Find Technical Content
  • Home
  • Ruckus Support Portal
  • Ruckus Networks
  • Table of Contents
  • Dark Mode

Powered by Titania Delivery

⚠ This cached page may be outdated. Click refresh to get the latest content.
Cached Version You are Offline

You are viewing a cached version of this page.

You are currently offline. This page was loaded from cache.

RUCKUS FastIron Security Configuration Guide, 09.0.10 53-1005727-25

  • 1 Vistance Legal Statements
  • Preface Ruckus
    • 3 Contact Information, Resources, and Conventions
      • 3.1 Contacting RUCKUS Customer Services and Support
      • 3.2 Document Feedback
      • 3.3 RUCKUS Product Documentation Resources
      • 3.4 Online Training Resources
      • 3.5 Document Conventions
      • 3.6 Command Syntax Conventions
  • About This Document
    • 4 About This Document
      • 4.1 New in this Document
      • 4.2 Supported Hardware
    • 5 Managing User Accounts
      • 5.1 User Accounts Overview
      • 5.2 Configuring Local User Accounts
        • 5.2.1 Configuring Advanced Local User Account Features
        • 5.2.2 Modifying Local User Account Passwords or Privileges
        • 5.2.3 Deleting Local User Accounts
      • 5.3 Enabling SSH Access
      • 5.4 Password and Device Recovery
  • 6 TACACS+ Server Authentication
    • 6.1 TACACS+ Security
      • 6.1.1 How TACACS+ Differs from TACACS
    • 6.2 TACACS+ Authentication, Authorization, and Accounting
      • 6.2.1 TACACS+ Authentication
      • 6.2.2 TACACS+ Authorization
      • 6.2.3 TACACS+ Accounting
      • 6.2.4 AAA Operations for TACACS+
        • 6.2.4.1 AAA Security for Commands Pasted into the running-config
    • 6.3 TACACS+ Configuration
      • 6.3.1 TACACS+ Configuration Considerations
      • 6.3.2 Identifying the TACACS+ Servers
      • 6.3.3 Configuring Authentication-method Lists for TACACS+
      • 6.3.4 Entering Privileged EXEC Mode after a Telnet or SSH Login
      • 6.3.5 Specifying Different Servers for Individual AAA Functions
      • 6.3.6 Setting Optional TACACS+ Parameters
        • 6.3.6.1 Setting the TACACS+ Key
        • 6.3.6.2 Setting the Retransmission Limit
        • 6.3.6.3 Setting the Timeout Parameter
      • 6.3.7 Configuring TACACS+ Authorization
        • 6.3.7.1 Configuring Exec Authorization
        • 6.3.7.2 Configuring Command Authorization
      • 6.3.8 TACACS+ Accounting Configuration
        • 6.3.8.1 Configuring TACACS+ Accounting for Telnet/SSH (Shell) Access
        • 6.3.8.2 Configuring TACACS+ Accounting for CLI Commands
        • 6.3.8.3 Configuring TACACS+ Accounting for System Events
      • 6.3.9 Configuring an Interface as the Source for All TACACS+ Packets
      • 6.3.10 Configuring TACACS+ for Devices in a Traditional Stack
      • 6.3.11 TACACS+ Configuration Example
    • 6.4 Displaying TACACS+ Statistics and Configuration Information
  • RADIUS Authentication
    • 7 RADIUS Authentication
      • 7.1 RADIUS Security
        • 7.1.1 RADIUS Authentication
        • 7.1.2 RADIUS Authorization
        • 7.1.3 RADIUS Accounting
        • 7.1.4 AAA Operations for RADIUS
        • 7.1.5 AAA Security for Commands Pasted into the running-config
      • 7.2 RADIUS Configuration Considerations
      • 7.3 Configuring RADIUS (Overview)
      • 7.4 Configuring Company-Specific Attributes on the RADIUS Server
      • 7.5 Identifying the RADIUS Server to the Ruckus Device
      • 7.6 Configuring an SSL Profile for Use with RADIUS Server Hosts
      • 7.7 Specifying Different Servers for Individual AAA Functions
      • 7.8 RADIUS Security Configuration Example
      • 7.9 Mapping RADIUS Servers to Ports
      • 7.10 RADIUS Configuration Example
      • 7.11 Setting Up RADIUS over IPv6
      • 7.12 Setting RADIUS Parameters
