Categories
Welcome Center
Education & Development
Cyber Security
Virtualization
General
Certification Preparation
Project Management
Posts
Groups
Training Resources
Infosec
IT & Security Bootcamps
Practice Exams
Security Awareness Training
About Us
Home
Certification Preparation
Cisco
CCNP (Professional)
What design reasons are there to not use the following commands (see post)?
FrankGuthrie
no ip redirects
no ip unreachables
no ip directed-broadcast
no ip proxy-arp
Can anyone tell me why to turn these 4 features off or why to keep them on. Is this done for security purposes?
Find more posts tagged with
Save $250 on 2025 certification boot camps from Infosec!
Book now with code EOY2025
Button
Comments
subnet.ninja
Most of them are from security reasons redirects,icmp unreacble and arp are traffic that punt to the CPU so the best practices is to disable them you can learn more in the following link:
Cisco Guide to Harden Cisco IOS Devices - Cisco
Legacy User
That link gives the break down of everything.
A quick tid bit to add because I seen it from a production side of things. The original reason IP Proxy-Arp was used on devices when there were older network devices <specialized vendor equipment,etc> that did not have an option to configure the default gateway or subnet mask. So what IP Proxy-arp does on the router or L3 switch would be to basically act like the default gateway for that device, "filling in the gaps" for it to forward traffic arp traffic to find the destination. This can generate ALOT of unnecessary additional traffic which could bog down everything cpu, link utilization.
Many times after upgrading EOL network equipment that had the ip proxy-arp enabled we commonly would get tickets for devices that don't have internet connection and its because those devices did not have the default gateway and/or subnet mask ever configured so only reason they previously worked was because of the IP proxy-arp command.
Quick Links
All Categories
Recent Posts
Activity
Unanswered
Groups
Best Of
INFOSEC Boot Camps
$250
OFF
Use code
EOY2025
to receive $250 off your 2025 certification boot camp!
BROWSE BOOT CAMPS