Find Technical Content
  • Home
  • Ruckus Support Portal
  • Ruckus Networks
  • Table of Contents
  • Dark Mode

Powered by Titania Delivery

⚠ This cached page may be outdated. Click refresh to get the latest content.
Cached Version You are Offline

You are viewing a cached version of this page.

You are currently offline. This page was loaded from cache.

RUCKUS FastIron Security Configuration Guide, 08.0.95 53-1005664-19

  • 1 Vistance Legal Statements
  • Preface Ruckus
    • 3 Contact Information, Resources, and Conventions
      • 3.1 Contacting RUCKUS Customer Services and Support
      • 3.2 Document Feedback
      • 3.3 RUCKUS Product Documentation Resources
      • 3.4 Online Training Resources
      • 3.5 Document Conventions
      • 3.6 Command Syntax Conventions
  • About This Document
    • 4 About This Document
      • 4.1 Supported Hardware
      • 4.2 New in this Document
      • 4.3 How Command Information is Presented in this Configuration Guide
    • 5 Managing User Accounts
      • 5.1 User Accounts Overview
        • 5.1.1 Configuration Enhancements for Local User Accounts
      • 5.2 Configuring Local User Accounts
        • 5.2.1 Configuring Advanced Local User Account Features
        • 5.2.2 Modifying Local User Account Passwords or Privileges
        • 5.2.3 Deleting Local User Accounts
      • 5.3 Recovering from a Lost Password
      • 5.4 Enabling Device Access Methods
      • 5.5 Remote Access For Managing Devices
        • 5.5.1 Remote Access Configuration Using Telnet
          • 5.5.1.1 Configuring Telnet Remote Access
        • 5.5.2 Remote Access Configuration Using SSH
        • 5.5.3 Using an IP Address to Restrict Remote Access
        • 5.5.4 Using an IP or MAC Address to Restrict Remote Access
        • 5.5.5 ACL Usage to Restrict Remote Access
          • 5.5.5.1 Using an ACL to Restrict Remote Access to Telnet
          • 5.5.5.2 Configuration Examples of Restricting Remote Access Using ACLs
        • 5.5.6 Restricting Remote Access to the Device to Specific VLAN IDs
          • 5.5.6.1 Using a Specific VLAN to Restrict Remote Access
        • 5.5.7 Designated VLAN for Management Sessions to a Layer 2 Switch
        • 5.5.8 Disabling Remote Access Methods
  • 6 TACACS+ Server Authentication
    • 6.1 TACACS and TACACS+ Security
      • 6.1.1 How TACACS+ Differs from TACACS
    • 6.2 TACACS/TACACS+ Authentication, Authorization, and Accounting
      • 6.2.1 Comparing TACACS Authentication to TACACS+ Authentication
        • 6.2.1.1 TACACS+ Authorization
        • 6.2.1.2 TACACS+ Accounting
      • 6.2.2 AAA Operations for TACACS/TACACS+
        • 6.2.2.1 AAA Security for Commands Pasted into the running-config
    • 6.3 TACACS and TACACS+ Configuration
      • 6.3.1 TACACS/TACACS+ Configuration Considerations
      • 6.3.2 Identifying the TACACS/TACACS+ Servers
      • 6.3.3 Specifying Different Servers for Individual AAA Functions
      • 6.3.4 Setting Optional TACACS and TACACS+ Parameters
        • 6.3.4.1 Setting the TACACS+ Key
        • 6.3.4.2 Setting the Retransmission Limit
        • 6.3.4.3 Setting the Timeout Parameter
        • 6.3.4.4 Enabling Management Access Based on a Port-based VLAN
      • 6.3.5 Configuring Authentication-method Lists for TACACS and TACACS+
        • 6.3.5.1 Entering Privileged EXEC Mode after a Telnet or SSH Login
        • 6.3.5.2 Configuring Authentication to Prompt for Password Only