      • 7.13 Configuring Detection of Dead RADIUS Servers
      • 7.14 Source Address Configuration for RADIUS Packets
      • 7.15 Configuring Authentication-method Lists for RADIUS
        • 7.15.1 Authentication-Method Values
        • 7.15.2 Entering Privileged EXEC Mode after a Telnet or SSH Login
      • 7.16 RADIUS Authorization
        • 7.16.1 Configuring Exec Authorization
        • 7.16.2 Configuring Command Authorization
        • 7.16.3 Enabling RADIUS CoA and Disconnect Message Handling for Dynamic Authorization
          • 7.16.3.1 RADIUS Disconnect Message and CoA Events
          • 7.16.3.2 Supported IETF Attributes in RFC 5176
      • 7.17 RADIUS Accounting
        • 7.17.1 Configuring RADIUS Accounting for Telnet/SSH (Shell) Access
        • 7.17.2 Configuring RADIUS Accounting for CLI Commands
        • 7.17.3 Configuring RADIUS Accounting for System Events
        • 7.17.4 RADIUS Accounting for 802.1X Authentication and MAC Authentication
          • 7.17.4.1 Enabling RADIUS Accounting for 802.1X Authentication and MAC Authentication
      • 7.18 Displaying RADIUS Configuration Information
    • 8 Authentication-Method Lists
      • 8.1 Authentication-Method List Overview
        • 8.1.1 Configuration Considerations for Authentication-method Lists
        • 8.1.2 Examples of Authentication-method Lists
    • 9 ICX Digital Certificates
      • 9.1 Overview of ICX Digital Certificates
      • 9.2 SSL Security
        • 9.2.1 Enabling the SSL Server on the Device
        • 9.2.4 Importing Digital Certificates and RSA Private Key Files
        • 9.2.8 Displaying Information about ICX Digital Certificates
      • 9.3 TLS Support
  • Secure Shell (SSH)
    • 10 Secure Shell (SSH)
      • 10.1 SSH Version 2 Overview
        • 10.1.1 Tested SSHv2 Clients
        • 10.1.2 SSHv2 Supported Features
        • 10.1.3 SSHv2 Unsupported Features
        • 10.1.4 SSHv2 Authentication Types
      • 10.2 Configuring SSHv2
        • 10.2.1 Enabling and Disabling SSH by Generating and Deleting Host Keys
          • 10.2.1.1 Generating an ECDSA or RSA Key Pair
          • 10.2.1.2 Deleting ECDSA and RSA Key Pairs
          • 10.2.1.3 Providing the Public Key to Clients
        • 10.2.2 Configuring RSA Challenge-Response Authentication
          • 10.2.2.1 Importing Authorized Public Keys into the ICX Device
          • 10.2.2.2 Enabling RSA Challenge-Response and Password Authentication
        • 10.2.3 Deleting the Public Keys
      • 10.3 Optional Parameters Overview
        • 10.3.1 SSH Rekey Configuration Notes
        • 10.3.2 Setting Optional Parameters
      • 10.4 Terminating an Active SSH Connection
      • 10.5 SSHv2 Client
        • 10.5.1 Enabling the SSHv2 Client
        • 10.5.2 Configuring SSHv2 Client Public Key Authentication
          • 10.5.2.1 Generating and Deleting a Client RSA Key Pair
          • 10.5.2.2 Exporting Client Public Keys
        • 10.5.3 Establishing an SSHv2 Client Connection
      • 10.6 Enabling SSH Access
      • 10.7 Displaying SSH Information
    • 11 BSI C5 Cloud Mode
      • 11.1 Overview of BSI C5 Cloud Mode
      • 11.2 BSI Cloud Mode Limitations
      • 11.3 Configuring BSI Cloud Mode and Optional Parameters
  • SCP client support
    • 12 SCP Client Support
      • 12.1 SCP Client
      • 12.2 SCP Client Support Limitations
      • 12.3 Supported SCP Client Configurations
      • 12.4 Downloading an Image from an SCP Server
      • 12.5 Uploading an Image to an SCP Server
      • 12.6 Uploading Configuration Files to an SCP Server
      • 12.7 Downloading Configuration Files from an SCP Server
      • 12.9 Secure Copy with SSH2
        • 12.9.1 Enabling and Disabling SCP
        • 12.9.2 Secure Copy Configuration Notes
  • 13 ACLs
    • 13.1 Layer 3 ACL Overview
      • 13.1.1 ACL Scaling
