可信验证、数据备份与恢复等7个安全控制点。每条命令均包含达标判据与整改建议,并附有一键巡检脚本与高风险核查清单,帮助测评人员高效完成测评工作。
⚠️ 免责声明:本文命令整理依据 GB/T 22239-2019、GB/T 28448-2019 标准,但不同厂商产品版本、配置方式存在差异。文中命令仅供参考,实际测评请以标准原文及测评机构要求为准。执行命令前请确认权限与环境,避免因操作失误导致业务中断。
一、身份鉴别
对应条款 8.1.4.1 / 8.1.2.4
1.1 账户唯一性与密码策略
本地用户账户
show running-config | section username
✓ 达标判据 无冗余/测试账户,每个账户均绑定明确角色
启用密码配置
show running-config | include enable secret
✓ 达标判据 已配置 enable secret(而非明文 enable password)
密码加密
show running-config | include service password-encryption
✓ 达标判据 已启用 service password-encryption,建议配合 AES 加密
密码复杂度策略
show running-config | include password-policy
✓ 达标判据 已启用密码复杂度(小写+大写+数字+特殊字符)
密码历史
show running-config | include password-history
✓ 达标判据 已配置密码历史记忆,避免重复使用旧密码
用户角色
show running-config | section username
✓ 达标判据 按最小权限分配角色(如 view/audit/admin/config)
▸ Cisco IOS/IOS-XE 设备特有配置
# 查看用户名及角色分配show running-config | section username
# 查看启用密码(应为MD5/AES加密显示)show running-config | include enable secret
# 查看密码加密设置show running-config | include service password-encryption show running-config | include password-encryption-algorithm
# 查看密码策略(复杂度、长度、有效期)show running-config | include password-policy show running-config | include password-history show running-config | include username
1.2 登录失败处理与会话超时
VTY线路超时
show line vty
✓ 达标判据 超时时间 ≤ 10分钟(默认600秒)
Console线路超时
show line console
✓ 达标判据 超时时间 ≤ 10分钟
SSH会话超时
show ssh
✓ 达标判据 SSH会话超时已配置,且空闲连接自动断开
登录失败锁定
show running-config | include login failure
✓ 达标判据 已配置登录失败锁定(配合AAA认证)
▸ Cisco IOS/IOS-XE 设备特有配置
# 查看VTY线路超时配置
show line vty
# 查看Console线路配置
show line console
# 查看全局超时设置
show running-config | include session-timeout show running-config | include login timeout
# 查看AAA认证配置(失败处理)
show running-config | include authentication
# 查看当前活跃会话
show users
# 查看线路状态
show line
1.3 远程管理安全
# 查看SSH服务状态及版本
show ip ssh
# 查看SSH详细配置
show ssh
# 查看SSH密钥信息
show crypto key mypubkey rsa
# 查看Telnet服务状态(应关闭,使用VTY线路禁用)
show running-config | include vty show running-config | section line vty
# 查看HTTP/HTTPS服务(应关闭HTTP,仅保留HTTPS)
show running-config | include ip http show running-config | include http
# 查看SNMP服务(版本及团体字)
show running-config | include snmp-server show snmp-server community show running-config | include snmp-server group
# 查看FTP/TFTP服务
show running-config | include ftp show running-config | include tftp
# 查看当前监听端口
show ip tcp | include LISTEN show tcp brief
# 查看高危服务是否关闭
show running-config | include server enable show running-config | include telnet show running-config | include http
高风险项:Telnet开启(未配置SSH)、SNMP v1/v2c使用默认团体字(public/private)、HTTP明文管理开启、FTP/TFTP明文传输开启,直接判定不符合三级要求。
1.4 双因子认证(高风险项)
测评方法:访谈确认是否采用组合认证技术(如”本地口令 + AAA(RADIUS/TACACS+)/证书认证”)。
▸ 核查命令
# 查看AAA全局配置及认证方案
show aaa show running-config | section aaa
# 查看RADIUS服务器配置
show running-config | include radius-server
# 查看TACACS+服务器配置
show running-config | include tacacs-server
# 查看LDAP认证配置
show running-config | include ldap
# 查看PKI/证书配置(用于802.1X或AAA认证)
show running-config | include crypto pki show crypto pki certificate chain show crypto pki trustpoint
# 查看802.1X认证(接入层端口)
show running-config | include dot1x show dot1x detail show running-config | include 802.1x
# 查看用户认证方法列表
show running-config | include authentication login
二、访问控制
对应条款 8.1.4.2 / 8.1.2.2
2.1 权限管理与角色分离
用户角色分配
show running-config | section username
✓ 达标判据 按运维/审计/配置划分角色,非管理员禁止执行高权限命令
命令级别控制
