New in this Document

The following table describes changes to this guide for the FastIron 08.0.95 release.

Summary of Changes in FastIron Release 08.0.95j

Feature

Description

Reference

Updates to address defects Updated: Minor updates have been introduced throughout the guide to address defects. All chapters
Minor editorial updates Updated: Minor editorial updates were made throughout the guide. All chapters

Summary of Changes in FastIron Release 08.0.95h

Feature

Description

Reference

SSH The ip ssh disable command is introduced in this release only. Enabling and Disabling SSH by Generating and Deleting Host Keys

Summary of Changes in FastIron Release 08.0.95a

Feature

Description

Reference

ICX 7550 devices Support for RUCKUS ICX 7550 Series Switches is added with this release. Updates occur throughout the guide.

Summary of Changes in FastIron Release 08.0.95

Feature

Description

Reference

ACL unified architecture Configuring and applying access-control lists (ACLs) has been made more consistent for IPv4 ACLs, IPv6 ACLs, and MAC ACLs (formerly MAC filters). Refer to:

IPv4 ACLs

IPv6 ACLs

MAC ACLs.

DDOS changes DDOS configuration changes to the VLAN level, rather than the VE level. The ip icmp attack-rate and ip tcp burst-normal commands have been updated. Refer to Avoiding Being a Victim in a Smurf Attack, Protecting against TCP SYN Attacks, and the RUCKUS FastIron Command Reference.
DHCP changes A number of changes and enhancements have been introduced for DHCP and DHCPv6 Snooping as a result of ACL rearchitecture. Refer to the RUCKUS FastIron DHCP Configuration Guide.
Flexible authentication change The authentication auth-filter command is deprecated and replaced by the authentication filter command, which allows configuration of a filter to override 802.1x authentication for specified MAC addresses. Refer to Static Authentication with MAC Filters and Configuring Flexible Authentication on an Interface.
ICX 7550 devices Support for ICX devices is added with this release. Updates occur throughout the guide.
ICX 7550 MACsec support ICX 7550 devices with an appropriate license support MACsec on Module 2 ports. Refer to Media Access Control Security.
IP Source Guard changes A number of changes and enhancements have been introduced for IPSG ACLs. Refer to "IP Source Guard" in the RUCKUS FastIron DHCP Configuration Guide.
ND hop limit checking ND-packet hop-limit checking is enabled by default and no longer requires configuration. The command enable nd-hop-limit is deprecated. Related configuration information has been removed.
PBR changes The show policy-routing command has been introduced. Refer to Displaying IPv4 PBR Information and Displaying IPv6 PBR Information as well as the RUCKUS FastIron Command Reference
IPv6 RA Guard support

All ACL unified architecture features are supported with RA Guard. Previously, MAC filters and MAC-bsed VLANs were not supported with IPv6 RA Guard.

The following command is added: show ipv6 raguard vlan

The former command raguard untrusted was modified to raguard untrust

The command show ipv6 raguard all is deprecated.

Refer to IPv6 RA Guard.

For more information on commands, refer to the RUCKUS FastIron Command Reference.