RUCKUS FastIron Security Configuration Guide, 08.0.95
- 1 Vistance Legal Statements
- Preface Ruckus
- About This Document
- 4 About This Document
- 5 Managing User Accounts
- 5.1 User Accounts Overview
- 5.2 Configuring Local User Accounts
- 5.3 Recovering from a Lost Password
- 5.4 Enabling Device Access Methods
- 5.5 Remote Access For Managing Devices
- 5.5.1 Remote Access Configuration Using Telnet
- 5.5.1.1 Configuring Telnet Remote Access
- 5.5.2 Remote Access Configuration Using SSH
- 5.5.3 Using an IP Address to Restrict Remote Access
- 5.5.4 Using an IP or MAC Address to Restrict Remote Access
- 5.5.5 ACL Usage to Restrict Remote Access
- 5.5.6 Restricting Remote Access to the Device to Specific VLAN IDs
- 5.5.7 Designated VLAN for Management Sessions to a Layer 2 Switch
- 5.5.8 Disabling Remote Access Methods
- 5.5.1 Remote Access Configuration Using Telnet
- 6 TACACS+ Server Authentication
- 6.1 TACACS and TACACS+ Security
- 6.2 TACACS/TACACS+ Authentication, Authorization, and Accounting
- 6.3 TACACS and TACACS+ Configuration
- 6.3.1 TACACS/TACACS+ Configuration Considerations
- 6.3.2 Identifying the TACACS/TACACS+ Servers
- 6.3.3 Specifying Different Servers for Individual AAA Functions
- 6.3.4 Setting Optional TACACS and TACACS+ Parameters
- 6.3.4.1 Setting the TACACS+ Key
- 6.3.4.2 Setting the Retransmission Limit
- 6.3.4.3 Setting the Timeout Parameter
- 6.3.4.4 Enabling Management Access Based on a Port-based VLAN
- 6.3.5 Configuring Authentication-method Lists for TACACS and TACACS+
- 6.3.6 Configuring TACACS+ Authorization
- 6.3.6.1 Configuring Exec Authorization
- 6.3.6.2 Configuring Command Authorization
- 6.3.7 TACACS+ Accounting Configuration
- 6.3.8 Configuring an Interface as the Source for All TACACS and TACACS+ Packets
- 6.3.9 Configuring TACACS/TACACS+ for Devices in a Traditional Stack
- 6.3.10 TACACS Configuration Example
- 6.3.11 TACACS+ Configuration Example
- 6.4 Displaying TACACS/TACACS+ Statistics and Configuration Information
- 7 RADIUS Authentication
- 7.1 RADIUS Security
- 7.2 RADIUS Configuration Considerations
- 7.3 Configuring RADIUS (Overview)
- 7.4 Configuring Company-Specific Attributes on the RADIUS Server
- 7.5 Identifying the RADIUS Server to the Ruckus Device
- 7.6 Specifying Different Servers for Individual AAA Functions
- 7.7 Mapping RADIUS Servers to Ports
- 7.8 RADIUS Configuration Example
- 7.9 Setting Up RADIUS over IPv6
- 7.10 Setting RADIUS Parameters
- 7.11 Configuring Detection of Dead RADIUS Servers
- 7.12 Source Address Configuration for RADIUS Packets
- 7.13 Configuring Authentication-method Lists for RADIUS
- 7.14 RADIUS Authorization
- 7.15 RADIUS Accounting
- 7.16 Displaying RADIUS Configuration Information
- 8 Security Vulnerability
- 8.1 SSL Security
- 8.1.1 Enabling the SSL Server on the Device
- 8.1.2 Specifying a Port for SSL Communication
- 8.1.3 Changing the SSL Server Certificate Key Size
- 8.1.4 Support for SSL Digital Certificates Larger than 2048 Bits
- 8.1.5 Importing Digital Certificates and RSA Private Key Files
- 8.1.6 Generating an SSL Certificate
- 8.1.7 Deleting the SSL Certificate
- 8.2 TLS Support
- 8.3 Authentication-method Lists
- 8.1 SSL Security
- 9 Secure Shell (SSH)
- 9.1 SSH Version 2 Overview
- 9.1.1 Tested SSH2 Clients
- 9.1.2 SSH2 Supported Features
- 9.1.3 SSH2 Unsupported Features
- 9.1.4 SSH2 Authentication Types
- 9.2 Configuring SSH2
