Chapter 20: Security Configuration Guide

Monitoring TACACS Plus

You can monitor TACACS Plus configuration and statistics within the SSR.

To monitor TACACS Plus, enter the following commands in Enable mode:

Show TACACS Plus server

tacacs-plus

show

stats

statistics.

 

 

 

 

 

 

 

Show all TACACS Plus

tacacs-plus

show

all

parameters.

 

 

 

 

 

 

 

Configuring Passwords

The SSR provides password authentication for accessing the User and Enable modes. If TACACS is not enabled on the SSR, only local password authentication is performed.

To configure SSR passwords, enter the following commands in Configure mode:

Set User mode password.

system

set

password

login <string>

 

 

 

 

 

Set Enable mode password.

system

set

password

enable <string>

 

 

 

 

 

Layer-2 Security Filters

Layer-2 security filters on the SSR allow you to configure ports to filter specific MAC addresses. When defining a Layer-2 security filter, you specify to which ports you want the filter to apply. You can specify the following security filters:

Address filters

These filters block traffic based on the frame's source MAC address, destination MAC address, or both source and destination MAC addresses in flow bridging mode. Address filters are always configured and applied to the input port.

Port-to-address lock filters

These filters prohibit a user connected to a locked port or set of ports from using another port.

Static entry filters

These filters allow or force traffic to go to a set of destination ports based on a frame's source MAC address, destination MAC address, or both source and destination MAC addresses in flow bridging mode. Static entries are always configured and applied at the input port.

Secure port filters

SmartSwitch Router User Reference Manual

279

Page 305
Image 305
Cabletron Systems 9032578-05 manual Layer-2 Security Filters, Configuring Passwords, Monitoring Tacacs Plus