Table Of Contents Reference Documents Reference Documents Security Area Reference Document Link Data Center Data Center Service Integration: Service Chassis Design Guide http://www.cisco.com/en/US/docs/solutions/Enterprise/Data_Center/dc_servchas/service-chassis_design.html Cisco Nexus 7000 in the Data Center Aggregation Layer with Services http://www.cisco.com/en/US/docs/solutions/Enterprise/Data_Center/nx_7000_dc.html Campus Design Campus Network for High Availability Design Guide http://www.cisco.com/en/US/docs/solutions/Enterprise/Campus/HA_campus_DG/hacampusdg.html Enterprise Campus 3.0 Architecture: Overview and Framework http://www.cisco.com/en/US/docs/solutions/Enterprise/Campus/campover.html Campus Design Zone Site http://www.cisco.com/en/US/netsol/ns815/networking_solutions_program_home.html DNS Protection DNS Best Practices, Network Protections, and Attack Identification http://www.cisco.com/web/about/security/intelligence/dns-bcp.html DoS Protection Remotely Triggered Black Hole Filtering http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6642/prod_white_paper0900aecd80313fac.pdf Edge Filtering BCP 38 http://tools.ietf.org/html/bcp38 RFC 2827 http://tools.ietf.org/html/rfc2827 RFC 3330 http://tools.ietf.org/html/rfc3330 E-mail Security Cisco IronPort C-Series http:// www.ironport.com/email Endpoint Security CSA http://www.cisco.com/go/csa CSSC http://cisco.com/en/US/products/ps7034/index.html Export Restrictions Cisco Global Export Trade http://www.cisco.com/web/about/doing_business/legal/global_export_trade/index.html Firewall ASA 5500 Series http://www.cisco.com/go/asa Cisco Firewall http://www.cisco.com/go/firewall IOS Firewall http://www.cisco.com/en/US/products/sw/secursw/ps1018/index.html Identity-Based Network Services Cisco Identity Based Networking Services (IBNS) http://www.cisco.com/go/ibns Cisco Network Admission Control (NAC) http://www.cisco.com/go/nac IP Spoofing Protection Configuring DHCP Features and IP Source Guard on Catalyst 3750 Switches http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_46_se/configuration/guide/swdhcp82.html Configuring DHCP Snooping and IP Source Guard on Catalyst 4500 Switches http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/31sg/configuration/guide/dhcp.html Configuring Unicast Reverse Path Forwarding http://www.cisco.com/en/US/docs/ios/security/configuration/guide/sec_cfg_unicast_rpf_ps6350_TSD_Products_Configuration_Guide_Chapter.html IPS Cisco IPS Portfolio http://www.cisco.com/go/ips Cisco IPS 4200 Series Configuration Examples and TechNotes http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/prod_configuration_examples_list.html Cisco IPS 4200 Series Configuration Guides http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_installation_and_configuration_guides_list.html Cisco IPS Tuning Overview (CCO Login required) http://www.cisco.com/en/US/partner/prod/collateral/vpndevc/ps5729/ps5713/ps4077/overview_c17-464691.html Configuring IPS High Bandwidth Using EtherChannel Load Balancing http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_configuration_example09186a0080671a8d.shtml Network Access Control Identity Based Networking Services (IBNS) Site http://www.cisco.com/go/ibns Network Appliance Site http://www.cisco.com/go/nacappliance NAC Profiler and NAC Server Collectors in a Layer 3 Out-of-Band Configuration Guide http://www.cisco.com/en/US/products/ps6128/products_configuration_example09186a0080a30ad7.shtml NAC User Management: Configuring Authentication Servers http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/416/CAM/m_auth.html Network Virtualization Solutions Virtualization Technology Site http://www.cisco.com/en/US/netsol/ns872/index.html PCI Design PCI Solution for Retail Design and Implementation Guide http://www.cisco.com/en/US/docs/solutions/Verticals/PCI_Retail/PCI_Retail_DIG.html QoS Design Enterprise QoS Solution Reference Network Design Guide http://www.cisco.com/en/US/docs/solutions/Enterprise/WAN_and_MAN/QoS_SRND/QoS-SRND-Book.htm Quality of Service (QoS) http://www.cisco.com/en/US/products/ps6558/products_ios_technology_home.html