show running-config | include privilege
✓ 达标判据 关键命令(如configure/reload)授权到L3以上
授权控制
show running-config | include authorization
✓ 达标判据 已启用命令授权,关键操作需二次授权
操作日志
show running-config | include logging host
✓ 达标判据 配置变更操作记录到审计日志
▸ Cisco IOS/IOS-XE 设备特有配置
# 查看用户角色及命令授权
show running-config | section username show running-config | include privilege
# 查看授权策略show running-config | include authorization show running-config | section authorization
# 查看操作日志(配置变更)
show logging | include config show running-config | include archive
# 查看当前会话及权限级别
show users show privilege
2.2 ACL与流量控制
# 查看所有ACL规则
show ip access-list show ip access-list all
# 查看ACL应用在接口情况
show ip access-list summary show running-config | include ip access-group
# 查看接口访问控制
show running-config | section interface show running-config | include access-group
# 查看管理口ACL(限制管理源IP)
show running-control-plane show running-config | include line vty
# 查看VLAN访问控制
show running-config | include vlan show vlan brief
# 查看端口隔离
show running-config | include port-security show port-security show port-security interface
# 查看DHCP Snooping绑定表
show ip dhcp snooping show ip dhcp snooping binding
# 查看IP Source Guard绑定
show ip source bind show running-config | include ip verify source
# 查看动态ARP检测(DAI)
show ip arp inspection show ip arp inspection interface show ip arp inspection statistics
# 查看ND Snooping(IPv6)
show ip nd snooping show ip nd snooping interface show ip nd snooping statistics
三、安全审计
对应条款 8.1.4.3 / 8.1.2.5
3.1 日志服务配置
日志输出(logging)
show running-config | include logging
✓ 达标判据 已启用日志记录(logging buffered / logging console)
日志主机(Syslog)
show running-config | include syslog 或 show logging host
✓ 达标判据 日志外发至远程Syslog服务器
日志级别
show logging
✓ 达标判据 记录信息级别(informational)及以上
日志缓冲
show running-config | include logging buffered
✓ 达标判据 缓冲区保留最近日志,大小适当
配置日志
show running-config | include logging on
✓ 达标判据 配置变更操作被记录到日志
安全日志
show running-config | include logging trap
✓ 达标判据 安全事件(登录失败、攻击等)触发Trap
▸ Cisco IOS/IOS-XE 设备特有配置
# 查看信息中心全局配置
show running-config | include logging show running-config | include logging on
# 查看日志主机(Syslog服务器)配置
show logging host show running-config | include syslog
# 查看日志输出通道及级别
show logging show logging | include facility
# 查看日志缓冲区内容(最近100条)
show log show log | last 100
# 查看Trap告警缓冲区
show logging | include trap
# 查看日志过滤规则
show running-config | include logging filter show running-config | include logging exception
3.2 日志管理与保护
# 查看NTP时间同步(确保日志时间准确)
show ntp status show ntp associations show running-config | include ntp
# 查看日志时间戳配置
show running-config | include timestamp
# 查看调试日志(应关闭)
show running-config | include debug show running-config | include debugging
# 查看安全日志(安全认证/攻击事件)
show logging | include security show logging | include authentication show logging | include ssh
# 查看攻击防范日志
show logging | include attack show logging | include ip unreach show logging | include syslog-connection
# 查看日志保留策略(如支持)
show running-config | include archive log show archive config
四、入侵防范
对应条款 8.1.4.4 / 8.1.2.3
4.1 服务最小化与端口管理
高危端口
show ip tcp | include LISTEN
✓ 达标判据 无Telnet/FTP/TFTP端口监听,仅SSH(22)/HTTPS(443)
服务状态
show running-config | include server enable
✓ 达标判据 仅开启必要服务,HTTP/Telnet/FTP均已关闭
固件版本
show version
✓ 达标判据 为官方最新稳定版本,已修补已知漏洞
未使用端口
show interface status
✓ 达标判据 未使用的端口已shutdown
▸ Cisco IOS/IOS-XE 设备特有配置
