New in This Document

The following table describes changes to this guide for the FastIron 10.0.10 software release.

Summary of Changes in FastIron Release 10.0.10h05

Feature Description Reference
Web Authentication Dependencies and Restrictions WebAuth requires global web-management to be enabled and at least one protocol (HTTP or HTTPS) active. Refer to Web Authentication Configuration Considerations and Configuring Web Authentication.
Updates to address defects Made other minor updates to content throughout to address defects. All chapters.
Minor editorial updates Minor editorial updates were made throughout the Configuration Guide. All chapters.

Summary of Changes in FastIron Release 10.0.10g_cd7

Feature Description Reference
PKI Certification If PKI certificates fail validation after a device reload, configure NTP in the startup configuration so the system clock is automatically synchronized at boot. Creating a Trustpoint
Updates to address defects Made other minor updates to content throughout to address defects. All chapters.
Minor editorial updates Minor editorial updates were made throughout the Configuration Guide. All chapters.

Summary of Changes in FastIron Release 10.0.10h_cd1

Feature Description Reference
FlexAuth and LLDP Override To replace the authenticated MAC address on a FlexAuth-enabled port with the MAC address received in an LLDP frame. Configuring Flexible Authentication Globally and Configuring Flexible Authentication on an Interface.
Updates to address defects Made other minor updates to content throughout to address defects. All chapters.
Minor editorial updates Minor editorial updates were made throughout the Configuration Guide. All chapters.

Summary of Enhancements in FastIron Release 10.0.10g_cd1

Feature

Description

Reference

Downloadable ACL Configuration on a RADIUS Server Beginning with FastIron 10.0.10g_cd1 release and later, a maximum of 45 rules can be sent from a RADIUS server. Prior releases supported a maximum of seven rules. Refer to Dynamic ACLs in Authentication.
Web Authentication Redirect Link The redirect URL sent from the RADIUS server shows on the login page after a successful authentication. Refer to Configuring ICX Vendor-Specific Attributes on the RADIUS Server and Web Authentication Pages.
Enable Privileged Mode Password The enable privilege-mode password command can be used to configure a password for the Privileged mode. Refer to Enable Privileged Mode Password.
Updates to address defects Minor updates on content throughout to address defects. All chapters
Minor editorial updates Minor editorial updates were made throughout the Configuration Guide. All chapters

Summary of Enhancements in FastIron Release 10.0.10f

Feature

Description

Reference

Introduction of RUCKUS ICX 8100 support Support for RUCKUS ICX 8100 devices is introduced. Throughout the guide
Reintroduction of RUCKUS ICX 7150 support

Support for RUCKUS ICX 7150 devices is reintroduced.

Throughout the guide
Radius Authentication Key Length The key-string in the radius-server key command can be from 1 through 128 characters in length. Identifying the RADIUS Server to the RUCKUS Device
Updates to address defects Minor updates on content throughout to address defects. All chapters
Minor editorial updates Minor editorial updates were made throughout the Configuration Guide. All chapters

FastIron release 10.0.10f reintroduces support for the RUCKUS ICX 7150 Series switches. ICX 7150-C08P and ICX 7150-C08PT are not supported.

Features supported on ICX 7150 devices in FastIron release 10.0.10f are based on the features supported in FastIron release 09.0.10j.

Refer to the RUCKUS FastIron Features and Standards Support Matrix for details and exceptions.

The ICX 7150 devices are not supported in FastIron releases 10.0.00, 10.0.00a, 10.0.10, 10.0.10a, 10.0.10b, 10.0.10c, 10.0.10d and 10.0.10e.

Summary of Enhancements in FastIron Release 10.0.10d

Feature

Description

Described in

RUCKUS ICX 7150-ES model support

FastIron release 10.0.10d adds support for ICX 7150-ES models. No other ICX 7150 models are supported.

Throughout the guide
Updates to address defects Minor updates on content throughout to address defects. All chapters.
Minor editorial updates Minor editorial updates were made throughout the guide. All chapters

Summary of Changes in FastIron Release 10.0.10c

Feature Description Reference
RADIUS priority New: You can specify the connection priority when configuring multiple RADIUS servers for 802.1x, MAC authentication, or Web authentication. Specifying RADIUS Server Priority
BSI C5 Cloud Mode New: Enhancements have been added in support of the German Federal Office for Information Security (BSI) cloud computing requirements (C5). The new BSI Cloud mode supports onboarding to SmartZone using an ECDSA certificate. BSI C5 Cloud Mode

and RUCKUS FastIron Command Reference

Additional SSH encryption methods New: The ip ssh host-key-method command introduces an option for enabling or disabling host key algorithms. The ip ssh key-exchange-method command is updated to include new secure key-exchange methods for SSH connections. The ip ssh encryption command allows selection of a range of new encryption algorithms. SSHv2 Supported Features

and the RUCKUS FastIron Command Reference

Additional SSH security options New: The ip ssh stricthostkeycheck ask command prompts the user to confirm the authenticity of the remote host if the host key is not recognized. The ip ssh delete-known-host-key command deletes the known host key for a server and prompts the user to accept or reject the new key on the next connection attempt. SSHv2 Supported Features

and Setting Optional Parameters

and the RUCKUS FastIron Command Reference

Updates to address defects Made other minor updates to content throughout to address defects. All chapters.
Minor editorial updates Minor editorial updates were made throughout the Configuration Guide. All chapters.

Summary of Changes in FastIron Release 10.0.10b

Feature Description Reference
Login privilege mode Reintroduced: You can configure the ICX device to enter privileged EXEC mode after a successful login through Telnet or SSH. Entering Privileged EXEC Mode after a Telnet or SSH Login
Updates to address defects Made other minor updates to content throughout to address defects. All chapters.
Minor editorial updates Minor editorial updates were made throughout the Configuration Guide. All chapters.

Summary of Changes in FastIron Release 10.0.10

Feature

Description

Reference

Strict password enforcement
Leaving this in but conditioned out for now. I have this as reintroduced in 10.0.00a, so it would not have to be here. But just in case...
New: The enable strict-password-enforcement command is reinstated in this release. Configuring Advanced Local User Account Features
Network segmentation support in conjunction with SmartZone 6.1.1 or SmartZone 6.1.2 New: In support of network segmentation, this release honors a RADIUS-returned VLAN for the Web Authentication client and adds related support for Web Authentication login page customization.

Honoring the RADIUS-Returned VLAN

Updates to address defects Updated: Minor updates have been introduced throughout the guide to address defects. All chapters
Minor editorial updates Updated: Minor editorial updates were made throughout the guide. All chapters