Find Technical Content
  • Home
  • Ruckus Support Portal
  • Ruckus Networks
  • Table of Contents
  • Dark Mode

Powered by Titania Delivery

⚠ This cached page may be outdated. Click refresh to get the latest content.
Cached Version You are Offline

You are viewing a cached version of this page.

You are currently offline. This page was loaded from cache.

RUCKUS FastIron Security Configuration Guide, 08.0.95 53-1005664-19

  • 1 Vistance Legal Statements
  • Preface Ruckus
    • 3 Contact Information, Resources, and Conventions
      • 3.1 Contacting RUCKUS Customer Services and Support
      • 3.2 Document Feedback
      • 3.3 RUCKUS Product Documentation Resources
      • 3.4 Online Training Resources
      • 3.5 Document Conventions
      • 3.6 Command Syntax Conventions
  • About This Document
    • 4 About This Document
      • 4.1 Supported Hardware
      • 4.2 New in this Document
      • 4.3 How Command Information is Presented in this Configuration Guide
    • 5 Managing User Accounts
      • 5.1 User Accounts Overview
        • 5.1.1 Configuration Enhancements for Local User Accounts
      • 5.2 Configuring Local User Accounts
        • 5.2.1 Configuring Advanced Local User Account Features
        • 5.2.2 Modifying Local User Account Passwords or Privileges
        • 5.2.3 Deleting Local User Accounts
      • 5.3 Recovering from a Lost Password
      • 5.4 Enabling Device Access Methods
      • 5.5 Remote Access For Managing Devices
        • 5.5.1 Remote Access Configuration Using Telnet
          • 5.5.1.1 Configuring Telnet Remote Access
        • 5.5.2 Remote Access Configuration Using SSH
        • 5.5.3 Using an IP Address to Restrict Remote Access
        • 5.5.4 Using an IP or MAC Address to Restrict Remote Access
        • 5.5.5 ACL Usage to Restrict Remote Access
          • 5.5.5.1 Using an ACL to Restrict Remote Access to Telnet
          • 5.5.5.2 Configuration Examples of Restricting Remote Access Using ACLs
        • 5.5.6 Restricting Remote Access to the Device to Specific VLAN IDs
          • 5.5.6.1 Using a Specific VLAN to Restrict Remote Access
        • 5.5.7 Designated VLAN for Management Sessions to a Layer 2 Switch
        • 5.5.8 Disabling Remote Access Methods
  • 6 TACACS+ Server Authentication
    • 6.1 TACACS and TACACS+ Security
      • 6.1.1 How TACACS+ Differs from TACACS
    • 6.2 TACACS/TACACS+ Authentication, Authorization, and Accounting
      • 6.2.1 Comparing TACACS Authentication to TACACS+ Authentication
        • 6.2.1.1 TACACS+ Authorization
        • 6.2.1.2 TACACS+ Accounting
      • 6.2.2 AAA Operations for TACACS/TACACS+
        • 6.2.2.1 AAA Security for Commands Pasted into the running-config
    • 6.3 TACACS and TACACS+ Configuration
      • 6.3.1 TACACS/TACACS+ Configuration Considerations
      • 6.3.2 Identifying the TACACS/TACACS+ Servers
      • 6.3.3 Specifying Different Servers for Individual AAA Functions
      • 6.3.4 Setting Optional TACACS and TACACS+ Parameters
        • 6.3.4.1 Setting the TACACS+ Key
        • 6.3.4.2 Setting the Retransmission Limit
        • 6.3.4.3 Setting the Timeout Parameter
        • 6.3.4.4 Enabling Management Access Based on a Port-based VLAN
      • 6.3.5 Configuring Authentication-method Lists for TACACS and TACACS+
        • 6.3.5.1 Entering Privileged EXEC Mode after a Telnet or SSH Login
        • 6.3.5.2 Configuring Authentication to Prompt for Password Only
        • 6.3.5.3 Telnet and SSH Prompts when the TACACS+ Server Is Unavailable