# 查看设备版本及补丁
show version show archive config show running-config | include image
# 查看所有已开启服务
show running-config | include server enable show running-config | include telnet show running-config | include http show running-config | include ftp
# 查看TCP/UDP监听端口
show ip tcp | include LISTEN show tcp brief show udp brief
# 查看接口下未使用的端口(应shutdown)
show interface status show interface brief
# 查看环路保护(STP)
show spanning-tree show spanning-tree summary show running-config | include spanning-tree
# 查看LLDP/CDP邻居(排查未授权接入)
show cdp neighbors show lldp neighbors show cdp table
4.2 网络攻击防范
# 查看URPF配置(单播反向路径转发)
show running-config | include ip verify source show running-config | include urpf
# 查看TCP拦截/连接限制
show running-config | include tcp intercept show running-config | include tcp max-syn
# 查看ICMP重定向
show running-config | include icmp redirect
# 查看Smurf/Land/Fraggle攻击防范
show running-config | include smurf show running-config | include fragment show running-config | include tcp
# 查看ARP攻击防范(DAI/DHCP Snooping)
show ip arp inspection show ip dhcp snooping
# 查看ND攻击防范(IPv6)
show ip nd snooping
# 查看DHCP仿冒防范
show ip dhcp snooping show ip dhcp snooping binding
# 查看BPDU保护(防私接交换机)
show spanning-tree bpduguard show running-config | include bpduguard
# 查看端口安全(MAC地址绑定)
show port-security show port-security interface
# 查看CPU防护
show control-plane show running-config | include control-plane show running-config | include service-policer
# 查看广播/组播/未知单播风暴抑制
show running-config | include storm-control show storm-control
五、恶意代码防范
对应条款 8.1.4.5
Cisco IOS/IOS-XE 设备通常无传统杀毒软件,重点检查固件及配置完整性:
固件完整性
show version
✓ 达标判据 IOS版本与官方发布一致,未使用第三方固件
配置一致性
show configuration differences
✓ 达标判据 当前运行配置与保存配置一致
配置备份
show startup-config
✓ 达标判据 启动配置存在且完整
▸ Cisco IOS/IOS-XE 设备特有配置
# 查看当前运行配置
show running-config
# 查看保存配置(下次启动配置)
show startup-config
# 对比当前配置与保存配置是否一致
show configuration differences
# 查看启动文件及存储
show boot show flash dir flash:
# 查看配置文件校验(如支持)
show md5sum flash: show crypto hash md5
# 查看License及功能授权
show license status show license
# 查看系统补丁及版本签名
show version | include "IOS" show archive config
六、可信验证
对应条款 8.1.4.6 · 网络设备可选
启动文件校验
show boot
✓ 达标判据 启动文件完整,启动顺序合理
配置归档
show archive config
✓ 达标判据 配置变更可追溯,存在版本记录
固件签名
show version
✓ 达标判据 官方发布版本,未使用非官方固件
安全密钥
show crypto key mypubkey rsa
✓ 达标判据 存在有效的加密密钥对
▸ Cisco IOS/IOS-XE 设备特有配置
# 查看启动文件路径及名称
show boot
# 查看BootROM版本
show version | include "Boot"
# 查看系统软件版本及补丁
show version show archive config
# 查看安全密钥(RSA/DSA)
show crypto key mypubkey rsa show crypto key mypubkey dsa show running-config | include crypto key
# 查看配置回滚点
show archive config
# 查看系统健康状态
show processes cpu show processes memory show environment show controllers
七、数据备份与恢复
对应条款 8.1.4.9
配置备份
show startup-config
✓ 达标判据 配置已保存(startup-config存在)
自动备份
show running-config | include archive
✓ 达标判据 存在自动归档配置
启动文件备份
show boot
✓ 达标判据 主备启动文件均存在
▸ Cisco IOS/IOS-XE 设备特有配置
# 查看启动配置文件
show boot show running-config | include boot
# 查看配置自动备份
show running-config | include archive show archive config
# 查看TFTP/FTP/SFTP备份配置
show running-config | include tftp show running-config | include ftp show running-config | include sftp
# 查看NQA/Track/BFD等可靠性配置
show running-config | include track show running-config | include bfd
# 查看VRRP/HSRP热备
show running-config | include hsrp show running-config | include vrrp show hsrp show vrrp