Routing Security Protecting Border Gateway Protocol for the Enterprise http://www.cisco.com/web/about/security/intelligence/protecting_bgp.html Security Design Cisco Network Security Baseline http://www.cisco.com/en/US/docs/solutions/Enterprise/Security/Baseline_Security/securebasebook.html Cisco SAFE http://www.cisco.com/go/safe Design Zone for Security http://www.cisco.com/en/US/netsol/ns744/networking_solutions_program_home.html Infrastructure Protection on Cisco Catalyst 6500 and 4500 Series Switches whitepaper http://www.cisco.com/application/pdf/en/us/guest/netsol/ns171/c649/ccmigration_09186a0080825564.pdf Switching Security Configuring DHCP Features and IP Source Guard http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_46_se/configuration/guide/swdhcp82.html Configuring Dynamic ARP Inspection on 3750 Switches http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_46_se/configuration/guide/swdynarp.html Configuring Port Security http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_46_se/configuration/guide/swtrafc.html#wp1038501 Configuring Storm Control http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_44_se/configuration/guide/swtrafc.html#wp1063295 Port Security Violations http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_46_se/configuration/guide/swtrafc.html#wp1090391 Smartports Macros on 3750 Switches http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_46_se/configuration/guide/swmacro.html Configuring SmartPort Macros on Catalyst 4500 http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/31sg/configuration/guide/macro.html Switch Security Services http://www.cisco.com/go/switchsecurity Telemetry Cisco IOS Netflow http://www.cisco.com/en/US/products/ps6601/products_ios_protocol_group_home.html Cisco Security Monitoring, Analysis, and Response System (CS-MARS) http://www.cisco.com/go/mars Embedded Event Manager (EEM) Scripting Community http://forums.cisco.com/eforum/servlet/EEM?page=main Network Time Protocol: Best Practices White Paper http://www.cisco.com/en/US/tech/tk869/tk769/technologies_white_paper09186a0080117070.shtml Teleworker Design Cisco Virtual Office http://www.cisco.com/go/cvo Cisco Virtual Office-Solution Reference Network Design (SRND) http://www.cisco.com/en/US/solutions/collateral/ns340/ns517/ns430/ns855/guide_c07-495139.html Threat Alerts Cisco Security Advisories http://www.cisco.com/en/US/products/products_security_advisories_listing.html Cisco Security Center http://tools.cisco.com/security/center/home.x Cisco Security IntelliShield Alert Manager Service http://www.cisco.com/en/US/products/ps6834/serv_group_home.html Threats Botnets: The New Threat Landscape http://www.cisco.com/en/US/solutions/collateral/ns340/ns394/ns171/ns441/networking_solutions_whitepaper0900aecd8072a537.html Infiltrating a Botnet http://www.cisco.com/web/about/security/intelligence/cwilliams-bots.html WAN Design Call Admission Control for IKE http://www.cisco.com/en/US/docs/ios/security/configuration/guide/sec_call_addmsn_ike.html Design Zone for WAN/MAN http://www.cisco.com/en/US/netsol/ns817/networking_solutions_program_home.html Digital Certificates/PKI for IPSec VPN's http://www.cisco.com/en/US/docs/solutions/Enterprise/Security/DCertPKI.html Dynamic Multipoint VPN (DMVPN) Design Guide http://www.cisco.com/en/US/docs/solutions/Enterprise/WAN_and_MAN/DMVPDG.html Secure WAN Design Zone http://www.cisco.com/en/US/solutions/ns340/ns414/ns742/ns744/networking_solutions_products_genericcontent0900aecd805f65bf.html Site-to-Site VPNs http://www.cisco.com/go/vpn Transport Diversity: Performance Routing (PfR) Design Guide http://www.cisco.com/en/US/docs/solutions/Enterprise/WAN_and_MAN/Transport_diversity/Transport_Diversity_PfR.html Web Security Cisco ASA.5500 Series Content Security Services http://www.cisco.com/go/cscssm Cisco IOS Content Filtering http://www.cisco.com/en/US/products/ps6643/index.html Cisco IronPort S-Series http:// www.ironport.com/web Cisco Web Application Firewall http://www.cisco.com/go/waf WLAN Security Wireless and Network Security Integration Design Guide http://www.cisco.com/en/US/docs/solutions/Enterprise/Mobility/secwlandg20/sw2dg.html