      • 6.3.6 Configuring TACACS+ Authorization
        • 6.3.6.1 Configuring Exec Authorization
        • 6.3.6.2 Configuring Command Authorization
      • 6.3.7 TACACS+ Accounting Configuration
        • 6.3.7.1 Configuring TACACS+ Accounting for Telnet/SSH (Shell) Access
        • 6.3.7.2 Configuring TACACS+ Accounting for CLI Commands
        • 6.3.7.3 Configuring TACACS+ Accounting for System Events
      • 6.3.8 Configuring an Interface as the Source for All TACACS and TACACS+ Packets
      • 6.3.9 Configuring TACACS/TACACS+ for Devices in a Traditional Stack
      • 6.3.10 TACACS Configuration Example
      • 6.3.11 TACACS+ Configuration Example
    • 6.4 Displaying TACACS/TACACS+ Statistics and Configuration Information
  • 7 RADIUS Authentication
    • 7.1 RADIUS Security
      • 7.1.1 RADIUS Authentication
      • 7.1.2 RADIUS Authorization
      • 7.1.3 RADIUS Accounting
      • 7.1.4 AAA Operations for RADIUS
      • 7.1.5 AAA Security for Commands Pasted into the running-config
    • 7.2 RADIUS Configuration Considerations
    • 7.3 Configuring RADIUS (Overview)
    • 7.4 Configuring Company-Specific Attributes on the RADIUS Server
    • 7.5 Identifying the RADIUS Server to the Ruckus Device
    • 7.6 Specifying Different Servers for Individual AAA Functions
    • 7.7 Mapping RADIUS Servers to Ports
    • 7.8 RADIUS Configuration Example
    • 7.9 Setting Up RADIUS over IPv6
    • 7.10 Setting RADIUS Parameters
    • 7.11 Configuring Detection of Dead RADIUS Servers
    • 7.12 Source Address Configuration for RADIUS Packets
    • 7.13 Configuring Authentication-method Lists for RADIUS
      • 7.13.1 Authentication-Method Values
      • 7.13.2 Entering Privileged EXEC Mode after a Telnet or SSH Login
      • 7.13.3 Configuring Enable Authentication to Prompt for Password Only
    • 7.14 RADIUS Authorization
      • 7.14.1 Configuring Exec Authorization
      • 7.14.2 Configuring Command Authorization
      • 7.14.3 Command Authorization and Accounting for Console Commands
      • 7.14.4 Enabling RADIUS CoA and Disconnect Message Handling for Dynamic Authorization
        • 7.14.4.1 RADIUS Disconnect Message and CoA Events
        • 7.14.4.2 Supported IETF Attributes in RFC 5176
    • 7.15 RADIUS Accounting
      • 7.15.1 Configuring RADIUS Accounting for Telnet/SSH (Shell) Access
      • 7.15.2 Configuring RADIUS Accounting for CLI Commands
      • 7.15.3 Configuring RADIUS Accounting for System Events
      • 7.15.4 RADIUS Accounting for 802.1X Authentication and MAC Authentication
        • 7.15.4.1 Enabling RADIUS Accounting for 802.1X Authentication and MAC Authentication
    • 7.16 Displaying RADIUS Configuration Information
  • 8 Security Vulnerability
    • 8.1 SSL Security
      • 8.1.1 Enabling the SSL Server on the Device
      • 8.1.2 Specifying a Port for SSL Communication
      • 8.1.3 Changing the SSL Server Certificate Key Size
      • 8.1.4 Support for SSL Digital Certificates Larger than 2048 Bits
      • 8.1.5 Importing Digital Certificates and RSA Private Key Files
      • 8.1.6 Generating an SSL Certificate
      • 8.1.7 Deleting the SSL Certificate
    • 8.2 TLS Support
    • 8.3 Authentication-method Lists
      • 8.3.1 Configuration Considerations for Authentication-method Lists
      • 8.3.2 Examples of Authentication-method Lists
  • 9 Secure Shell (SSH)
    • 9.1 SSH Version 2 Overview
      • 9.1.1 Tested SSH2 Clients
      • 9.1.2 SSH2 Supported Features
      • 9.1.3 SSH2 Unsupported Features
      • 9.1.4 SSH2 Authentication Types