# 查看链路聚合及冗余
show etherchannel summary show etherchannel port-channel show running-config | include channel-group
# 查看设备堆叠/IRF状态(如支持)
show stack show switch show stack-state
一键巡检脚本(Cisco IOS/IOS-XE 设备)
CISCO
===== 1 身份鉴别 =====
show running-config | section username show running-config | include enable secret show running-config | include service password-encryption show running-config | include password-policy show running-config | include password-history show users show line vty show line console show running-config | include authentication show running-config | include radius-server show running-config | include tacacs-server show running-config | include ldap show running-config | include dot1x
===== 2 访问控制 =====
show ip access-list all show running-control-plane show running-config | include access-group show running-config | include port-security show port-security show ip dhcp snooping show ip dhcp snooping binding show ip source bind show ip arp inspection
===== 3 安全审计 =====
show logging show logging host show running-config | include logging show running-config | include syslog show log | last 50 show ntp status show ntp associations show running-config | include debug
===== 4 入侵防范 =====
show version show running-config | include server enable show ip tcp | include LISTEN show interface status show spanning-tree summary show running-config | include urpf show running-config | include tcp intercept show running-config | include bpduguard show port-security interface show control-plane show running-config | include storm-control
===== 5 恶意代码防范 =====
show running-config show startup-config show configuration differences show boot dir flash:
===== 6 可信验证 =====
show boot show version show archive config show crypto key mypubkey rsa show processes cpu show processes memory show environment
===== 7 数据备份 =====
show startup-config show running-config | include archive show archive config show boot show running-config | include hsrp show running-config | include vrrp show etherchannel summary show stack
===== 8 Cisco特有 =====
show running-config | include ip http show running-config | include ip ssh show running-config | include snmp-server show running-config | include crypto pki show running-config | include license
高风险项重点核查清单
01Telnet服务开启
验证命令 show running-config | section line vty
不合规判定 VTY线路未禁用Telnet或未配置SSH
整改建议 line vty 0 15 → transport input ssh → exit
02SNMP使用默认团体字
验证命令 show snmp-server community
不合规判定 团体字为 public 或 private
整改建议 no snmp-server community public RO → 使用 snmp-server group
03HTTP明文管理开启
验证命令 show running-config | include ip http
不合规判定 ip http server 已启用
整改建议 no ip http server → ip http secure-server
04无密码复杂度策略
验证命令 show running-config | include password-policy
不合规判定 未配置密码复杂度、长度、有效期
整改建议 配置 password-policy + username 策略
05无日志外发
验证命令 show logging host
不合规判定 日志未外发至远程Syslog服务器
整改建议 logging host
06无NTP时间同步
验证命令 show ntp status
不合规判定 未配置NTP服务器,时间不同步
整改建议 ntp server
07高危服务开启(FTP/TFTP)
验证命令 show running-config | include ftp
不合规判定 FTP/TFTP服务开启
整改建议 no ip ftp → 如需文件传输,配置SFTP
08未保存配置
验证命令 show configuration differences
不合规判定 运行配置与保存配置不一致
整改建议 copy running-config startup-config
09STP未启用
验证命令 show spanning-tree summary
不合规判定 STP全局未启用,存在环路风险
整改建议 spanning-tree mode rapid-pvst
10端口安全未启用
验证命令 show port-security
不合规判定 接入端口未启用端口安全
整改建议 interface
11调试模式开启
验证命令 show running-config | include debug
