New in This Document
The following table describes changes to this guide for the FastIron 10.0.10 software release.
Summary of Changes in FastIron Release 10.0.10h05
| Feature | Description | Reference |
|---|---|---|
| Web Authentication Dependencies and Restrictions | WebAuth requires global web-management to be enabled and at least one protocol (HTTP or HTTPS) active. | Refer to Web Authentication Configuration Considerations and Configuring Web Authentication. |
| Updates to address defects | Made other minor updates to content throughout to address defects. | All chapters. |
| Minor editorial updates | Minor editorial updates were made throughout the Configuration Guide. | All chapters. |
Summary of Changes in FastIron Release 10.0.10g_cd7
| Feature | Description | Reference |
|---|---|---|
| PKI Certification | If PKI certificates fail validation after a device reload, configure NTP in the startup configuration so the system clock is automatically synchronized at boot. | Creating a Trustpoint |
| Updates to address defects | Made other minor updates to content throughout to address defects. | All chapters. |
| Minor editorial updates | Minor editorial updates were made throughout the Configuration Guide. | All chapters. |
Summary of Changes in FastIron Release 10.0.10h_cd1
| Feature | Description | Reference |
|---|---|---|
| FlexAuth and LLDP Override | To replace the authenticated MAC address on a FlexAuth-enabled port with the MAC address received in an LLDP frame. | Configuring Flexible Authentication Globally and Configuring Flexible Authentication on an Interface. |
| Updates to address defects | Made other minor updates to content throughout to address defects. | All chapters. |
| Minor editorial updates | Minor editorial updates were made throughout the Configuration Guide. | All chapters. |
Summary of Enhancements in FastIron Release 10.0.10g_cd1
|
Feature |
Description |
Reference |
|---|---|---|
| Downloadable ACL Configuration on a RADIUS Server | Beginning with FastIron 10.0.10g_cd1 release and later, a maximum of 45 rules can be sent from a RADIUS server. Prior releases supported a maximum of seven rules. | Refer to Dynamic ACLs in Authentication. |
| Web Authentication Redirect Link | The redirect URL sent from the RADIUS server shows on the login page after a successful authentication. | Refer to Configuring ICX Vendor-Specific Attributes on the RADIUS Server and Web Authentication Pages. |
| Enable Privileged Mode Password | The enable privilege-mode
password command can be used to configure a password for
the Privileged mode. |
Refer to Enable Privileged Mode Password. |
| Updates to address defects | Minor updates on content throughout to address defects. | All chapters |
| Minor editorial updates | Minor editorial updates were made throughout the Configuration Guide. | All chapters |
Summary of Enhancements in FastIron Release 10.0.10f
|
Feature |
Description |
Reference |
|---|---|---|
| Introduction of RUCKUS ICX 8100 support | Support for RUCKUS ICX 8100 devices is introduced. | Throughout the guide |
| Reintroduction of RUCKUS ICX 7150 support |
Support for RUCKUS ICX 7150 devices is reintroduced. |
Throughout the guide |
| Radius Authentication Key Length | The key-string in the radius-server key command
can be from 1 through 128 characters in length. |
Identifying the RADIUS Server to the RUCKUS Device |
| Updates to address defects | Minor updates on content throughout to address defects. | All chapters |
| Minor editorial updates | Minor editorial updates were made throughout the Configuration Guide. | All chapters |
FastIron release 10.0.10f reintroduces support for the RUCKUS ICX 7150 Series switches. ICX 7150-C08P and ICX 7150-C08PT are not supported.
Features supported on ICX 7150 devices in FastIron release 10.0.10f are based on the features supported in FastIron release 09.0.10j.
Refer to the RUCKUS FastIron Features and Standards Support Matrix for details and exceptions.
The ICX 7150 devices are not supported in FastIron releases 10.0.00, 10.0.00a, 10.0.10, 10.0.10a, 10.0.10b, 10.0.10c, 10.0.10d and 10.0.10e.
Summary of Enhancements in FastIron Release 10.0.10d
Summary of Changes in FastIron Release 10.0.10c
| Feature | Description | Reference |
|---|---|---|
| RADIUS priority | New: You can specify the connection priority when configuring multiple RADIUS servers for 802.1x, MAC authentication, or Web authentication. | Specifying RADIUS Server Priority |
| BSI C5 Cloud Mode | New: Enhancements have been added in support of the German Federal Office for Information Security (BSI) cloud computing requirements (C5). The new BSI Cloud mode supports onboarding to SmartZone using an ECDSA certificate. | BSI C5 Cloud Mode |
| Additional SSH encryption methods | New: The ip ssh
host-key-method command introduces an option for enabling
or disabling host key algorithms. The ip ssh
key-exchange-method command is updated to include new
secure key-exchange methods for SSH connections. The ip ssh
encryption command allows selection of a range of new
encryption algorithms. |
SSHv2 Supported Features |
| Additional SSH security options | New: The ip ssh stricthostkeycheck ask
command prompts the user to confirm the authenticity of the remote host
if the host key is not recognized. The ip ssh
delete-known-host-key command deletes the known host key
for a server and prompts the user to accept or reject the new key on the
next connection attempt. |
SSHv2 Supported Features and Setting Optional Parameters |
| Updates to address defects | Made other minor updates to content throughout to address defects. | All chapters. |
| Minor editorial updates | Minor editorial updates were made throughout the Configuration Guide. | All chapters. |
Summary of Changes in FastIron Release 10.0.10b
| Feature | Description | Reference |
|---|---|---|
| Login privilege mode | Reintroduced: You can configure the ICX device to enter privileged EXEC mode after a successful login through Telnet or SSH. | Entering Privileged EXEC Mode after a Telnet or SSH Login |
| Updates to address defects | Made other minor updates to content throughout to address defects. | All chapters. |
| Minor editorial updates | Minor editorial updates were made throughout the Configuration Guide. | All chapters. |
Summary of Changes in FastIron Release 10.0.10
|
Feature |
Description |
Reference |
|---|---|---|
| Strict password enforcement
Leaving
this in but conditioned out for now. I have this as reintroduced in
10.0.00a, so it would not have to be here. But just in
case...
|
New: The
enable
strict-password-enforcement command is reinstated in this
release. |
Configuring Advanced Local User Account Features |
| Network segmentation support in conjunction with SmartZone 6.1.1 or SmartZone 6.1.2 | New: In support of network segmentation, this release honors a RADIUS-returned VLAN for the Web Authentication client and adds related support for Web Authentication login page customization. | |
| Updates to address defects | Updated: Minor updates have been introduced throughout the guide to address defects. | All chapters |
| Minor editorial updates | Updated: Minor editorial updates were made throughout the guide. | All chapters |