    • 9.2 Configuring SSH2
      • 9.2.1 Enabling and Disabling SSH by Generating and Deleting Host Keys
        • 9.2.1.1 Generating a DSA or RSA Key Pair
        • 9.2.1.2 Deleting DSA and RSA Key Pairs
        • 9.2.1.3 Providing the Public Key to Clients
      • 9.2.2 Configuring DSA or RSA Challenge-Response Authentication
        • 9.2.2.1 Import Authorized Public Keys into the ICX Device
        • 9.2.2.2 Enable DSA or RSA Challenge-Response and Password Authentication
      • 9.2.3 Deleting the Public Keys
    • 9.3 Optional Parameters Overview
      • 9.3.1 SSH Rekey Configuration Notes
      • 9.3.2 Set Optional Parameters
    • 9.4 Filtering SSH Access Using ACLs
    • 9.5 Terminating an Active SSH Connection
    • 9.6 SSH2 Client
      • 9.6.1 Enabling SSH2 Client
      • 9.6.2 Configuring SSH2 Client Public Key Authentication
        • 9.6.2.1 Generating and Deleting a Client DSA Key Pair
        • 9.6.2.2 Generating and Deleting a Client RSA Key Pair
        • 9.6.2.3 Exporting Client Public Keys
      • 9.6.3 Establishing an SSH2 Client Connection
    • 9.7 Displaying SSH Information
  • SCP client support
    • 10 SCP Client Support
      • 10.1 SCP Client
      • 10.2 SCP Client Support Limitations
      • 10.3 Supported SCP Client Configurations
      • 10.4 Downloading an Image from an SCP Server
      • 10.5 Uploading an Image to an SCP Server
      • 10.6 Uploading Configuration Files to an SCP Server
      • 10.7 Downloading Configuration Files from an SCP Server
      • 10.8 Copying an Image between Devices
      • 10.9 Secure Copy with SSH2
        • 10.9.1 Enabling and Disabling SCP
        • 10.9.2 Secure copy configuration notes
        • 10.9.3 Example File Transfers Using SCP
          • 10.9.3.1 Copying a File to the running-config
          • 10.9.3.2 Copying a File to the startup config
          • 10.9.3.3 Copying the running-config File to an SCP-enabled Client
          • 10.9.3.4 Copying the startup config File to an SCP-enabled Client
          • 10.9.3.5 Copying a Software Image File to Flash Memory
          • 10.9.3.6 Copying a Software Image File from Flash Memory
          • 10.9.3.7 Importing a Digital Certificate Using SCP
          • 10.9.3.8 Importing an RSA Private Key
          • 10.9.3.9 Importing a DSA or RSA Public Key
          • 10.9.3.10 Copying License Files
  • 11 ACLs
    • 11.1 Layer 3 ACL Overview
      • 11.1.1 ACL Scaling
      • 11.1.2 Default ACL Action
      • 11.1.3 How Hardware-based ACLs Work
      • 11.1.4 How Fragmented Packets Are Processed
    • 11.2 IPv4 ACLs
      • 11.2.1 IPv4 ACL Configuration Guidelines
      • 11.2.2 Creating and Applying a Standard IPv4 ACL
      • 11.2.3 IPv4 Extended ACL Traffic Filtering Criteria
      • 11.2.4 Creating and Applying an Extended IPv4 ACL
      • 11.2.5 Applying Egress ACLs to Control (CPU) Traffic
      • 11.2.6 Preserving User Input for ACL TCP/UDP Port Numbers
      • 11.2.7 Enabling Strict Control of ACL Filtering of Fragmented Packets
      • 11.2.8 Filtering on IP Precedence and ToS Values
      • 11.2.9 ACLs to Filter ARP Packets
        • 11.2.9.1 Configuration Considerations for Filtering ARP Packets
        • 11.2.9.2 Configuring ACLs for ARP Filtering
        • 11.2.9.3 Displaying ACL Filters for ARP
        • 11.2.9.4 Clearing the Filter Count
      • 11.2.10 QoS Options for IP ACLs
        • 11.2.10.1 Configuration Notes for QoS Options
        • 11.2.10.2 Using a Combined ACL for 802.1p Marking
        • 11.2.10.3 Configuring QoS Priority for a VLAN
