Static routing security.
Oleg Petukhov, lawyer in the field of international law and personal data protection, information security specialist security, protection of information and personal data.
Telegram channel: https://t.me/protectioninformation
Telegram Group: https://t.me/informationprotection1
Website: https://legascom.ru
Email: online@legascom.ru
#informationprotection #informationsecurity
To prevent the intentional or unintentional modification of static routes on routers, the following measures must be taken. First of all, you should implement physical protection so that users do not have access to routers. After all, with physical access to the device, there are much more opportunities for unauthorized entry. For example, in Cisco Systems equipment, if you have physical access, you can reset the administrator password without knowing it. To do this, it is enough to perform a number of manipulations described on the official website of this manufacturer.
Another security measure is to grant administrative authority only to those users who can run the routing and remote access service. Actually, the very mention of users here is not entirely correct, since there is nothing for an ordinary user to do in the router configuration interface. At least in the interface of the hardware router. But in small networks, one server is often used, which is both a router, a file server, a server, and a database server. In general, such a solution is unacceptable both from the point of view of security, as well as from the point of view of fault tolerance and performance. But small organizations don't have much money, so they save on equipment. When using a single server to solve multiple tasks, users should not have the rights to make changes to the routing settings. For Windows-based machines, it will be enough for you to grant the user the Users rights. In any case, do not give users Administrator rights, otherwise you risk not only getting unauthorized changes to the routing settings, but also completely losing the server.
The same applies for servers running Linux OS. Do not give ordinary users administrative rights.