      • 13.1.2 Default ACL Action
      • 13.1.3 How Hardware-based ACLs Work
      • 13.1.4 How Fragmented Packets Are Processed
    • 13.2 IPv4 ACLs
      • 13.2.1 IPv4 ACL Configuration Guidelines
      • 13.2.2 Creating and Applying a Standard IPv4 ACL
      • 13.2.3 IPv4 Extended ACL Traffic Filtering Criteria
      • 13.2.4 Creating and Applying an Extended IPv4 ACL
      • 13.2.5 Applying Egress ACLs to Control (CPU) Traffic
      • 13.2.7 Enabling Strict Control of ACL Filtering of Fragmented Packets
      • 13.2.8 Filtering on IP Precedence and ToS Values
      • 13.2.9 ACLs to Filter ARP Packets
        • 13.2.9.1 Configuration Considerations for Filtering ARP Packets
        • 13.2.9.2 Configuring ACLs for ARP Filtering
        • 13.2.9.3 Displaying ACL Filters for ARP
        • 13.2.9.4 Clearing the Filter Count
      • 13.2.10 QoS Options for IP ACLs
        • 13.2.10.1 Configuration Notes for QoS Options
        • 13.2.10.2 Using a Combined ACL for 802.1p Marking
        • 13.2.10.3 Configuring QoS Priority for a VLAN
        • 13.2.10.4 DSCP Matching
      • 13.2.11 ACL-based Rate Limiting
      • 13.2.12 ACLs to Control Multicast Features
      • 13.2.13 Displaying IPv4 ACL Information
    • 13.3 IPv6 ACLs
      • 13.3.1 IPv6 ACL Traffic Filtering Criteria
      • 13.3.2 IPv6 Protocol Names and Numbers
      • 13.3.3 Default and Implicit IPv6 ACL Action
      • 13.3.4 IPv6 ACL Configuration Notes
      • 13.3.5 Creating and Applying an IPv6 ACL
      • 13.3.6 Neighbor Discovery (ND)-Packet DoS Attacks
      • 13.3.7 Displaying IPv6 ACLs
    • 13.4 Applying an ACL to a LAG Interface
    • 13.5 Applying ACLs to VLANs
    • 13.6 ACL Logging
      • 13.6.1 Configuration Notes for ACL Logging
      • 13.6.2 Enabling ACL Logging
    • 13.7 ACL Statistics
    • 13.8 ACL Accounting
      • 13.8.1 Changing the Accounting Period
      • 13.8.2 Configuring ACL Accounting
    • 13.9 Adding a Comment for an Entry in an ACL
      • 13.9.1 Deleting a Comment from an ACL Entry
      • 13.9.2 Viewing Comments in an ACL
    • 13.10 Sequence-based ACL Editing
      • 13.10.1 Inserting Rules into ACLs
      • 13.10.2 Deleting Rules from ACLs
    • 13.11 Displaying TCAM Information for ACLs
  • 14 MAC ACLs
    • 14.1 Layer 2 ACL Overview
    • 14.2 MAC Scaling by ICX Device
    • 14.3 MAC ACL Default Action
    • 14.4 MAC ACL Configuration Notes and Limitations
    • 14.5 Configuring and Applying MAC ACLs
    • 14.6 Displaying MAC ACL Information
  • SS_Policy-Based Routing
    • 15 Policy-Based Routing
      • 15.1 Policy-Based Routing Overview
      • 15.2 Route Maps
      • 15.3 Configuration Guidelines for IPv4 PBR
        • 15.3.1 Configuring an IPv4 PBR Policy with an IPv4 Address as the Next Hop
        • 15.3.2 Configuring an IPv4 PBR Policy with the NULL0 Interface as the Next Hop
        • 15.3.3 Configuring an IPv4 PBR Policy with a Tunnel as the Next Hop
        • 15.3.4 Configuring an IPv4 PBR Policy by Setting a VRF-aware Next Hop in a Route Map
        • 15.3.5 Displaying IPv4 PBR Information
      • 15.4 Configuration Guidelines for IPv6 PBR
        • 15.4.1 Configuring an IPv6 PBR Policy with an IPv6 Address as the Next Hop
        • 15.4.2 Configuring an IPv6 PBR Policy with the NULL0 Interface as the Next Hop
        • 15.4.3 Configuring an IPv6 PBR Policy with a Tunnel as the Next Hop
        • 15.4.4 Displaying IPv6 PBR Information
  • MACsec Key-Based Security
    • 16 Media Access Control Security
      • 16.1 MACsec Overview
      • 16.2 How MACsec Works
        • 16.2.1 MACsec Frame Format
      • 16.3 Configuring MACsec
      • 16.4 Enabling MACsec and Configuring Group Parameters
        • 16.4.1 Configuring MACsec Key-Server Priority
        • 16.4.2 Configuring MACsec Integrity and Encryption