        • 11.2.10.4 DSCP Matching
      • 11.2.11 ACL-based Rate Limiting
      • 11.2.12 ACLs to Control Multicast Features
      • 11.2.13 Displaying IPv4 ACL Information
    • 11.3 IPv6 ACLs
      • 11.3.1 IPv6 ACL Traffic Filtering Criteria
      • 11.3.2 IPv6 Protocol Names and Numbers
      • 11.3.3 Default and Implicit IPv6 ACL Action
      • 11.3.4 IPv6 ACL Configuration Notes
      • 11.3.5 Creating and Applying an IPv6 ACL
      • 11.3.6 Neighbor Discovery (ND)-Packet DoS Attacks
      • 11.3.7 Displaying IPv6 ACLs
    • 11.4 Applying an ACL to a LAG Interface
    • 11.5 Applying ACLs to VLANs
    • 11.6 ACL Logging
      • 11.6.1 Configuration Notes for ACL Logging
      • 11.6.2 Enabling ACL Logging
    • 11.7 ACL Statistics
    • 11.8 ACL Accounting
      • 11.8.1 Changing the Accounting Period
      • 11.8.2 Configuring ACL Accounting
    • 11.9 Adding a Comment for an Entry in an ACL
      • 11.9.1 Deleting a Comment from an ACL Entry
      • 11.9.2 Viewing Comments in an ACL
    • 11.10 Sequence-based ACL Editing
      • 11.10.1 Inserting Rules into ACLs
      • 11.10.2 Deleting Rules from ACLs
    • 11.11 Displaying TCAM Information for ACLs
  • 12 MAC ACLs
    • 12.1 Layer 2 ACL Overview
    • 12.2 MAC Scaling by ICX Device
    • 12.3 MAC ACL Default Action
    • 12.4 MAC ACL Configuration Notes and Limitations
    • 12.5 Configuring and Applying MAC ACLs
    • 12.6 Displaying MAC ACL Information
  • SS_Policy-Based Routing
    • 13 Policy-Based Routing
      • 13.1 Policy-Based Routing Overview
      • 13.2 Route Maps
      • 13.3 Configuration Guidelines for IPv4 PBR
        • 13.3.1 Configuring an IPv4 PBR Policy with an IPv4 Address as the Next Hop
        • 13.3.2 Configuring an IPv4 PBR Policy with the NULL0 Interface as the Next Hop
        • 13.3.3 Configuring an IPv4 PBR Policy with a Tunnel as the Next Hop
        • 13.3.4 Configuring an IPv4 PBR Policy by Setting a VRF-aware Next Hop in a Route Map
        • 13.3.5 Displaying IPv4 PBR Information
      • 13.4 Configuration Guidelines for IPv6 PBR
        • 13.4.1 Configuring an IPv6 PBR Policy with an IPv6 Address as the Next Hop
        • 13.4.2 Configuring an IPv6 PBR Policy with the NULL0 Interface as the Next Hop
        • 13.4.3 Configuring an IPv6 PBR Policy with a Tunnel as the Next Hop
        • 13.4.4 Displaying IPv6 PBR Information
  • MACsec Key-Based Security
    • 14 Media Access Control Security
      • 14.1 MACsec Overview
      • 14.2 How MACsec Works
        • 14.2.1 MACsec Frame Format
      • 14.3 Configuring MACsec
      • 14.4 Enabling MACsec and Configuring Group Parameters
        • 14.4.1 Configuring MACsec Key-Server Priority
        • 14.4.2 Configuring MACsec Integrity and Encryption
        • 14.4.3 Configuring MACsec Frame Validation
        • 14.4.4 Configuring Replay Protection
      • 14.5 Enabling and Configuring Group Interfaces for MACsec
        • 14.5.1 Configuring the Pre-shared Key
      • 14.6 Sample MACsec Configuration
      • 14.7 Displaying MACsec Information
        • 14.7.1 Displaying MACsec Configuration Details
        • 14.7.2 Displaying Information on Current MACsec Sessions
        • 14.7.3 Displaying MKA Protocol Statistics for an Interface
        • 14.7.4 Displaying MACsec Secure Channel Activity for an Interface
  • Port MAC Security
    • 15 Port MAC Security (PMS)
      • 15.1 Port MAC Security Overview
        • 15.1.1 Local and Global Resources Used for Port MAC Security