        • 6.3.5.3 Telnet and SSH Prompts when the TACACS+ Server Is Unavailable
      • 6.3.6 Configuring TACACS+ Authorization
        • 6.3.6.1 Configuring Exec Authorization
        • 6.3.6.2 Configuring Command Authorization
      • 6.3.7 TACACS+ Accounting Configuration
        • 6.3.7.1 Configuring TACACS+ Accounting for Telnet/SSH (Shell) Access
        • 6.3.7.2 Configuring TACACS+ Accounting for CLI Commands
        • 6.3.7.3 Configuring TACACS+ Accounting for System Events
      • 6.3.8 Configuring an Interface as the Source for All TACACS and TACACS+ Packets
      • 6.3.9 Configuring TACACS/TACACS+ for Devices in a Traditional Stack
      • 6.3.10 TACACS Configuration Example
      • 6.3.11 TACACS+ Configuration Example
    • 6.4 Displaying TACACS/TACACS+ Statistics and Configuration Information
  • 7 RADIUS Authentication
    • 7.1 RADIUS Security
      • 7.1.1 RADIUS Authentication
      • 7.1.2 RADIUS Authorization
      • 7.1.3 RADIUS Accounting
      • 7.1.4 AAA Operations for RADIUS
      • 7.1.5 AAA Security for Commands Pasted into the running-config
    • 7.2 RADIUS Configuration Considerations
    • 7.3 Configuring RADIUS (Overview)
    • 7.4 Configuring Company-Specific Attributes on the RADIUS Server
    • 7.5 Identifying the RADIUS Server to the Ruckus Device
    • 7.6 Specifying Different Servers for Individual AAA Functions
    • 7.7 Mapping RADIUS Servers to Ports
    • 7.8 RADIUS Configuration Example
    • 7.9 Setting Up RADIUS over IPv6
    • 7.10 Setting RADIUS Parameters
    • 7.11 Configuring Detection of Dead RADIUS Servers
    • 7.12 Source Address Configuration for RADIUS Packets
    • 7.13 Configuring Authentication-method Lists for RADIUS
      • 7.13.1 Authentication-Method Values
      • 7.13.2 Entering Privileged EXEC Mode after a Telnet or SSH Login
      • 7.13.3 Configuring Enable Authentication to Prompt for Password Only
    • 7.14 RADIUS Authorization
      • 7.14.1 Configuring Exec Authorization
      • 7.14.2 Configuring Command Authorization
      • 7.14.3 Command Authorization and Accounting for Console Commands
      • 7.14.4 Enabling RADIUS CoA and Disconnect Message Handling for Dynamic Authorization
        • 7.14.4.1 RADIUS Disconnect Message and CoA Events
        • 7.14.4.2 Supported IETF Attributes in RFC 5176
    • 7.15 RADIUS Accounting
      • 7.15.1 Configuring RADIUS Accounting for Telnet/SSH (Shell) Access
      • 7.15.2 Configuring RADIUS Accounting for CLI Commands
      • 7.15.3 Configuring RADIUS Accounting for System Events
      • 7.15.4 RADIUS Accounting for 802.1X Authentication and MAC Authentication
        • 7.15.4.1 Enabling RADIUS Accounting for 802.1X Authentication and MAC Authentication
    • 7.16 Displaying RADIUS Configuration Information
  • 8 Security Vulnerability
    • 8.1 SSL Security
      • 8.1.1 Enabling the SSL Server on the Device
      • 8.1.2 Specifying a Port for SSL Communication
      • 8.1.3 Changing the SSL Server Certificate Key Size
      • 8.1.4 Support for SSL Digital Certificates Larger than 2048 Bits
      • 8.1.5 Importing Digital Certificates and RSA Private Key Files
      • 8.1.6 Generating an SSL Certificate
      • 8.1.7 Deleting the SSL Certificate
    • 8.2 TLS Support
    • 8.3 Authentication-method Lists
      • 8.3.1 Configuration Considerations for Authentication-method Lists
      • 8.3.2 Examples of Authentication-method Lists
  • 9 Secure Shell (SSH)
    • 9.1 SSH Version 2 Overview
      • 9.1.1 Tested SSH2 Clients