        • 16.4.3 Configuring MACsec Frame Validation
        • 16.4.4 Configuring Replay Protection
        • 16.4.5 Configuring Data-Delay Protection
      • 16.5 Enabling and Configuring Group Interfaces for MACsec
        • 16.5.1 Configuring the Pre-shared Key
      • 16.6 Sample MACsec Configuration
      • 16.7 Displaying MACsec Information
        • 16.7.1 Displaying MACsec Configuration Details
        • 16.7.2 Displaying Information on Current MACsec Sessions
        • 16.7.3 Displaying MKA Protocol Statistics for an Interface
        • 16.7.4 Displaying MACsec Secure Channel Activity for an Interface
  • Port MAC Security
    • 17 Port MAC Security (PMS)
      • 17.1 Port MAC Security Overview
        • 17.1.1 Local and Global Resources Used for Port MAC Security
        • 17.1.2 Configuration Considerations for Port MAC Security
        • 17.1.3 Secure MAC Movement
      • 17.2 Port MAC Security Configuration
      • 17.3 Configuring Port MAC Security
      • 17.4 Displaying Port MAC Security Information
      • 17.5 Clearing Restricted MAC Addresses and Port Security Violation Statistics
  • 18 Flexible Authentication
    • 18.1 Flexible Authentication Overview
      • 18.1.1 MAC VLANs
      • 18.1.2 Data VLAN Requirements for Flexible Authentication
      • 18.1.3 Voice VLAN Requirements for Flexible Authentication
      • 18.1.4 Authentication Modes
      • 18.1.5 Tagged VM Client Support
      • 18.1.6 Static Authentication with MAC Authentication Filters
      • 18.1.7 Authentication Actions
        • 18.1.7.1 Authentication Timeout Action
      • 18.1.8 Authentication Session Limits on an Interface
      • 18.1.10 How Flexible Authentication Works
      • 18.1.11 Configuration Considerations and Guidelines for Flexible Authentication
    • 18.2 802.1X Authentication
      • 18.2.1 Device Roles in an 802.1X Configuration
      • 18.2.2 Communication Between the Devices
      • 18.2.3 Controlled and Uncontrolled Ports
      • 18.2.4 Port Control for Authentication
      • 18.2.5 Message Exchange During Authentication
        • 18.2.5.1 EAP Pass-Through Support
    • 18.3 MAC Authentication
      • 18.3.1 MAC Address Formats Sent to the RADIUS Server
      • 18.3.2 Authenticating Multiple Hosts Connected to the Same Port
      • 18.3.3 How Flexible Authentication Works for Multiple Clients
      • 18.3.4 Flexible Authentication Accounting
      • 18.3.5 Change of Authorization
      • 18.3.6 Multiple RADIUS Servers
      • 18.3.8 Session Aging
      • 18.3.9 Periodic Reauthentication of Authenticated Clients
      • 18.3.10 Denial of Service Protection Support
      • 18.3.11 SNMP Traps for Flexible Authentication
      • 18.3.12 Syslog Messages for Flexible Authentication
    • 18.4 RADIUS Attributes for Authentication and Accounting
    • 18.5 Configuring ICX Vendor-Specific Attributes on the RADIUS Server
    • 18.6 Support for the RADIUS User-Name Attribute in Access-Accept Messages
    • 18.7 Dynamic VLAN Assignment
      • 18.7.1 Configuring the RADIUS Server to Support Dynamic VLAN Assignment for Authentication
      • 18.7.2 Authentication Success Scenarios
      • 18.7.3 Authentication Failure Scenarios
      • 18.7.4 Authentication Server Timeout Scenarios
      • 18.7.5 Authentication Client Timeout Scenarios (No Response to EAP Packets)
      • 18.7.6 Automatic Removal of Dynamic VLAN Assignments for 802.1X and MAC Authenticated Ports
    • 18.8 Dynamic ACLs in Authentication
      • 18.8.1 Configuration Guidelines for Dynamic ACLs
      • 18.8.2 Dynamically Applying Existing ACLs
    • 18.9 Support for IP Source Guard Protection
    • 18.10 Configuring Flexible Authentication
      • 18.10.1 Flexible Authentication Configuration Prerequisites
      • 18.10.2 Configuring Flexible Authentication Globally