        • 15.1.2 Configuration Considerations for Port MAC Security
        • 15.1.3 Secure MAC Movement
      • 15.2 Port MAC Security Configuration
      • 15.3 Configuring Port MAC Security
      • 15.4 Clearing Port Security Statistics
        • 15.4.1 Clearing Restricted MAC Addresses
        • 15.4.2 Clearing Violation Statistics
      • 15.5 Displaying Port MAC Security Information
  • 16 Flexible Authentication
    • 16.1 Flexible Authentication Overview
      • 16.1.1 MAC VLANs
      • 16.1.2 Data VLAN Requirements for Flexible Authentication
      • 16.1.3 Voice VLAN Requirements for Flexible Authentication
      • 16.1.4 Authentication Modes
      • 16.1.5 Tagged VM Client Support
      • 16.1.6 Static Authentication with MAC Authentication Filters
      • 16.1.7 Authentication Actions
        • 16.1.7.1 Authentication Timeout Action
      • 16.1.8 Authentication Session Limits on an Interface
      • 16.1.10 How Flexible Authentication Works
      • 16.1.11 Configuration Considerations and Guidelines for Flexible Authentication
    • 16.2 802.1X Authentication
      • 16.2.1 Device Roles in an 802.1X Configuration
      • 16.2.2 Communication between the Devices
      • 16.2.3 Controlled and Uncontrolled Ports
      • 16.2.4 Port Control for Authentication
      • 16.2.5 Message Exchange During Authentication
        • 16.2.5.1 EAP Pass-Through Support
    • 16.3 MAC Authentication
      • 16.3.1 MAC Address Formats Sent to the RADIUS Server
      • 16.3.2 Authenticating Multiple Hosts Connected to the Same Port
      • 16.3.3 How Flexible Authentication Works for Multiple Clients
      • 16.3.4 Flexible Authentication Accounting
      • 16.3.5 Change of Authorization
      • 16.3.6 Multiple RADIUS Servers
      • 16.3.8 Session Aging
      • 16.3.9 Periodic Reauthentication of Authenticated Clients
      • 16.3.10 Denial of Service Protection Support
      • 16.3.11 SNMP Traps for Flexible Authentication
      • 16.3.12 Syslog Messages for Flexible Authentication
    • 16.4 RADIUS Attributes for Authentication and Accounting
    • 16.5 Configuring ICX Vendor-Specific Attributes on the RADIUS Server
    • 16.6 Support for the RADIUS User-name attribute in Access-Accept Messages
    • 16.7 Dynamic VLAN Assignment
      • 16.7.1 Configuring the RADIUS Server to Support Dynamic VLAN Assignment for Authentication
      • 16.7.2 Authentication Success Scenarios
      • 16.7.3 Authentication Failure Scenarios
      • 16.7.4 Authentication Server Timeout Scenarios
      • 16.7.5 Authentication Client Timeout Scenarios (No Response to EAP Packets)
      • 16.7.6 Automatic Removal of Dynamic VLAN Assignments for 802.1X and MAC Authenticated Ports
    • 16.8 Dynamic ACLs in Authentication
      • 16.8.1 Configuration Guidelines for Dynamic ACLs
      • 16.8.2 Dynamically Applying Existing ACLs
    • 16.9 Support for IP Source Guard Protection
    • 16.10 Configuring Flexible Authentication
      • 16.10.1 Flexible Authentication Configuration Prerequisites
      • 16.10.2 Configuring Flexible Authentication Globally
      • 16.10.3 Configuring Flexible Authentication on an Interface
      • 16.10.4 Enabling 802.1X Authentication
      • 16.10.5 Enabling MAC Authentication
      • 16.10.6 Excluding the RADIUS Server for Login Features
    • 16.11 Displaying Authentication Information
      • 16.11.1 Displaying Configuration
      • 16.11.2 Displaying Statistics
      • 16.11.3 Displaying the Authentication Sessions
      • 16.11.4 Displaying Information about User ACLs
