What is a Network Baseline Configuration?
A network baseline configuration is a documented, approved, and version-controlled standard for every category of network device in your environment — core switches, edge routers, perimeter firewalls, wireless access points, and VPN concentrators. It defines what is enabled, what is disabled, how the device is accessed, and how it logs. The baseline is the reference point against which all change management is measured. ISO/IEC 27001:2022 Annex A.8.9 requires "configuration management" for all IT assets. CERT-In expects network device configurations to be documented, hardened, and regularly reviewed.
Top Network Misconfigurations Found in Indian Enterprise Audits
Source: InfraVeritas 360 field assessment data — 200+ Indian enterprise audits, 2024–2026
The 7 Network Baseline Essentials
- Remove all default credentials: Every network device must have its factory-default username and password changed before production deployment. Document the change process.
- Restrict management access: SSH only (disable Telnet). Restrict management interface access to a dedicated management VLAN. Use MFA for privileged network access.
- Implement VLAN segmentation: Minimum separation: user VLAN, server VLAN, management VLAN, DMZ, and guest network. No flat /16 or /8 subnets in production.
- Disable unused interfaces: Shut down all unused switch ports and router interfaces. Unused ports are silent pivot points in lateral movement attacks.
- Configure centralised syslog: All network devices must forward logs to a SIEM or syslog server. CERT-In requires 180-day log retention.
- Enable SNMP v3 only: SNMP v1 and v2c transmit community strings in plaintext. Use SNMPv3 with authentication and encryption, or disable SNMP entirely on non-monitored devices.
- Document and version-control configs: Use network configuration management tools (Ansible, RANCID, or Cisco NSO) to back up and version-control device configurations automatically.
Configuration Drift: The Silent Compliance Risk
Configuration drift occurs when individual administrators make undocumented changes — adding a firewall rule "temporarily," disabling a logging policy for troubleshooting, opening a port "just for now." Over time, the live configuration bears no resemblance to the documented baseline. Drift is the leading cause of audit failures in ISO 27001 surveillance reviews. The solution is continuous compliance scanning — automated tools that compare live device configurations against the approved baseline and alert on every deviation.
Assess Your Network Baseline
InfraVeritas 360 conducts on-site network configuration assessments — reviewing every perimeter device, switch, and firewall against your documented baseline and compliance framework requirements.
Review Your Network Baseline →