      • 18.10.3 Configuring Flexible Authentication on an Interface
      • 18.10.4 Enabling 802.1X Authentication
      • 18.10.5 Enabling MAC Authentication
      • 18.10.6 Excluding the RADIUS Server for Login Features
    • 18.11 Displaying Authentication Information
      • 18.11.1 Displaying Configuration
      • 18.11.2 Displaying Statistics
      • 18.11.3 Displaying the Authentication Sessions
      • 18.11.4 Displaying Information About User ACLs
      • 18.11.5 Displaying Dynamically Assigned VLAN Information
    • 18.12 Clearing Authentication Details
  • 19 IPsec
    • 19.1 IPsec Overview
      • 19.1.1 Acronyms
      • 19.1.2 Establishment of an IPsec Tunnel
      • 19.1.3 Configuration of an IPsec Tunnel
      • 19.1.4 Configuration of Traffic to Route over an IPsec Tunnel
      • 19.1.5 Supported Algorithms
      • 19.1.6 Support for PSK for IKEv2 SAs
      • 19.1.7 Unicast IPv4 over IPsec Tunnels
      • 19.1.8 IPv6 over IPsec Tunnels
      • 19.1.9 IPsec Scalability Limits
      • 19.1.10 Supported Features and Functionality
      • 19.1.11 Unsupported Features
      • 19.1.12 Limitations
      • 19.1.13 IKEv2 Traps
      • 19.1.14 IPsec Traps
      • 19.1.15 IPSec over NAT
      • 19.1.16 Downgrade Considerations
    • 19.2 Configuring Global Parameters for IKEv2
    • 19.3 Configuring an IKEv2 Proposal
    • 19.4 Configuring an IKEv2 Policy
    • 19.5 Configuring an IKEv2 Authentication Proposal
    • 19.6 Configuring an IKEv2 Profile
    • 19.7 Configuring an IPsec Proposal
    • 19.8 Configuring an IPsec Profile
    • 19.9 Activating an IPsec Profile on a VTI
    • 19.10 Routing Traffic over IPsec Using Static Routing
    • 19.11 Routing Traffic over an IPsec Tunnel Using PBR
    • 19.12 Re-establishing SAs
    • 19.13 Enabling IKEv2 Extended Logging
    • 19.14 Disabling Traps and Syslog Messages for IKEv2 and IPsec
    • 19.15 Displaying IPsec Module Information
    • 19.16 Displaying IKEv2 Configuration Information
    • 19.17 Displaying IPsec Configuration Information
    • 19.18 Displaying and Clearing Statistics for IKEv2 and IPsec
    • 19.19 Configuration Example for an IPsec Tunnel Using Default Settings (Site-to-Site VPN)
    • 19.20 Configuration Example for a Hub-to-Spoke VPN Using IPsec
    • 19.21 Configuration Example for an IPsec Tunnel in an IPsec Tunnel
    • 19.22 PKI Support for IPsec
      • 19.22.1 Certificates
      • 19.22.2 Certificate Authority
      • 19.22.3 Certificate Revocation List
      • 19.22.4 CRL Distribution Point
      • 19.22.5 Distinguished Name
      • 19.22.6 Entity
      • 19.22.7 Lightweight Directory Access Protocol
      • 19.22.8 PKI Repository
      • 19.22.9 Registration Authority
      • 19.22.10 Requester
      • 19.22.11 Certificate Enrollment Using SCEP
        • 19.22.11.1 Types of Enrollment
        • 19.22.11.2 Requirements for Requesting a Certificate
        • 19.22.11.3 Communications Between Requesters and the CA
      • 19.22.12 Configuring PKI
        • 19.22.12.1 Configuring an Entity Distinguished Name
        • 19.22.12.2 Creating a Trustpoint
        • 19.22.12.3 Configuring CA Authentication
        • 19.22.12.4 Generating a Certificate Request
        • 19.22.12.5 Extended Key Usage
        • 19.22.12.6 Creating a PKI Enrollment Profile
        • 19.22.12.7 Installing Identity Certificates
        • 19.22.12.8 Clearing the Certificate Revocation List (CRL) and PKI Counters
        • 19.22.12.9 Enabling PKI Logging
      • 19.22.13 PKI Syslog Notification of Certificates Nearing Expiration
      • 19.22.14 Displaying PKI Information
  • HTTP and HTTPS Authentication
    • 20 HTTP and HTTPS
      • 20.1 Web Authentication Overview
      • 20.2 Captive Portal Authentication (External Web Authentication)
