New in this Document

The following tables describe changes to this guide for all FastIron 09.0.10 software releases.

Summary of Changes in FastIron Release 09.0.10j

Feature Description Reference
BSI C5 Cloud Mode New: Enhancements have been added in support of the German Federal Office for Information Security (BSI) cloud computing requirements (C5). The new BSI Cloud mode supports onboarding to SmartZone using an ECDSA certificate. BSI C5 Cloud Mode

and the RUCKUS FastIron Command Reference

Additional SSH encryption methods New: The ip ssh host-key-method command introduces options for enabling or disabling host key algorithms. The ip ssh key-exchange-method command is updated to include new secure key-exchange methods. The ip ssh encryption command is introduced to allow selection of a range of new encryption algorithms. SSHv2 Supported Features

Setting Optional Parameters

and the RUCKUS FastIron Command Reference

Additional SSH security options New: The ip ssh stricthostkeycheck ask command prompts the user to confirm the authenticity of the remote host if the host key is not recognized. The ip ssh delete-known-host-key command deletes the known host key for a server and prompts the user to accept or reject the new key on the next connection attempt. SSHv2 Supported Features

Setting Optional Parameters

and the RUCKUS FastIron Command Reference

Updates to address defects Made other minor updates to content throughout to address defects. All chapters.
Minor editorial updates Minor editorial updates were made throughout the Configuration Guide. All chapters.

Summary of Changes in FastIron Release 09.0.10h

Feature Description Reference
Login privilege mode Reintroduced: You can configure the ICX device to enter privileged EXEC mode after a successful login through Telnet or SSH. Entering Privileged EXEC Mode after a Telnet or SSH Login
Ability to disable HMAC-SHA1 New: The ip ssh message-authentication-code disable-hmac-sha1 command is introduced in this release to allow HMAC-SHA1 to be disabled. SSHv2 Supported Features
Updates to address defects Made other minor updates to content throughout to address defects. All chapters.
Minor editorial updates Minor editorial updates were made throughout the Configuration Guide. All chapters.

Summary of Changes in FastIron Release 09.0.10e

Feature Description Reference
Strict password enforcement New: The enable strict-password-enforcement command is reinstated in this release. Configuring Advanced Local User Account Features
Updates to address defects Removed deprecated clear web-connection command and made other minor updates to content throughout to address defects. All chapters.
Minor editorial updates Minor editorial updates were made throughout the Configuration Guide. All chapters.

Summary of Changes in FastIron Release 09.0.10d

Feature

Description

Reference

New: Network segmentation support in conjunction with SmartZone 6.1.1 In support of network segmentation, this release honors a RADIUS-returned VLAN for the Web Authentication client and adds related support for Web Authentication login page customization.

Honoring the RADIUS-Returned VLAN

Summary of Changes in FastIron Release 09.0.10c

Feature

Description

Reference

MACsec data-delay protection The command macsec delay-protection has been introduced. Configuring Data-Delay Protection

Summary of Changes in FastIron Release 09.0.10b

Feature

Description

Reference

MACsec enhancements Configurable MKA keychains applied at the interface level are introduced as an alternative to the individually configured pre-shared key. Media Access Control Security

Creating and Configuring an MKA Keychain

RADIUS Security enhancements RADIUS server security (RADsec) is supported for Flexible authentication from this release. Previously, RADsec was supported only for Console login. Configuring an SSL Profile for Use with RADIUS Server Hosts

Specifying Different Servers for Individual AAA Functions

Importing Digital Certificates and RSA Private Key Files

SSH access support for SHA-2 with 384 bits An ICX device can be accessed using an ECDSA algorithm with 384-bit or 256-bit key sizes while connecting through SSH. SSHv2 Supported Features

Note: FastIron releases 09.0.00, 09.0.00a, and 09.0.10 are no longer available for download due to the discovery of a critical defect.

 

This is a protected line.

Refer to TSB 2022-001 – FastIron 09.0.00 and 09.0.10 - Risk of Filesystem Corruption on the Technical Support Bulletins page for more details.

This is a protected line.
 

RUCKUS recommends upgrading to FastIron release 09.0.10a or later for all ICX switches currently running any of the afore-mentioned releases.

This is a protected line.
 

All the software features supported in FastIron release 09.0.00, 09.0.00a, and 09.0.10 remain available and supported in FastIron release 09.0.10a and later releases unless specifically noted.

This is a protected line.
 

For completeness, the feature descriptions for all changes introduced in the unavailable releases; that is, FastIron 09.0.00, 09.0.00a, and 09.0.10, are included in this section.

Summary of Changes in FastIron Release 09.0.10a

Feature

Description

Reference

TCP keychain A TCP authentication keychain can be configured. Settings can be applied to MSDP and BGP sessions. TCP Keychain Options
Web authentication redirect page customization Remove or modify UserID or Password labels on the authentication redirect page. Web Authentication Options
Web authentication honoring the RADIUS-returned VLAN Honor a RADIUS-returned VLAN for Web Authentication clients. Web Authentication Options
New SSH key exchange method The DH Group-14 SHA 256 key exchange method is supported for general use. Previously, this method was supported only in FIPS mode. Optional Parameters Overview in the SSH chapter
This release introduces a set of changes to simplify the management of ICX devices. The changes include support for user and password based access only, a unified approach to management access control, and the deprecation of now obsolete commands. Changes occur throughout the guide. Refer to subsequent entries in this table and to the FastIron 09.0.10a Release Notes for more information.
Changes to user account management

From this release, all access to ICX devices is via username and password only. Login without a username or without a password is not allowed.

Managing User Accounts
Management access control The management access command has been introduced to control management protocol access to ICX switches. This function replaces the ability to bind ACLs to management protocols as a means to control access.

The RUCKUS FastIron Management Configuration Guide for information on restricting management protocol access using the management access command

The FastIron 09.0.10a for RUCKUS ICX Switches Release Notes for information on new features

The RUCKUS FastIron Command Reference for information on deprecated, modified, and new commands

Changes to Authentication-method Lists The following authentication methods are no longer supported:
  • line (enable via Telnet password)
  • enable (via configured password for Super-User level privileges)
  • TACACS

Managing User Accounts

Authentication-Method List Overview

Changes to AAA Authentication

The following authentication methods are no longer supported:

  • line (enable via Telnet password)
  • enable (via configured password for Super-User level privileges)
  • TACACS

RADIUS Authentication

TACACS+ Server Authentication

Web authentication white-lists Web authentication allows additional sites that may be required during authentication as IPv4 address or FQDN entries in a web authentication white-list, generally referred to as "walled-garden" web authentication. Configuring Web Authentication Options
Changes to ICX digital certificate commands and parameters Self signed certificate generation is no longer supported. TFTP can be used for importing certificates. HTTPS is enabled by default. Only RSA keys can be used. Available maximum key sizes are 4096 (the default) and 2048 bits. Some SSL certificate commands have changed.

ICX Digital Certificates

The RUCKUS FastIron Command Reference

Changes to HTTP and HTTPS HTTPS is enabled by default. HTTP and HTTPS
Unsupported hardware This release and future releases do not support ICX 7750 devices. References have been removed throughout the guide.
Unsupported protocol This release and future releases do not support TACACS. TACACS+ is still supported. References have been removed throughout the guide.
Unsupported feature This release and future releases do not support Campus Fabric (SPX). References have been removed throughout the guide.