- 9.3 Optional Parameters Overview
- 9.3.1 SSH Rekey Configuration Notes
- 9.3.2 Set Optional Parameters
- 9.4 Filtering SSH Access Using ACLs
- 9.5 Terminating an Active SSH Connection
- 9.6 SSH2 Client
- 9.7 Displaying SSH Information
- 9.1 SSH Version 2 Overview
- SCP client support
- 10 SCP Client Support
- 10.1 SCP Client
- 10.2 SCP Client Support Limitations
- 10.3 Supported SCP Client Configurations
- 10.4 Downloading an Image from an SCP Server
- 10.5 Uploading an Image to an SCP Server
- 10.6 Uploading Configuration Files to an SCP Server
- 10.7 Downloading Configuration Files from an SCP Server
- 10.8 Copying an Image between Devices
- 10.9 Secure Copy with SSH2
- 10.9.1 Enabling and Disabling SCP
- 10.9.2 Secure copy configuration notes
- 10.9.3 Example File Transfers Using SCP
- 10.9.3.1 Copying a File to the running-config
- 10.9.3.2 Copying a File to the startup config
- 10.9.3.3 Copying the running-config File to an SCP-enabled Client
- 10.9.3.4 Copying the startup config File to an SCP-enabled Client
- 10.9.3.5 Copying a Software Image File to Flash Memory
- 10.9.3.6 Copying a Software Image File from Flash Memory
- 10.9.3.7 Importing a Digital Certificate Using SCP
- 10.9.3.8 Importing an RSA Private Key
- 10.9.3.9 Importing a DSA or RSA Public Key
- 10.9.3.10 Copying License Files
- 10 SCP Client Support
- 11 ACLs
- 11.1 Layer 3 ACL Overview
- 11.1.1 ACL Scaling
- 11.1.2 Default ACL Action
- 11.1.3 How Hardware-based ACLs Work
- 11.1.4 How Fragmented Packets Are Processed
- 11.2 IPv4 ACLs
- 11.2.1 IPv4 ACL Configuration Guidelines
- 11.2.2 Creating and Applying a Standard IPv4 ACL
- 11.2.3 IPv4 Extended ACL Traffic Filtering Criteria
- 11.2.4 Creating and Applying an Extended IPv4 ACL
- 11.2.5 Applying Egress ACLs to Control (CPU) Traffic
- 11.2.6 Preserving User Input for ACL TCP/UDP Port Numbers
- 11.2.7 Enabling Strict Control of ACL Filtering of Fragmented Packets
- 11.2.8 Filtering on IP Precedence and ToS Values
- 11.2.9 ACLs to Filter ARP Packets
- 11.2.9.1 Configuration Considerations for Filtering ARP Packets
- 11.2.9.2 Configuring ACLs for ARP Filtering
- 11.2.9.3 Displaying ACL Filters for ARP
- 11.2.9.4 Clearing the Filter Count
- 11.2.10 QoS Options for IP ACLs
- 11.2.10.1 Configuration Notes for QoS Options
- 11.2.10.2 Using a Combined ACL for 802.1p Marking
- 11.2.10.3 Configuring QoS Priority for a VLAN
- 11.2.10.4 DSCP Matching
- 11.2.11 ACL-based Rate Limiting
- 11.2.12 ACLs to Control Multicast Features
- 11.2.13 Displaying IPv4 ACL Information
- 11.3 IPv6 ACLs
- 11.4 Applying an ACL to a LAG Interface
- 11.5 Applying ACLs to VLANs
- 11.6 ACL Logging
- 11.6.1 Configuration Notes for ACL Logging
- 11.6.2 Enabling ACL Logging
- 11.7 ACL Statistics
- 11.8 ACL Accounting
- 11.8.1 Changing the Accounting Period
- 11.8.2 Configuring ACL Accounting
- 11.9 Adding a Comment for an Entry in an ACL
- 11.10 Sequence-based ACL Editing
- 11.10.1 Inserting Rules into ACLs
- 11.10.2 Deleting Rules from ACLs
- 11.11 Displaying TCAM Information for ACLs
- 11.1 Layer 3 ACL Overview
- 12 MAC ACLs
- SS_Policy-Based Routing
- 13 Policy-Based Routing
- 13.1 Policy-Based Routing Overview
- 13.2 Route Maps
- 13.3 Configuration Guidelines for IPv4 PBR
- 13.3.1 Configuring an IPv4 PBR Policy with an IPv4 Address as the Next Hop
- 13.3.2 Configuring an IPv4 PBR Policy with the NULL0 Interface as the Next Hop
- 13.3.3 Configuring an IPv4 PBR Policy with a Tunnel as the Next Hop
- 13.3.4 Configuring an IPv4 PBR Policy by Setting a VRF-aware Next Hop in a Route Map
- 13.3.5 Displaying IPv4 PBR Information
- 13.4 Configuration Guidelines for IPv6 PBR
- 13 Policy-Based Routing
- MACsec Key-Based Security
- 14 Media Access Control Security
- Port MAC Security
- 16 Flexible Authentication
- 16.1 Flexible Authentication Overview
- 16.1.1 MAC VLANs
- 16.1.2 Data VLAN Requirements for Flexible Authentication
- 16.1.3 Voice VLAN Requirements for Flexible Authentication
- 16.1.4 Authentication Modes
- 16.1.5 Tagged VM Client Support
- 16.1.6 Static Authentication with MAC Authentication Filters
- 16.1.7 Authentication Actions
- 16.1.7.1 Authentication Timeout Action
- 16.1.8 Authentication Session Limits on an Interface
- 16.1.10 How Flexible Authentication Works
- 16.1.11 Configuration Considerations and Guidelines for Flexible Authentication
- 16.2 802.1X Authentication
- 16.3 MAC Authentication
- 16.3.1 MAC Address Formats Sent to the RADIUS Server
- 16.3.2 Authenticating Multiple Hosts Connected to the Same Port
- 16.3.3 How Flexible Authentication Works for Multiple Clients
- 16.3.4 Flexible Authentication Accounting
- 16.3.5 Change of Authorization
- 16.3.6 Multiple RADIUS Servers
- 16.3.8 Session Aging
- 16.3.9 Periodic Reauthentication of Authenticated Clients
- 16.3.10 Denial of Service Protection Support
- 16.3.11 SNMP Traps for Flexible Authentication
- 16.3.12 Syslog Messages for Flexible Authentication
- 16.4 RADIUS Attributes for Authentication and Accounting
- 16.5 Configuring ICX Vendor-Specific Attributes on the RADIUS Server
- 16.6 Support for the RADIUS User-name attribute in Access-Accept Messages
- 16.7 Dynamic VLAN Assignment
- 16.7.1 Configuring the RADIUS Server to Support Dynamic VLAN Assignment for Authentication
- 16.7.2 Authentication Success Scenarios
- 16.7.3 Authentication Failure Scenarios
- 16.7.4 Authentication Server Timeout Scenarios
- 16.7.5 Authentication Client Timeout Scenarios (No Response to EAP Packets)
- 16.7.6 Automatic Removal of Dynamic VLAN Assignments for 802.1X and MAC Authenticated Ports
- 16.8 Dynamic ACLs in Authentication
- 16.9 Support for IP Source Guard Protection
- 16.10 Configuring Flexible Authentication
- 16.10.1 Flexible Authentication Configuration Prerequisites
- 16.10.2 Configuring Flexible Authentication Globally
- 16.10.3 Configuring Flexible Authentication on an Interface
- 16.10.4 Enabling 802.1X Authentication
- 16.10.5 Enabling MAC Authentication
- 16.10.6 Excluding the RADIUS Server for Login Features
- 16.11 Displaying Authentication Information
- 16.11.1 Displaying Configuration
- 16.11.2 Displaying Statistics
- 16.11.3 Displaying the Authentication Sessions
- 16.11.4 Displaying Information about User ACLs
- 16.11.5 Displaying Dynamically Assigned VLAN Information
- 16.12 Clearing Authentication Details
- 16.1 Flexible Authentication Overview
- 17 IPsec
- 17.1 IPsec Overview
- 17.1.1 Acronyms
- 17.1.2 Establishment of an IPsec Tunnel
- 17.1.3 Configuration of an IPsec Tunnel
- 17.1.4 Configuration of Traffic to Route over an IPsec Tunnel
- 17.1.5 Supported Algorithms
- 17.1.6 Support for PSK for IKEv2 SAs
- 17.1.7 Unicast IPv4 over IPsec Tunnels
- 17.1.8 IPv6 over IPsec Tunnels
- 17.1.9 IPsec Scalability Limits
- 17.1.10 Supported Features and Functionality