      • 9.1.2 SSH2 Supported Features
      • 9.1.3 SSH2 Unsupported Features
      • 9.1.4 SSH2 Authentication Types
    • 9.2 Configuring SSH2
      • 9.2.1 Enabling and Disabling SSH by Generating and Deleting Host Keys
        • 9.2.1.1 Generating a DSA or RSA Key Pair
        • 9.2.1.2 Deleting DSA and RSA Key Pairs
        • 9.2.1.3 Providing the Public Key to Clients
      • 9.2.2 Configuring DSA or RSA Challenge-Response Authentication
        • 9.2.2.1 Import Authorized Public Keys into the ICX Device
        • 9.2.2.2 Enable DSA or RSA Challenge-Response and Password Authentication
      • 9.2.3 Deleting the Public Keys
    • 9.3 Optional Parameters Overview
      • 9.3.1 SSH Rekey Configuration Notes
      • 9.3.2 Set Optional Parameters
    • 9.4 Filtering SSH Access Using ACLs
    • 9.5 Terminating an Active SSH Connection
    • 9.6 SSH2 Client
      • 9.6.1 Enabling SSH2 Client
      • 9.6.2 Configuring SSH2 Client Public Key Authentication
        • 9.6.2.1 Generating and Deleting a Client DSA Key Pair
        • 9.6.2.2 Generating and Deleting a Client RSA Key Pair
        • 9.6.2.3 Exporting Client Public Keys
      • 9.6.3 Establishing an SSH2 Client Connection
    • 9.7 Displaying SSH Information
  • SCP client support
    • 10 SCP Client Support
      • 10.1 SCP Client
      • 10.2 SCP Client Support Limitations
      • 10.3 Supported SCP Client Configurations
      • 10.4 Downloading an Image from an SCP Server
      • 10.5 Uploading an Image to an SCP Server
      • 10.6 Uploading Configuration Files to an SCP Server
      • 10.7 Downloading Configuration Files from an SCP Server
      • 10.8 Copying an Image between Devices
      • 10.9 Secure Copy with SSH2
        • 10.9.1 Enabling and Disabling SCP
        • 10.9.2 Secure copy configuration notes
        • 10.9.3 Example File Transfers Using SCP
          • 10.9.3.1 Copying a File to the running-config
          • 10.9.3.2 Copying a File to the startup config
          • 10.9.3.3 Copying the running-config File to an SCP-enabled Client
          • 10.9.3.4 Copying the startup config File to an SCP-enabled Client
          • 10.9.3.5 Copying a Software Image File to Flash Memory
          • 10.9.3.6 Copying a Software Image File from Flash Memory
          • 10.9.3.7 Importing a Digital Certificate Using SCP
          • 10.9.3.8 Importing an RSA Private Key
          • 10.9.3.9 Importing a DSA or RSA Public Key
          • 10.9.3.10 Copying License Files
  • 11 ACLs
    • 11.1 Layer 3 ACL Overview
      • 11.1.1 ACL Scaling
      • 11.1.2 Default ACL Action
      • 11.1.3 How Hardware-based ACLs Work
      • 11.1.4 How Fragmented Packets Are Processed
    • 11.2 IPv4 ACLs
      • 11.2.1 IPv4 ACL Configuration Guidelines
      • 11.2.2 Creating and Applying a Standard IPv4 ACL
      • 11.2.3 IPv4 Extended ACL Traffic Filtering Criteria
      • 11.2.4 Creating and Applying an Extended IPv4 ACL
      • 11.2.5 Applying Egress ACLs to Control (CPU) Traffic
      • 11.2.6 Preserving User Input for ACL TCP/UDP Port Numbers
      • 11.2.7 Enabling Strict Control of ACL Filtering of Fragmented Packets
      • 11.2.8 Filtering on IP Precedence and ToS Values
      • 11.2.9 ACLs to Filter ARP Packets
        • 11.2.9.1 Configuration Considerations for Filtering ARP Packets
        • 11.2.9.2 Configuring ACLs for ARP Filtering
        • 11.2.9.3 Displaying ACL Filters for ARP
        • 11.2.9.4 Clearing the Filter Count