      • 16.11.5 Displaying Dynamically Assigned VLAN Information
    • 16.12 Clearing Authentication Details
  • 17 IPsec
    • 17.1 IPsec Overview
      • 17.1.1 Acronyms
      • 17.1.2 Establishment of an IPsec Tunnel
      • 17.1.3 Configuration of an IPsec Tunnel
      • 17.1.4 Configuration of Traffic to Route over an IPsec Tunnel
      • 17.1.5 Supported Algorithms
      • 17.1.6 Support for PSK for IKEv2 SAs
      • 17.1.7 Unicast IPv4 over IPsec Tunnels
      • 17.1.8 IPv6 over IPsec Tunnels
      • 17.1.9 IPsec Scalability Limits
      • 17.1.10 Supported Features and Functionality
      • 17.1.11 Unsupported Features
      • 17.1.12 Limitations
      • 17.1.13 IKEv2 Traps
      • 17.1.14 IPsec Traps
      • 17.1.15 IPSec over NAT
      • 17.1.16 Downgrade Considerations
    • 17.2 Configuring Global Parameters for IKEv2
    • 17.3 Configuring an IKEv2 Proposal
    • 17.4 Configuring an IKEv2 Policy
    • 17.5 Configuring an IKEv2 Authentication Proposal
    • 17.6 Configuring an IKEv2 Profile
    • 17.7 Configuring an IPsec Proposal
    • 17.8 Configuring an IPsec Profile
    • 17.9 Activating an IPsec Profile on a VTI
    • 17.10 Routing Traffic over IPsec Using Static Routing
    • 17.11 Routing Traffic over an IPsec Tunnel Using PBR
    • 17.12 Re-establishing SAs
    • 17.13 Enabling IKEv2 Extended Logging
    • 17.14 Disabling Traps and Syslog Messages for IKEv2 and IPsec
    • 17.15 Displaying IPsec Module Information
    • 17.16 Displaying IKEv2 Configuration Information
    • 17.17 Displaying IPsec Configuration Information
    • 17.18 Displaying and Clearing Statistics for IKEv2 and IPsec
    • 17.19 Configuration Example for an IPsec Tunnel Using Default Settings (Site-to-Site VPN)
    • 17.20 Configuration Example for a Hub-to-Spoke VPN Using IPsec
    • 17.21 Configuration Example for an IPsec Tunnel in an IPsec Tunnel
    • 17.22 PKI Support for IPsec
      • 17.22.1 Certificates
      • 17.22.2 Certificate Authority
      • 17.22.3 Certificate Revocation List
      • 17.22.4 CRL Distribution Point
      • 17.22.5 Distinguished Name
      • 17.22.6 Entity
      • 17.22.7 Lightweight Directory Access Protocol
      • 17.22.8 PKI Repository
      • 17.22.9 Registration Authority
      • 17.22.10 Requester
      • 17.22.11 Certificate Enrollment Using SCEP
        • 17.22.11.1 Types of Enrollment
        • 17.22.11.2 Requirements for Requesting a Certificate
        • 17.22.11.3 Communications Between Requesters and the CA
      • 17.22.12 Configuring PKI
        • 17.22.12.1 Configuring an Entity Distinguished Name
        • 17.22.12.2 Creating a Trustpoint
        • 17.22.12.3 Configuring CA Authentication
        • 17.22.12.4 Generating a Certificate Request
        • 17.22.12.5 Extended Key Usage
        • 17.22.12.6 Creating a PKI Enrollment Profile
        • 17.22.12.7 Installing Identity Certificates
        • 17.22.12.8 Clearing the Certificate Revocation List (CRL) and PKI Counters
        • 17.22.12.9 Enabling PKI Logging
        • 17.22.12.10 Displaying PKI Information
  • HTTP and HTTPS Authentication
    • 18 HTTP and HTTPS
      • 18.1 Web Authentication Overview
      • 18.2 Captive Portal Authentication (External Web Authentication)
        • 18.2.1 Captive Portal Profile for External Web Authentication
        • 18.2.2 Captive Portal on a VLAN
        • 18.2.3 Dynamic IP ACLs in Web Authentication
        • 18.2.4 Configuration Considerations for Applying IP ACLs
        • 18.2.5 Dynamically Applying Existing ACLs