Reference Documents
Data Center
Data Center Service Integration: Service Chassis Design Guide
http://www.cisco.com/en/US/docs/solutions/Enterprise/Data_Center/dc_servchas/service-chassis_design.html
Cisco Nexus 7000 in the Data Center Aggregation Layer with Services
http://www.cisco.com/en/US/docs/solutions/Enterprise/Data_Center/nx_7000_dc.html
Campus Design
Campus Network for High Availability Design Guide
http://www.cisco.com/en/US/docs/solutions/Enterprise/Campus/HA_campus_DG/hacampusdg.html
Enterprise Campus 3.0 Architecture: Overview and Framework
http://www.cisco.com/en/US/docs/solutions/Enterprise/Campus/campover.html
Campus Design Zone Site
http://www.cisco.com/en/US/netsol/ns815/networking_solutions_program_home.html
DNS Protection
DNS Best Practices, Network Protections, and Attack Identification
http://www.cisco.com/web/about/security/intelligence/dns-bcp.html
DoS Protection
Remotely Triggered Black Hole Filtering
http://www.cisco.com/en/US/prod/collateral/iosswrel/ps6537/ps6586/ps6642/prod_white_paper0900aecd80313fac.pdf
Edge Filtering
BCP 38
http://tools.ietf.org/html/bcp38
RFC 2827
http://tools.ietf.org/html/rfc2827
RFC 3330
http://tools.ietf.org/html/rfc3330
E-mail Security
Cisco IronPort C-Series
http:// www.ironport.com/email
Endpoint Security
CSA
http://www.cisco.com/go/csa
CSSC
http://cisco.com/en/US/products/ps7034/index.html
Export Restrictions
Cisco Global Export Trade
http://www.cisco.com/web/about/doing_business/legal/global_export_trade/index.html
Firewall
ASA 5500 Series
http://www.cisco.com/go/asa
Cisco Firewall
http://www.cisco.com/go/firewall
IOS Firewall
http://www.cisco.com/en/US/products/sw/secursw/ps1018/index.html
Identity-Based Network Services
Cisco Identity Based Networking Services (IBNS)
http://www.cisco.com/go/ibns
Cisco Network Admission Control (NAC)
http://www.cisco.com/go/nac
IP Spoofing Protection
Configuring DHCP Features and IP Source Guard on Catalyst 3750 Switches
http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_46_se/configuration/guide/swdhcp82.html
Configuring DHCP Snooping and IP Source Guard on Catalyst 4500 Switches
http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/31sg/configuration/guide/dhcp.html
Configuring Unicast Reverse Path Forwarding
http://www.cisco.com/en/US/docs/ios/security/configuration/guide/sec_cfg_unicast_rpf_ps6350_TSD_Products_Configuration_Guide_Chapter.html
IPS
Cisco IPS Portfolio
http://www.cisco.com/go/ips
Cisco IPS 4200 Series Configuration Examples and TechNotes
http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/prod_configuration_examples_list.html
Cisco IPS 4200 Series Configuration Guides
http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_installation_and_configuration_guides_list.html
Cisco IPS Tuning Overview (CCO Login required)
http://www.cisco.com/en/US/partner/prod/collateral/vpndevc/ps5729/ps5713/ps4077/overview_c17-464691.html
Configuring IPS High Bandwidth Using EtherChannel Load Balancing
http://www.cisco.com/en/US/products/hw/vpndevc/ps4077/products_configuration_example09186a0080671a8d.shtml
Network Access Control
Identity Based Networking Services (IBNS) Site
Network Appliance Site
http://www.cisco.com/go/nacappliance
NAC Profiler and NAC Server Collectors in a Layer 3 Out-of-Band Configuration Guide
http://www.cisco.com/en/US/products/ps6128/products_configuration_example09186a0080a30ad7.shtml
NAC User Management: Configuring Authentication Servers
http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/416/CAM/m_auth.html
Network Virtualization Solutions
Virtualization Technology Site
http://www.cisco.com/en/US/netsol/ns872/index.html
PCI Design
PCI Solution for Retail Design and Implementation Guide
http://www.cisco.com/en/US/docs/solutions/Verticals/PCI_Retail/PCI_Retail_DIG.html
QoS Design
Enterprise QoS Solution Reference Network Design Guide
http://www.cisco.com/en/US/docs/solutions/Enterprise/WAN_and_MAN/QoS_SRND/QoS-SRND-Book.htm
Quality of Service (QoS)
http://www.cisco.com/en/US/products/ps6558/products_ios_technology_home.html