        • 20.2.1 Captive Portal Profile for External Web Authentication
        • 20.2.2 Captive Portal on a VLAN
        • 20.2.3 Dynamic IP ACLs in Web Authentication
        • 20.2.4 Configuration Considerations for Applying IP ACLs
        • 20.2.5 Dynamically Applying Existing ACLs (HTTP and HTTPS)
        • 20.2.6 RADIUS Attribute for Session Timeout
      • 20.3 Web Authentication Configuration Considerations
      • 20.4 Configuring Web Authentication
      • 20.5 Prerequisites for Captive Portal Support with RUCKUS Cloudpath
      • 20.6 Prerequisites for Configuring Captive Portal with Aruba ClearPass
      • 20.7 Prerequisites for Configuring External Web Authentication with Cisco ISE
      • 20.8 Prerequisite Configurations on an ICX Switch for Captive Portal Authentication
      • 20.9 Creating the Captive Portal Profile for External Web Authentication
      • 20.10 Configuring Captive Portal (External Web Authentication)
      • 20.11 Web Authentication Mode Configuration
        • 20.11.1 Using Local User Databases
          • 20.11.1.1 Configuring a Local User Database
        • 20.11.2 Passcodes for User Authentication
          • 20.11.2.1 Configuring Passcode Authentication
        • 20.11.3 Automatic Authentication
          • 20.11.3.1 Configuring Automatic Authentication
      • 20.12 Web Authentication Options
        • 20.12.1 Configuring Web Authentication Options
        • 20.12.2 Web Authentication Pages
          • 20.12.2.1 Customizing Web Authentication Pages
      • 20.13 Displaying Web Authentication Information
      • 20.14 Image Download over HTTPS
      • 20.15 Configuration Download over HTTPS
      • 20.16 Configuration Upload over HTTPS
  • Denial of Service Protection
    • 21 Protecting against Denial of Service Attacks
      • 21.1 Denial of Service Protection Overview
      • 21.2 Protecting against Smurf Attacks
        • 21.2.1 Avoiding Being an Intermediary in a Smurf Attack
        • 21.2.2 Avoiding Being a Victim in a Smurf Attack
          • 21.2.2.1 Configuring Threshold Values for ICMP Packets Globally
          • 21.2.2.2 Configuring ICMP Threshold Values on an Interface
      • 21.3 Protecting against TCP SYN Attacks
        • 21.3.1 Configuring Threshold Values for TCP SYN Packets Globally
        • 21.3.2 Configuring TCP SYN Threshold Values on an Interface
        • 21.3.3 TCP MSS Adjustment Overview
        • 21.3.4 Example of TCP MSS Adjustment
        • 21.3.5 Impact on Existing Functionality
        • 21.3.6 TCP MSS Adjustment Limitations
      • 21.4 Displaying Statistics from a DoS Attack
      • 21.5 Clear DoS Attack Statistics
  • 22 IPv6 RA Guard
    • 22.1 Securing IPv6 Address Configuration
    • 22.2 IPv6 RA Guard Overview
      • 22.2.1 RA Guard Policy
      • 22.2.2 Whitelist
      • 22.2.3 Prefix List
      • 22.2.4 Maximum Preference
      • 22.2.5 Trusted, Untrusted, and Host Ports
    • 22.3 Configuration Notes and Feature Limitations for IPv6 RA Guard
    • 22.4 Configuring IPv6 RA Guard
    • 22.5 Example of Configuring IPv6 RA Guard
      • 22.5.1 Example: Configuring IPv6 RA Guard on a Device
      • 22.5.2 Example: Configuring IPv6 RA Guard in a Network
      • 22.5.3 Example: Verifying the RA Guard Configuration
  • 23 Joint Interoperability Test Command
    • 23.1 JITC Overview
  • OpenSSL Acknowledgements
    • 24 OpenSSL License
      • 24.1 OpenSSL License
  • 25 Keychain Module
    • 25.1 Keychain Module Overview
      • 25.1.1 Components of a Keychain
    • 25.2 OSPF Keychain Authentication
      • 25.2.1 Configuring a Keychain Module
    • 25.3 TCP Keychain Options
      • 25.3.1 Configuring TCP Keychain Options
    • 25.4 MKA Keychain Overview and Considerations
      • 25.4.1 Creating and Configuring an MKA Keychain