        • 18.2.6 RADIUS Attribute for Session Timeout
      • 18.3 Web Authentication Configuration Considerations
      • 18.4 Web Authentication Configuration Tasks
      • 18.5 Prerequisites for Captive Portal Support with RUCKUS Cloudpath
      • 18.6 Prerequisites for Configuring Captive Portal with Aruba ClearPass
      • 18.7 Prerequisites for Configuring External Web Authentication with Cisco ISE
      • 18.8 Prerequisite Configurations on an ICX Switch for Captive Portal Authentication
      • 18.9 Creating the Captive Portal Profile for External Web Authentication
      • 18.10 Configuring Captive Portal (External Web Authentication)
      • 18.11 Enabling and Disabling Web Authentication
      • 18.12 Web Authentication Mode Configuration
        • 18.12.1 Using Local User Databases
          • 18.12.1.1 Configuring a Local User Database
          • 18.12.1.2 Creating a Local User Database
          • 18.12.1.3 Adding a User Record to a Local User Database
          • 18.12.1.4 Deleting a User Record from a Local User Database
          • 18.12.1.5 Deleting All User Records from a Local User Database
          • 18.12.1.6 Creating a Text File of User Records
          • 18.12.1.7 Importing a Text File of User Records from a TFTP Server
          • 18.12.1.8 Using a RADIUS Server as the Web Authentication Method
          • 18.12.1.9 Setting the Local User Database Authentication Method
          • 18.12.1.10 Setting the Web Authentication Failover Sequence
          • 18.12.1.11 Assigning a Local User Database to a Web Authentication VLAN
        • 18.12.2 Passcodes for User Authentication
          • 18.12.2.1 Configuring Passcode Authentication
          • 18.12.2.2 Creating Static Passcodes
          • 18.12.2.3 Enabling Passcode Authentication
          • 18.12.2.4 Configuring the Length of Dynamically Generated Passcodes
          • 18.12.2.5 Configuring the Passcode Refresh Method
          • 18.12.2.6 Configuring a Grace Period for an Expired Passcode
          • 18.12.2.7 Flushing All Expired Passcodes that Are in the Grace Period
          • 18.12.2.8 Disabling and Re-enabling Passcode Logging
          • 18.12.2.9 Resending the Passcode Log Message
          • 18.12.2.10 Manually Refreshing the Passcode
        • 18.12.3 Automatic Authentication
      • 18.13 Web Authentication Options
        • 18.13.1 Enabling RADIUS Accounting for Web Authentication
        • 18.13.2 Changing the Login Mode (HTTPS or HTTP)
        • 18.13.3 Specifying Trusted Ports
        • 18.13.4 Specifying Hosts that Are Permanently Authenticated
        • 18.13.5 Configuring the Re-authentication Period
        • 18.13.6 Defining the Web Authentication Cycle
        • 18.13.7 Limiting the Number of Web Authentication Attempts
        • 18.13.8 Clearing Authenticated Hosts from the Web Authentication Table
        • 18.13.9 Setting and Clearing the Block Duration for Web Authentication Attempts
        • 18.13.10 Manually Blocking and Unblocking a Specific Host
        • 18.13.11 Limiting the Number of Authenticated Hosts
        • 18.13.12 Filtering DNS Queries
        • 18.13.13 Forcing Re-authentication When Ports Are Down
        • 18.13.14 Forcing Re-authentication After an Inactive Period
        • 18.13.15 Defining the Web Authorization Redirect Address
        • 18.13.16 Deleting a Web Authentication VLAN
        • 18.13.17 Web Authentication Pages
          • 18.13.17.1 Displaying Text for Web Authentication Pages
          • 18.13.17.2 Customizing Web Authentication Pages