Routing Security
Protecting Border Gateway Protocol for the Enterprise
http://www.cisco.com/web/about/security/intelligence/protecting_bgp.html
Security Design
Cisco Network Security Baseline
http://www.cisco.com/en/US/docs/solutions/Enterprise/Security/Baseline_Security/securebasebook.html
Cisco SAFE
http://www.cisco.com/go/safe
Design Zone for Security
http://www.cisco.com/en/US/netsol/ns744/networking_solutions_program_home.html
Infrastructure Protection on Cisco Catalyst 6500 and 4500 Series Switches whitepaper
http://www.cisco.com/application/pdf/en/us/guest/netsol/ns171/c649/ccmigration_09186a0080825564.pdf
Switching Security
Configuring DHCP Features and IP Source Guard
Configuring Dynamic ARP Inspection on 3750 Switches
http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_46_se/configuration/guide/swdynarp.html
Configuring Port Security
http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_46_se/configuration/guide/swtrafc.html#wp1038501
Configuring Storm Control
http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_44_se/configuration/guide/swtrafc.html#wp1063295
Port Security Violations
http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_46_se/configuration/guide/swtrafc.html#wp1090391
Smartports Macros on 3750 Switches
http://www.cisco.com/en/US/docs/switches/lan/catalyst3750/software/release/12.2_46_se/configuration/guide/swmacro.html
Configuring SmartPort Macros on Catalyst 4500
http://www.cisco.com/en/US/docs/switches/lan/catalyst4500/12.2/31sg/configuration/guide/macro.html
Switch Security Services
http://www.cisco.com/go/switchsecurity
Telemetry
Cisco IOS Netflow
http://www.cisco.com/en/US/products/ps6601/products_ios_protocol_group_home.html
Cisco Security Monitoring, Analysis, and Response System (CS-MARS)
http://www.cisco.com/go/mars
Embedded Event Manager (EEM) Scripting Community
http://forums.cisco.com/eforum/servlet/EEM?page=main
Network Time Protocol: Best Practices White Paper
http://www.cisco.com/en/US/tech/tk869/tk769/technologies_white_paper09186a0080117070.shtml
Teleworker Design
Cisco Virtual Office
http://www.cisco.com/go/cvo
Cisco Virtual Office-Solution Reference Network Design (SRND)
http://www.cisco.com/en/US/solutions/collateral/ns340/ns517/ns430/ns855/guide_c07-495139.html
Threat Alerts
Cisco Security Advisories
http://www.cisco.com/en/US/products/products_security_advisories_listing.html
Cisco Security Center
http://tools.cisco.com/security/center/home.x
Cisco Security IntelliShield Alert Manager Service
http://www.cisco.com/en/US/products/ps6834/serv_group_home.html
Threats
Botnets: The New Threat Landscape
http://www.cisco.com/en/US/solutions/collateral/ns340/ns394/ns171/ns441/networking_solutions_whitepaper0900aecd8072a537.html
Infiltrating a Botnet
http://www.cisco.com/web/about/security/intelligence/cwilliams-bots.html
WAN Design
Call Admission Control for IKE
http://www.cisco.com/en/US/docs/ios/security/configuration/guide/sec_call_addmsn_ike.html
Design Zone for WAN/MAN
http://www.cisco.com/en/US/netsol/ns817/networking_solutions_program_home.html
Digital Certificates/PKI for IPSec VPN's
http://www.cisco.com/en/US/docs/solutions/Enterprise/Security/DCertPKI.html
Dynamic Multipoint VPN (DMVPN) Design Guide
http://www.cisco.com/en/US/docs/solutions/Enterprise/WAN_and_MAN/DMVPDG.html
Secure WAN Design Zone
http://www.cisco.com/en/US/solutions/ns340/ns414/ns742/ns744/networking_solutions_products_genericcontent0900aecd805f65bf.html
Site-to-Site VPNs
http://www.cisco.com/go/vpn
Transport Diversity: Performance Routing (PfR) Design Guide
http://www.cisco.com/en/US/docs/solutions/Enterprise/WAN_and_MAN/Transport_diversity/Transport_Diversity_PfR.html
Web Security
Cisco ASA.5500 Series Content Security Services
http://www.cisco.com/go/cscssm
Cisco IOS Content Filtering
http://www.cisco.com/en/US/products/ps6643/index.html
Cisco IronPort S-Series
http:// www.ironport.com/web
Cisco Web Application Firewall
http://www.cisco.com/go/waf
WLAN Security
Wireless and Network Security Integration Design Guide
http://www.cisco.com/en/US/docs/solutions/Enterprise/Mobility/secwlandg20/sw2dg.html