- 17.1.11 Unsupported Features
- 17.1.12 Limitations
- 17.1.13 IKEv2 Traps
- 17.1.14 IPsec Traps
- 17.1.15 IPSec over NAT
- 17.1.16 Downgrade Considerations
- 17.2 Configuring Global Parameters for IKEv2
- 17.3 Configuring an IKEv2 Proposal
- 17.4 Configuring an IKEv2 Policy
- 17.5 Configuring an IKEv2 Authentication Proposal
- 17.6 Configuring an IKEv2 Profile
- 17.7 Configuring an IPsec Proposal
- 17.8 Configuring an IPsec Profile
- 17.9 Activating an IPsec Profile on a VTI
- 17.10 Routing Traffic over IPsec Using Static Routing
- 17.11 Routing Traffic over an IPsec Tunnel Using PBR
- 17.12 Re-establishing SAs
- 17.13 Enabling IKEv2 Extended Logging
- 17.14 Disabling Traps and Syslog Messages for IKEv2 and IPsec
- 17.15 Displaying IPsec Module Information
- 17.16 Displaying IKEv2 Configuration Information
- 17.17 Displaying IPsec Configuration Information
- 17.18 Displaying and Clearing Statistics for IKEv2 and IPsec
- 17.19 Configuration Example for an IPsec Tunnel Using Default Settings (Site-to-Site VPN)
- 17.20 Configuration Example for a Hub-to-Spoke VPN Using IPsec
- 17.21 Configuration Example for an IPsec Tunnel in an IPsec Tunnel
- 17.22 PKI Support for IPsec
- 17.22.1 Certificates
- 17.22.2 Certificate Authority
- 17.22.3 Certificate Revocation List
- 17.22.4 CRL Distribution Point
- 17.22.5 Distinguished Name
- 17.22.6 Entity
- 17.22.7 Lightweight Directory Access Protocol
- 17.22.8 PKI Repository
- 17.22.9 Registration Authority
- 17.22.10 Requester
- 17.22.11 Certificate Enrollment Using SCEP
- 17.22.11.1 Types of Enrollment
- 17.22.11.2 Requirements for Requesting a Certificate
- 17.22.11.3 Communications Between Requesters and the CA
- 17.22.12 Configuring PKI
- 17.22.12.1 Configuring an Entity Distinguished Name
- 17.22.12.2 Creating a Trustpoint
- 17.22.12.3 Configuring CA Authentication
- 17.22.12.4 Generating a Certificate Request
- 17.22.12.5 Extended Key Usage
- 17.22.12.6 Creating a PKI Enrollment Profile
- 17.22.12.7 Installing Identity Certificates
- 17.22.12.8 Clearing the Certificate Revocation List (CRL) and PKI Counters
- 17.22.12.9 Enabling PKI Logging
- 17.22.12.10 Displaying PKI Information
- 17.1 IPsec Overview
- HTTP and HTTPS Authentication
- 18 HTTP and HTTPS
- 18.1 Web Authentication Overview
- 18.2 Captive Portal Authentication (External Web Authentication)
- 18.3 Web Authentication Configuration Considerations
- 18.4 Web Authentication Configuration Tasks
- 18.5 Prerequisites for Captive Portal Support with RUCKUS Cloudpath
- 18.6 Prerequisites for Configuring Captive Portal with Aruba ClearPass
- 18.7 Prerequisites for Configuring External Web Authentication with Cisco ISE
- 18.8 Prerequisite Configurations on an ICX Switch for Captive Portal Authentication
- 18.9 Creating the Captive Portal Profile for External Web Authentication
- 18.10 Configuring Captive Portal (External Web Authentication)
- 18.11 Enabling and Disabling Web Authentication
- 18.12 Web Authentication Mode Configuration
- 18.12.1 Using Local User Databases
- 18.12.1.1 Configuring a Local User Database
- 18.12.1.2 Creating a Local User Database
- 18.12.1.3 Adding a User Record to a Local User Database
- 18.12.1.4 Deleting a User Record from a Local User Database
- 18.12.1.5 Deleting All User Records from a Local User Database
- 18.12.1.6 Creating a Text File of User Records
- 18.12.1.7 Importing a Text File of User Records from a TFTP Server