      • 11.2.10 QoS Options for IP ACLs
        • 11.2.10.1 Configuration Notes for QoS Options
        • 11.2.10.2 Using a Combined ACL for 802.1p Marking
        • 11.2.10.3 Configuring QoS Priority for a VLAN
        • 11.2.10.4 DSCP Matching
      • 11.2.11 ACL-based Rate Limiting
      • 11.2.12 ACLs to Control Multicast Features
      • 11.2.13 Displaying IPv4 ACL Information
    • 11.3 IPv6 ACLs
      • 11.3.1 IPv6 ACL Traffic Filtering Criteria
      • 11.3.2 IPv6 Protocol Names and Numbers
      • 11.3.3 Default and Implicit IPv6 ACL Action
      • 11.3.4 IPv6 ACL Configuration Notes
      • 11.3.5 Creating and Applying an IPv6 ACL
      • 11.3.6 Neighbor Discovery (ND)-Packet DoS Attacks
      • 11.3.7 Displaying IPv6 ACLs
    • 11.4 Applying an ACL to a LAG Interface
    • 11.5 Applying ACLs to VLANs
    • 11.6 ACL Logging
      • 11.6.1 Configuration Notes for ACL Logging
      • 11.6.2 Enabling ACL Logging
    • 11.7 ACL Statistics
    • 11.8 ACL Accounting
      • 11.8.1 Changing the Accounting Period
      • 11.8.2 Configuring ACL Accounting
    • 11.9 Adding a Comment for an Entry in an ACL
      • 11.9.1 Deleting a Comment from an ACL Entry
      • 11.9.2 Viewing Comments in an ACL
    • 11.10 Sequence-based ACL Editing
      • 11.10.1 Inserting Rules into ACLs
      • 11.10.2 Deleting Rules from ACLs
    • 11.11 Displaying TCAM Information for ACLs
  • 12 MAC ACLs
    • 12.1 Layer 2 ACL Overview
    • 12.2 MAC Scaling by ICX Device
    • 12.3 MAC ACL Default Action
    • 12.4 MAC ACL Configuration Notes and Limitations
    • 12.5 Configuring and Applying MAC ACLs
    • 12.6 Displaying MAC ACL Information
  • SS_Policy-Based Routing
    • 13 Policy-Based Routing
      • 13.1 Policy-Based Routing Overview
      • 13.2 Route Maps
      • 13.3 Configuration Guidelines for IPv4 PBR
        • 13.3.1 Configuring an IPv4 PBR Policy with an IPv4 Address as the Next Hop
        • 13.3.2 Configuring an IPv4 PBR Policy with the NULL0 Interface as the Next Hop
        • 13.3.3 Configuring an IPv4 PBR Policy with a Tunnel as the Next Hop
        • 13.3.4 Configuring an IPv4 PBR Policy by Setting a VRF-aware Next Hop in a Route Map
        • 13.3.5 Displaying IPv4 PBR Information
      • 13.4 Configuration Guidelines for IPv6 PBR
        • 13.4.1 Configuring an IPv6 PBR Policy with an IPv6 Address as the Next Hop
        • 13.4.2 Configuring an IPv6 PBR Policy with the NULL0 Interface as the Next Hop
        • 13.4.3 Configuring an IPv6 PBR Policy with a Tunnel as the Next Hop
        • 13.4.4 Displaying IPv6 PBR Information
  • MACsec Key-Based Security
    • 14 Media Access Control Security
      • 14.1 MACsec Overview
      • 14.2 How MACsec Works
        • 14.2.1 MACsec Frame Format
      • 14.3 Configuring MACsec
      • 14.4 Enabling MACsec and Configuring Group Parameters
        • 14.4.1 Configuring MACsec Key-Server Priority
        • 14.4.2 Configuring MACsec Integrity and Encryption
        • 14.4.3 Configuring MACsec Frame Validation
        • 14.4.4 Configuring Replay Protection
      • 14.5 Enabling and Configuring Group Interfaces for MACsec
        • 14.5.1 Configuring the Pre-shared Key
      • 14.6 Sample MACsec Configuration
      • 14.7 Displaying MACsec Information
        • 14.7.1 Displaying MACsec Configuration Details
        • 14.7.2 Displaying Information on Current MACsec Sessions
        • 14.7.3 Displaying MKA Protocol Statistics for an Interface