Vistance Legal Statements

©2026 Vistance Networks, Inc. All rights reserved.

No part of this content may be reproduced in any form or by any means or used to make any derivative work (such as translation, transformation, or adaptation) without written permission from Vistance Networks, Inc. and/or its affiliates (“Vistance”). Vistance reserves the right to revise or change this content from time to time without obligation on the part of Vistance to provide notification of such revision or change.

Export Restrictions

These products and associated technical data (in print or electronic form) may be subject to export control laws of the United States of America. It is your responsibility to determine the applicable regulations and to comply with them. The following notice is applicable for all products or technology subject to export control:

These items are controlled by the U.S. Government and authorized for export only to the country of ultimate destination for use by the ultimate consignee or end-user(s) herein identified. They may not be resold, transferred, or otherwise disposed of, to any other country or to any person other than the authorized ultimate consignee or end-user(s), either in their original form or after being incorporated into other items, without first obtaining approval from the U.S. government or as otherwise authorized by U.S. law and regulations.  

Disclaimer

THIS CONTENT AND ASSOCIATED PRODUCTS OR SERVICES ("MATERIALS"), ARE PROVIDED "AS IS" AND WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS OR IMPLIED. TO THE FULLEST EXTENT PERMISSIBLE PURSUANT TO APPLICABLE LAW, VISTANCE DISCLAIMS ALL WARRANTIES, EXPRESS OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE, TITLE, NON-INFRINGEMENT, FREEDOM FROM COMPUTER VIRUS, AND WARRANTIES ARISING FROM COURSE OF DEALING OR COURSE OF PERFORMANCE. Vistance does not represent or warrant that the functions described or contained in the Materials will be uninterrupted or error-free, that defects will be corrected, or are free of viruses or other harmful components. Vistance does not make any warranties or representations regarding the use of the Materials in terms of their completeness, correctness, accuracy, adequacy, usefulness, timeliness, reliability or otherwise. As a condition of your use of the Materials, you warrant to Vistance that you will not make use thereof for any purpose that is unlawful or prohibited by their associated terms of use.

Limitation of Liability

IN NO EVENT SHALL VISTANCE, VISTANCE AFFILIATES, OR THEIR OFFICERS, DIRECTORS, EMPLOYEES, AGENTS, SUPPLIERS, LICENSORS AND THIRD PARTY PARTNERS, BE LIABLE FOR ANY DIRECT, INDIRECT, SPECIAL, PUNITIVE, INCIDENTAL, EXEMPLARY OR CONSEQUENTIAL DAMAGES, OR ANY DAMAGES WHATSOEVER, EVEN IF VISTANCE HAS BEEN PREVIOUSLY ADVISED OF THE POSSIBILITY OF SUCH DAMAGES, WHETHER IN AN ACTION UNDER CONTRACT, TORT, OR ANY OTHER THEORY ARISING FROM YOUR ACCESS TO, OR USE OF, THE MATERIALS. Because some jurisdictions do not allow limitations on how long an implied warranty lasts, or the exclusion or limitation of liability for consequential or incidental damages, some of the above limitations may not apply to you.

Trademarks

Vistance Networks, Aurora Networks, and RUCKUS Networks and their associated logos are trademarks of Vistance Networks, Inc. and/or its affiliates in the U.S. and other countries. For additional trademark information see https://www.vistancenetworks.com/trademarks/. All product names, trademarks and registered trademarks are property of their respective owners.

Patent Marking Notice

For applicable patents, see:

  • www.an-pat.com (Aurora Networks)
  • www.RN-pat.com (RUCKUS Networks)

Did you find what you were looking for?

Thanks!

Ruckus Wireless

© 2026 Ruckus Wireless LLC All rights reserved.

  • Accessibility
  • Privacy & Cookies
  • Do Not Sell My Information
  • Trademarks
  • Terms
  • Feedback