- 18.12.1.8 Using a RADIUS Server as the Web Authentication Method
- 18.12.1.9 Setting the Local User Database Authentication Method
- 18.12.1.10 Setting the Web Authentication Failover Sequence
- 18.12.1.11 Assigning a Local User Database to a Web Authentication VLAN
- 18.12.2 Passcodes for User Authentication
- 18.12.2.1 Configuring Passcode Authentication
- 18.12.2.2 Creating Static Passcodes
- 18.12.2.3 Enabling Passcode Authentication
- 18.12.2.4 Configuring the Length of Dynamically Generated Passcodes
- 18.12.2.5 Configuring the Passcode Refresh Method
- 18.12.2.6 Configuring a Grace Period for an Expired Passcode
- 18.12.2.7 Flushing All Expired Passcodes that Are in the Grace Period
- 18.12.2.8 Disabling and Re-enabling Passcode Logging
- 18.12.2.9 Resending the Passcode Log Message
- 18.12.2.10 Manually Refreshing the Passcode
- 18.12.3 Automatic Authentication
- 18.12.1 Using Local User Databases
- 18.13 Web Authentication Options
- 18.13.1 Enabling RADIUS Accounting for Web Authentication
- 18.13.2 Changing the Login Mode (HTTPS or HTTP)
- 18.13.3 Specifying Trusted Ports
- 18.13.4 Specifying Hosts that Are Permanently Authenticated
- 18.13.5 Configuring the Re-authentication Period
- 18.13.6 Defining the Web Authentication Cycle
- 18.13.7 Limiting the Number of Web Authentication Attempts
- 18.13.8 Clearing Authenticated Hosts from the Web Authentication Table
- 18.13.9 Setting and Clearing the Block Duration for Web Authentication Attempts
- 18.13.10 Manually Blocking and Unblocking a Specific Host
- 18.13.11 Limiting the Number of Authenticated Hosts
- 18.13.12 Filtering DNS Queries
- 18.13.13 Forcing Re-authentication When Ports Are Down
- 18.13.14 Forcing Re-authentication After an Inactive Period
- 18.13.15 Defining the Web Authorization Redirect Address
- 18.13.16 Deleting a Web Authentication VLAN
- 18.13.17 Web Authentication Pages
- 18.13.17.1 Displaying Text for Web Authentication Pages
- 18.13.17.2 Customizing Web Authentication Pages
- 18.14 Image Download over HTTPS
- 18.15 Configuration Download over HTTPS
- 18.16 Configuration Upload over HTTPS
- 18.17 Displaying Web Authentication Information
- 18.17.1 Displaying the Web Authentication Configuration
- 18.17.2 Displaying a List of Authenticated Hosts
- 18.17.3 Displaying a List of Hosts Attempting to Authenticate
- 18.17.4 Displaying a List of Blocked Hosts
- 18.17.5 Displaying a List of Local User Databases
- 18.17.6 Displaying a List of Users in a Local User Database
- 18.17.7 Displaying Passcodes
- 18.17.8 Displaying Captive Portal Profile Details
- 18 HTTP and HTTPS
- Denial of Service Protection
- 20 IPv6 RA Guard
- 20.1 Securing IPv6 Address Configuration
- 20.2 IPv6 RA Guard Overview
- 20.2.1 RA Guard Policy
- 20.2.2 Whitelist
- 20.2.3 Prefix List
- 20.2.4 Maximum Preference
- 20.2.5 Trusted, Untrusted, and Host Ports
- 20.3 Configuration Notes and Feature Limitations for IPv6 RA Guard
- 20.4 Configuring IPv6 RA Guard
- 20.5 Example of Configuring IPv6 RA Guard
- 21 Joint Interoperability Test Command
- 21.1 JITC Overview
- OpenSSL Acknowledgements
- 22 OpenSSL License
- 22.1 OpenSSL License
- 22 OpenSSL License
- 23 Keychain Module
- 23.1 Keychain Module Overview
- 23.1.1 Components of a Keychain
- 23.1.2 OSPF Keychain Authentication
- 23.1.3 Configuring a Keychain Module
- 23.1 Keychain Module Overview