        • 14.7.4 Displaying MACsec Secure Channel Activity for an Interface
  • Port MAC Security
    • 15 Port MAC Security (PMS)
      • 15.1 Port MAC Security Overview
        • 15.1.1 Local and Global Resources Used for Port MAC Security
        • 15.1.2 Configuration Considerations for Port MAC Security
        • 15.1.3 Secure MAC Movement
      • 15.2 Port MAC Security Configuration
      • 15.3 Configuring Port MAC Security
      • 15.4 Clearing Port Security Statistics
        • 15.4.1 Clearing Restricted MAC Addresses
        • 15.4.2 Clearing Violation Statistics
      • 15.5 Displaying Port MAC Security Information
  • 16 Flexible Authentication
    • 16.1 Flexible Authentication Overview
      • 16.1.1 MAC VLANs
      • 16.1.2 Data VLAN Requirements for Flexible Authentication
      • 16.1.3 Voice VLAN Requirements for Flexible Authentication
      • 16.1.4 Authentication Modes
      • 16.1.5 Tagged VM Client Support
      • 16.1.6 Static Authentication with MAC Authentication Filters
      • 16.1.7 Authentication Actions
        • 16.1.7.1 Authentication Timeout Action
      • 16.1.8 Authentication Session Limits on an Interface
      • 16.1.10 How Flexible Authentication Works
      • 16.1.11 Configuration Considerations and Guidelines for Flexible Authentication
    • 16.2 802.1X Authentication
      • 16.2.1 Device Roles in an 802.1X Configuration
      • 16.2.2 Communication between the Devices
      • 16.2.3 Controlled and Uncontrolled Ports
      • 16.2.4 Port Control for Authentication
      • 16.2.5 Message Exchange During Authentication
        • 16.2.5.1 EAP Pass-Through Support
    • 16.3 MAC Authentication
      • 16.3.1 MAC Address Formats Sent to the RADIUS Server
      • 16.3.2 Authenticating Multiple Hosts Connected to the Same Port
      • 16.3.3 How Flexible Authentication Works for Multiple Clients
      • 16.3.4 Flexible Authentication Accounting
      • 16.3.5 Change of Authorization
      • 16.3.6 Multiple RADIUS Servers
      • 16.3.8 Session Aging
      • 16.3.9 Periodic Reauthentication of Authenticated Clients
      • 16.3.10 Denial of Service Protection Support
      • 16.3.11 SNMP Traps for Flexible Authentication
      • 16.3.12 Syslog Messages for Flexible Authentication
    • 16.4 RADIUS Attributes for Authentication and Accounting
    • 16.5 Configuring ICX Vendor-Specific Attributes on the RADIUS Server
    • 16.6 Support for the RADIUS User-name attribute in Access-Accept Messages
    • 16.7 Dynamic VLAN Assignment
      • 16.7.1 Configuring the RADIUS Server to Support Dynamic VLAN Assignment for Authentication
      • 16.7.2 Authentication Success Scenarios
      • 16.7.3 Authentication Failure Scenarios
      • 16.7.4 Authentication Server Timeout Scenarios
      • 16.7.5 Authentication Client Timeout Scenarios (No Response to EAP Packets)
      • 16.7.6 Automatic Removal of Dynamic VLAN Assignments for 802.1X and MAC Authenticated Ports
    • 16.8 Dynamic ACLs in Authentication
      • 16.8.1 Configuration Guidelines for Dynamic ACLs
      • 16.8.2 Dynamically Applying Existing ACLs
    • 16.9 Support for IP Source Guard Protection
    • 16.10 Configuring Flexible Authentication
      • 16.10.1 Flexible Authentication Configuration Prerequisites
      • 16.10.2 Configuring Flexible Authentication Globally
      • 16.10.3 Configuring Flexible Authentication on an Interface
      • 16.10.4 Enabling 802.1X Authentication
      • 16.10.5 Enabling MAC Authentication
