< Home

Security Hardening Levels and Basis

Based on security hardening requirements, security hardening policies for a device can be classified into two levels.
  • Level 1: security hardening policies that must be configured
  • Level 2: enhanced security hardening policies, which can be configured based on service requirements

Security hardening can be performed using commands. To check security risks in the system, run the display security risk [ trap-info ] [ feature feature-name ] [ level { high | medium | low } ] command. Then perform security hardening based on the command output to eliminate security risks.

For example, if SNMPv1 is configured and the display security risk [ feature feature-name ] command output shows that SNMPv1 has security risks, the system will prompt you to use SNMPv3.

<HUAWEI> display security risk feature snmp
Risk level       : high     
Feature name     : SNMP     
Risk information : SNMP V1/V2c is enabled 
Repair action    : Disable SNMP V1/V2c and enable SNMP V3 only
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic