Index

Numerics

802.1x port security accounting, 163

accounting attributes for RADIUS, 183 accounting configuration, 182 allowing access to multiple hosts, 179 and sFlow, 162

applying IP ACLs and MAC address filters, 170 authenticating multiple hosts, 159 authentication with dynamic VLAN assignment, 198 clearing statistics, 188

communication between the devices, 155 configuration, 163

configuring an authentication method, 164 configuring per-user IP ACLs or MAC address filters, 173

configuring re-authentication,175 device roles in a configuration, 154 disabling strict security mode, 171

displaying dynamically-assigned VLAN information, 188

displaying information, 184

displaying MAC address and IP ACL information, 189 displaying multiple-host authentication information, 191

displaying statistics, 187

displaying the status of strict security mode, 190 dynamic VLAN assignment, 166

dynamically applying ACLs or MAC address filters, 172 enabling, 174

enabling accounting, 183 hub configuration, 197 initializing, 178

MAC address filtering, 182

message exchange during authentication, 157 multi-device authentication and security on the same port, 199

overview, 154

sample configurations, 196

saving dynamic VLAN assignments to the running- config file, 169

setting RADIUS parameters, 164

setting the EAP frame retransmissions, 178

setting the IP MTU size, 158 setting the port control, 174 setting the quiet period, 176

specifying a timeout for retransmission of messages, 178

specifying the RADIUS timeout action, 165 specifying the wait interval, 176 support for RADIUS, 159

A

AAA operations for TACACS/TACACS+, 29

AAA security for commands pasted into the running-config file, 29

access methods

disabling SNMP access, 12 disabling TFTP access, 12

access restrictions, remote, 6

ACL

adding a comment to an entry, 103 adding a comment to an IPv6 entry, 138

applying an IPv4 ACL to a subset of ports (Layer 3), 110 applying an IPv4 ACL to VLAN members (Layer 2), 110 applying egress to CPU traffic, 101

applying IPv6 to a trunk group, 138 applying to a virtual interface in a VLAN, 104 comment text management, 102 configuration example, 87

configuration example for extended named, 101 configuration examples for extended, 95 configuration notes for filtering, 109 configuration tasks for logging, 106 configuring for ARP filtering, 112

configuring IPv6, 129 configuring standard ACLs, 86 configuring the route map, 122 creating IPv6, 132

default and implicit IPv6 action, 131 deleting a comment from an entry, 103 deleting a comment from an IPv6 entry, 139 deny permit, 133

displaying ACL information, 119 displaying filters for ARP, 113

Brocade ICX 6650 Security Configuration Guide

303

53-1002601-01

 

Page 323
Image 323
Brocade Communications Systems 6650 manual Index