      • 16.10.6 Excluding the RADIUS Server for Login Features
    • 16.11 Displaying Authentication Information
      • 16.11.1 Displaying Configuration
      • 16.11.2 Displaying Statistics
      • 16.11.3 Displaying the Authentication Sessions
      • 16.11.4 Displaying Information about User ACLs
      • 16.11.5 Displaying Dynamically Assigned VLAN Information
    • 16.12 Clearing Authentication Details
  • 17 IPsec
    • 17.1 IPsec Overview
      • 17.1.1 Acronyms
      • 17.1.2 Establishment of an IPsec Tunnel
      • 17.1.3 Configuration of an IPsec Tunnel
      • 17.1.4 Configuration of Traffic to Route over an IPsec Tunnel
      • 17.1.5 Supported Algorithms
      • 17.1.6 Support for PSK for IKEv2 SAs
      • 17.1.7 Unicast IPv4 over IPsec Tunnels
      • 17.1.8 IPv6 over IPsec Tunnels
      • 17.1.9 IPsec Scalability Limits
      • 17.1.10 Supported Features and Functionality
      • 17.1.11 Unsupported Features
      • 17.1.12 Limitations
      • 17.1.13 IKEv2 Traps
      • 17.1.14 IPsec Traps
      • 17.1.15 IPSec over NAT
      • 17.1.16 Downgrade Considerations
    • 17.2 Configuring Global Parameters for IKEv2
    • 17.3 Configuring an IKEv2 Proposal
    • 17.4 Configuring an IKEv2 Policy
    • 17.5 Configuring an IKEv2 Authentication Proposal
    • 17.6 Configuring an IKEv2 Profile
    • 17.7 Configuring an IPsec Proposal
    • 17.8 Configuring an IPsec Profile
    • 17.9 Activating an IPsec Profile on a VTI
    • 17.10 Routing Traffic over IPsec Using Static Routing
    • 17.11 Routing Traffic over an IPsec Tunnel Using PBR
    • 17.12 Re-establishing SAs
    • 17.13 Enabling IKEv2 Extended Logging
    • 17.14 Disabling Traps and Syslog Messages for IKEv2 and IPsec
    • 17.15 Displaying IPsec Module Information
    • 17.16 Displaying IKEv2 Configuration Information
    • 17.17 Displaying IPsec Configuration Information
    • 17.18 Displaying and Clearing Statistics for IKEv2 and IPsec
    • 17.19 Configuration Example for an IPsec Tunnel Using Default Settings (Site-to-Site VPN)
    • 17.20 Configuration Example for a Hub-to-Spoke VPN Using IPsec
    • 17.21 Configuration Example for an IPsec Tunnel in an IPsec Tunnel
    • 17.22 PKI Support for IPsec
      • 17.22.1 Certificates
      • 17.22.2 Certificate Authority
      • 17.22.3 Certificate Revocation List
      • 17.22.4 CRL Distribution Point
      • 17.22.5 Distinguished Name
      • 17.22.6 Entity
      • 17.22.7 Lightweight Directory Access Protocol
      • 17.22.8 PKI Repository
      • 17.22.9 Registration Authority
      • 17.22.10 Requester
      • 17.22.11 Certificate Enrollment Using SCEP
        • 17.22.11.1 Types of Enrollment
        • 17.22.11.2 Requirements for Requesting a Certificate
        • 17.22.11.3 Communications Between Requesters and the CA
      • 17.22.12 Configuring PKI
        • 17.22.12.1 Configuring an Entity Distinguished Name
        • 17.22.12.2 Creating a Trustpoint
        • 17.22.12.3 Configuring CA Authentication
        • 17.22.12.4 Generating a Certificate Request
        • 17.22.12.5 Extended Key Usage
        • 17.22.12.6 Creating a PKI Enrollment Profile
        • 17.22.12.7 Installing Identity Certificates
        • 17.22.12.8 Clearing the Certificate Revocation List (CRL) and PKI Counters
        • 17.22.12.9 Enabling PKI Logging
        • 17.22.12.10 Displaying PKI Information
  • HTTP and HTTPS Authentication
    • 18 HTTP and HTTPS
      • 18.1 Web Authentication Overview