      • 18.14 Image Download over HTTPS
      • 18.15 Configuration Download over HTTPS
      • 18.16 Configuration Upload over HTTPS
      • 18.17 Displaying Web Authentication Information
        • 18.17.1 Displaying the Web Authentication Configuration
        • 18.17.2 Displaying a List of Authenticated Hosts
        • 18.17.3 Displaying a List of Hosts Attempting to Authenticate
        • 18.17.4 Displaying a List of Blocked Hosts
        • 18.17.5 Displaying a List of Local User Databases
        • 18.17.6 Displaying a List of Users in a Local User Database
        • 18.17.7 Displaying Passcodes
        • 18.17.8 Displaying Captive Portal Profile Details
  • Denial of Service Protection
    • 19 Protecting against Denial of Service Attacks
      • 19.1 Denial of Service Protection Overview
      • 19.2 Protecting against Smurf Attacks
        • 19.2.1 Avoiding Being an Intermediary in a Smurf Attack
        • 19.2.2 Avoiding Being a Victim in a Smurf Attack
          • 19.2.2.1 Configuring Threshold Values for ICMP Packets Globally
          • 19.2.2.2 Configuring ICMP Threshold Values on an Interface
      • 19.3 Protecting against TCP SYN Attacks
        • 19.3.1 Configuring Threshold Values for TCP SYN Packets Globally
        • 19.3.2 Configuring TCP SYN Threshold Values on an Interface
        • 19.3.3 TCP MSS Adjustment Overview
        • 19.3.4 Example
        • 19.3.5 Impact on Existing Functionality
        • 19.3.6 DDOS Limitations
        • 19.3.7 TCP MSS Adjustment Limitations
      • 19.4 Displaying Statistics from a DoS Attack
      • 19.5 Clear DoS Attack Statistics
  • 20 IPv6 RA Guard
    • 20.1 Securing IPv6 Address Configuration
    • 20.2 IPv6 RA Guard Overview
      • 20.2.1 RA Guard Policy
      • 20.2.2 Whitelist
      • 20.2.3 Prefix List
      • 20.2.4 Maximum Preference
      • 20.2.5 Trusted, Untrusted, and Host Ports
    • 20.3 Configuration Notes and Feature Limitations for IPv6 RA Guard
    • 20.4 Configuring IPv6 RA Guard
    • 20.5 Example of Configuring IPv6 RA Guard
      • 20.5.1 Example: Configuring IPv6 RA Guard on a Device
      • 20.5.2 Example: Configuring IPv6 RA Guard in a Network
      • 20.5.3 Example: Verifying the RA Guard Configuration
  • 21 Joint Interoperability Test Command
    • 21.1 JITC Overview
  • OpenSSL Acknowledgements
    • 22 OpenSSL License
      • 22.1 OpenSSL License
  • 23 Keychain Module
    • 23.1 Keychain Module Overview
      • 23.1.1 Components of a Keychain
      • 23.1.2 OSPF Keychain Authentication
      • 23.1.3 Configuring a Keychain Module

RADIUS Authentication

In this section:

  1. RADIUS Security
  2. RADIUS Configuration Considerations
  3. Configuring RADIUS (Overview)
  4. Configuring Company-Specific Attributes on the RADIUS Server
  5. Identifying the RADIUS Server to the RUCKUS Device
  6. Specifying Different Servers for Individual AAA Functions
  7. Mapping RADIUS Servers to Ports
  8. RADIUS Configuration Example
  9. Setting Up RADIUS over IPv6
  10. Setting RADIUS Parameters
  11. Configuring Detection of Dead RADIUS Servers
  12. Source Address Configuration for RADIUS Packets
  13. Configuring Authentication-method Lists for RADIUS
  14. RADIUS Authorization
  15. RADIUS Accounting
  16. Displaying RADIUS Configuration Information

Did you find what you were looking for?

Thanks!

Ruckus Wireless

© 2026 Ruckus Wireless LLC All rights reserved.

  • Accessibility
  • Privacy & Cookies
  • Do Not Sell My Information
  • Trademarks
  • Terms
  • Feedback