不合规判定 存在 debug all 或类似命令
整改建议 undebug all
12未使用SHA2密钥
验证命令 show crypto key mypubkey rsa
不合规判定 SSH密钥位数不足(<2048位)
整改建议 crypto key generate rsa general-purpose modulus 2048
13密码未加密
验证命令 show running-config | include service password-encryption
不合规判定 未启用 service password-encryption
整改建议 service password-encryption
14未关闭HTTP服务器
验证命令 show running-config | include ip http
不合规判定 ip http server 未禁用
整改建议 no ip http server
15登录无超时
验证命令 show line vty
不合规判定 VTY超时时间 > 10分钟
整改建议 line vty 0 15 → exec-timeout 10 0
Cisco IOS/IOS-XE 设备 vs 标准Linux服务器对比
| 对比项 | 标准Linux服务器 | Cisco IOS/IOS-XE 设备 |
| — | — | — |
| 操作系统/内核 | Linux内核 | Cisco IOS/IOS-XE |
| 命令行类型 | bash/shell | Cisco IOS CLI(show命令体系) |
| 用户管理 | /etc/passwd、useradd、PAM | username
测评执行要点
- 权限要求
• 需具备 Privileged EXEC Mode(enable模式) 权限执行 show 命令
• 查看 show running-config 需要 L1(enabled)权限
• 部分命令(如 show privilege)仅需 L0(用户模式)即可执行
• 进入 enable 模式:enable
- 现场核查重点
• 管理面暴露:核查是否仅通过SSH访问,VTY线路是否已禁用Telnet
• SNMP安全:核查是否使用v3且启用认证加密,v1/v2c是否已禁用
• 配置一致性:核查 show running-config 与 show startup-config 是否一致
• 固件版本:核查是否为官方最新补丁版本,是否存在已知CVE漏洞
• 日志完整性:核查日志是否外发至集中日志服务器,NTP是否已同步
• 密码策略:核查 enable secret 是否使用加密,service password-encryption 是否启用
- 不同产品差异
• IOS vs IOS-XE:IOS-XE 支持更多高级特性(如 show archive、ip verify source、control-plane);IOS 设备部分命令不支持
• 交换机 vs 路由器:交换机使用 show etherchannel、show port-security、show spanning-tree;路由器使用 show ip route、show ip ospf
• IOS vs NX-OS:Cisco NX-OS(用于ACI/Nexus)命令略有差异,如 show feature、show interface brief 等
常用命令速查
系统信息
show version # 版本信息
show interfaces status # 接口状态
show environment # 环境监控(风扇/电源/温度)
show processes cpu # CPU使用率
show processes memory # 内存使用率
show clock # 系统时间
网络状态
show interfaces brief # 接口状态概览
show ip interface brief # IP接口状态
show ip route # 路由表
show arp # ARP表
show mac address-table # MAC地址表
show ip tcp # TCP连接
show udp # UDP连接
show running-config # 当前运行配置
安全配置
show running-config # 当前运行配置
show startup-config # 保存配置
show ip access-list # ACL规则
show running-config | include password-policy # 密码策略
show ip ssh # SSH状态
show running-config | include snmp-server # SNMP配置
show running-config | include authentication # AAA认证
日志审计
show log # 日志缓冲区
show logging host # 日志主机
show logging # 日志通道及级别
show ntp status # NTP状态
show ntp associations # NTP会话
可靠性
show spanning-tree # 生成树
show vrrp # VRRP热备
show hsrp # HSRP热备
show etherchannel summary # 链路聚合
show ntp status # NTP状态
show archive config # 配置归档
参考标准
| 标准编号 | 标准名称 | | — | — | | GB/T 22239-2019 | 《信息安全技术 网络安全等级保护基本要求》 | | GB/T 28448-2019 | 《信息安全技术 网络安全等级保护测评要求》 | | GB/T 25070-2019 | 《信息安全技术 网络安全等级保护安全设计技术要求》 |
关注路劲科技,关注网络安全!
END
关于我们:
北京路劲科技有限公司(Beijing Lujin Technology Co. , Ltd.)成立于2019年1月4日,是一家提供全面系统集成与信息安全解决方案的专业IT技术服务公司。公司秉承“为网络安全保驾护航”的企业愿景及“提升国家整体安全”的使命,依据风险评估模型和等级保护标准,采用大数据等技术手段,开展网络安全相关业务。公司致力于为各个行业的业务信息化提供软件和通用解决方案、系统架构,系统管理和数据安全服务、以及IT咨询规划、系统集成与系统服务等专业化服务。公司立足北京,走向全国,始终坚持“换位、细节、感恩”的核心价值观,以“共赢、共享、共成长”的经营理念为出发点,集合了一批敢于创新、充满活力、热衷于为IT行业服务的优秀人才,致力于成为您身边的网络安全专家。
关注路劲科技,关注网络安全!
公司:北京路劲科技有限公司
地址:北京市昌平区南邵镇双营西路78号院2号楼5层504
免责声明:
本文所载程序、技术方法仅面向合法合规的安全研究与教学场景,旨在提升网络安全防护能力,具有明确的技术研究属性。
任何单位或个人未经授权,将本文内容用于攻击、破坏等非法用途的,由此引发的全部法律责任、民事赔偿及连带责任,均由行为人独立承担,本站不承担任何连带责任。
本站内容均为技术交流与知识分享目的发布,若存在版权侵权或其他异议,请通过邮件联系处理,具体联系方式可点击页面上方的联系我。
本文转载自:北京路劲科技有限公司 《等保测评命令——思科(Cisco)网络设备》
版权声明
本站仅做备份收录,仅供研究与教学参考之用。
读者将信息用于其他用途的,全部法律及连带责任由读者自行承担,本站不承担任何责任。








评论