      • 18.2 Captive Portal Authentication (External Web Authentication)
        • 18.2.1 Captive Portal Profile for External Web Authentication
        • 18.2.2 Captive Portal on a VLAN
        • 18.2.3 Dynamic IP ACLs in Web Authentication
        • 18.2.4 Configuration Considerations for Applying IP ACLs
        • 18.2.5 Dynamically Applying Existing ACLs
        • 18.2.6 RADIUS Attribute for Session Timeout
      • 18.3 Web Authentication Configuration Considerations
      • 18.4 Web Authentication Configuration Tasks
      • 18.5 Prerequisites for Captive Portal Support with RUCKUS Cloudpath
      • 18.6 Prerequisites for Configuring Captive Portal with Aruba ClearPass
      • 18.7 Prerequisites for Configuring External Web Authentication with Cisco ISE
      • 18.8 Prerequisite Configurations on an ICX Switch for Captive Portal Authentication
      • 18.9 Creating the Captive Portal Profile for External Web Authentication
      • 18.10 Configuring Captive Portal (External Web Authentication)
      • 18.11 Enabling and Disabling Web Authentication
      • 18.12 Web Authentication Mode Configuration
        • 18.12.1 Using Local User Databases
          • 18.12.1.1 Configuring a Local User Database
          • 18.12.1.2 Creating a Local User Database
          • 18.12.1.3 Adding a User Record to a Local User Database
          • 18.12.1.4 Deleting a User Record from a Local User Database
          • 18.12.1.5 Deleting All User Records from a Local User Database
          • 18.12.1.6 Creating a Text File of User Records
          • 18.12.1.7 Importing a Text File of User Records from a TFTP Server
          • 18.12.1.8 Using a RADIUS Server as the Web Authentication Method
          • 18.12.1.9 Setting the Local User Database Authentication Method
          • 18.12.1.10 Setting the Web Authentication Failover Sequence
          • 18.12.1.11 Assigning a Local User Database to a Web Authentication VLAN
        • 18.12.2 Passcodes for User Authentication
          • 18.12.2.1 Configuring Passcode Authentication
          • 18.12.2.2 Creating Static Passcodes
          • 18.12.2.3 Enabling Passcode Authentication
          • 18.12.2.4 Configuring the Length of Dynamically Generated Passcodes
          • 18.12.2.5 Configuring the Passcode Refresh Method
          • 18.12.2.6 Configuring a Grace Period for an Expired Passcode
          • 18.12.2.7 Flushing All Expired Passcodes that Are in the Grace Period
          • 18.12.2.8 Disabling and Re-enabling Passcode Logging
          • 18.12.2.9 Resending the Passcode Log Message
          • 18.12.2.10 Manually Refreshing the Passcode
        • 18.12.3 Automatic Authentication
      • 18.13 Web Authentication Options
        • 18.13.1 Enabling RADIUS Accounting for Web Authentication
        • 18.13.2 Changing the Login Mode (HTTPS or HTTP)
        • 18.13.3 Specifying Trusted Ports
        • 18.13.4 Specifying Hosts that Are Permanently Authenticated
        • 18.13.5 Configuring the Re-authentication Period
        • 18.13.6 Defining the Web Authentication Cycle
        • 18.13.7 Limiting the Number of Web Authentication Attempts
        • 18.13.8 Clearing Authenticated Hosts from the Web Authentication Table
        • 18.13.9 Setting and Clearing the Block Duration for Web Authentication Attempts
        • 18.13.10 Manually Blocking and Unblocking a Specific Host
        • 18.13.11 Limiting the Number of Authenticated Hosts
        • 18.13.12 Filtering DNS Queries
        • 18.13.13 Forcing Re-authentication When Ports Are Down
        • 18.13.14 Forcing Re-authentication After an Inactive Period
        • 18.13.15 Defining the Web Authorization Redirect Address
        • 18.13.16 Deleting a Web Authentication VLAN
        • 18.13.17 Web Authentication Pages
          • 18.13.17.1 Displaying Text for Web Authentication Pages
          • 18.13.17.2 Customizing Web Authentication Pages
      • 18.14 Image Download over HTTPS
      • 18.15 Configuration Download over HTTPS
      • 18.16 Configuration Upload over HTTPS
      • 18.17 Displaying Web Authentication Information
        • 18.17.1 Displaying the Web Authentication Configuration
        • 18.17.2 Displaying a List of Authenticated Hosts
        • 18.17.3 Displaying a List of Hosts Attempting to Authenticate
        • 18.17.4 Displaying a List of Blocked Hosts
        • 18.17.5 Displaying a List of Local User Databases
        • 18.17.6 Displaying a List of Users in a Local User Database
        • 18.17.7 Displaying Passcodes
        • 18.17.8 Displaying Captive Portal Profile Details
  • Denial of Service Protection
    • 19 Protecting against Denial of Service Attacks
      • 19.1 Denial of Service Protection Overview
      • 19.2 Protecting against Smurf Attacks
        • 19.2.1 Avoiding Being an Intermediary in a Smurf Attack
        • 19.2.2 Avoiding Being a Victim in a Smurf Attack
          • 19.2.2.1 Configuring Threshold Values for ICMP Packets Globally
          • 19.2.2.2 Configuring ICMP Threshold Values on an Interface
      • 19.3 Protecting against TCP SYN Attacks
        • 19.3.1 Configuring Threshold Values for TCP SYN Packets Globally
        • 19.3.2 Configuring TCP SYN Threshold Values on an Interface
        • 19.3.3 TCP MSS Adjustment Overview
        • 19.3.4 Example
        • 19.3.5 Impact on Existing Functionality
        • 19.3.6 DDOS Limitations
        • 19.3.7 TCP MSS Adjustment Limitations
      • 19.4 Displaying Statistics from a DoS Attack
      • 19.5 Clear DoS Attack Statistics
  • 20 IPv6 RA Guard
    • 20.1 Securing IPv6 Address Configuration
    • 20.2 IPv6 RA Guard Overview
      • 20.2.1 RA Guard Policy
      • 20.2.2 Whitelist
      • 20.2.3 Prefix List
      • 20.2.4 Maximum Preference
      • 20.2.5 Trusted, Untrusted, and Host Ports
    • 20.3 Configuration Notes and Feature Limitations for IPv6 RA Guard
    • 20.4 Configuring IPv6 RA Guard
    • 20.5 Example of Configuring IPv6 RA Guard
      • 20.5.1 Example: Configuring IPv6 RA Guard on a Device
      • 20.5.2 Example: Configuring IPv6 RA Guard in a Network
      • 20.5.3 Example: Verifying the RA Guard Configuration
  • 21 Joint Interoperability Test Command
    • 21.1 JITC Overview
  • OpenSSL Acknowledgements
    • 22 OpenSSL License
      • 22.1 OpenSSL License
  • 23 Keychain Module
    • 23.1 Keychain Module Overview
      • 23.1.1 Components of a Keychain
      • 23.1.2 OSPF Keychain Authentication
      • 23.1.3 Configuring a Keychain Module

TACACS+ Server Authentication

In this section:

  1. TACACS and TACACS+ Security
  2. TACACS/TACACS+ Authentication, Authorization, and Accounting
  3. TACACS and TACACS+ Configuration
  4. Displaying TACACS/TACACS+ Statistics and Configuration Information

Did you find what you were looking for?

Thanks!

Ruckus Wireless

© 2026 Ruckus Wireless LLC All rights reserved.

  • Accessibility
  • Privacy & Cookies
  • Do Not Sell My Information
  • Trademarks
  • Terms
  • Feedback