New in this Document
The following tables describe changes to this guide for all FastIron 09.0.10 software releases.
Summary of Changes in FastIron Release 09.0.10j
| Feature | Description | Reference |
|---|---|---|
| BSI C5 Cloud Mode | New: Enhancements have been added in support of the German Federal Office for Information Security (BSI) cloud computing requirements (C5). The new BSI Cloud mode supports onboarding to SmartZone using an ECDSA certificate. | BSI C5 Cloud Mode |
| Additional SSH encryption methods | New: The ip ssh
host-key-method command introduces options for enabling or
disabling host key algorithms. The ip ssh
key-exchange-method command is updated to include new
secure key-exchange methods. The ip ssh
encryption command is introduced to allow selection of a
range of new encryption algorithms. |
SSHv2 Supported Features |
| Additional SSH security options | New: The
ip ssh
stricthostkeycheck ask command prompts the user to confirm
the authenticity of the remote host if the host key is not recognized.
The ip ssh
delete-known-host-key command deletes the known host key
for a server and prompts the user to accept or reject the new key on the
next connection attempt. |
SSHv2 Supported Features |
| Updates to address defects | Made other minor updates to content throughout to address defects. | All chapters. |
| Minor editorial updates | Minor editorial updates were made throughout the Configuration Guide. | All chapters. |
Summary of Changes in FastIron Release 09.0.10h
| Feature | Description | Reference |
|---|---|---|
| Login privilege mode | Reintroduced: You can configure the ICX device to enter privileged EXEC mode after a successful login through Telnet or SSH. | Entering Privileged EXEC Mode after a Telnet or SSH Login |
| Ability to disable HMAC-SHA1 | New: The ip ssh
message-authentication-code disable-hmac-sha1 command is
introduced in this release to allow HMAC-SHA1 to be disabled. |
SSHv2 Supported Features |
| Updates to address defects | Made other minor updates to content throughout to address defects. | All chapters. |
| Minor editorial updates | Minor editorial updates were made throughout the Configuration Guide. | All chapters. |
Summary of Changes in FastIron Release 09.0.10e
| Feature | Description | Reference |
|---|---|---|
| Strict password enforcement | New: The enable
strict-password-enforcement command is reinstated in this
release. |
Configuring Advanced Local User Account Features |
| Updates to address defects | Removed deprecated clear web-connection command and made other minor updates to content throughout to address defects. | All chapters. |
| Minor editorial updates | Minor editorial updates were made throughout the Configuration Guide. | All chapters. |
Summary of Changes in FastIron Release 09.0.10d
Summary of Changes in FastIron Release 09.0.10c
|
Feature |
Description |
Reference |
|---|---|---|
| MACsec data-delay protection | The command macsec
delay-protection has been introduced. |
Configuring Data-Delay Protection |
Summary of Changes in FastIron Release 09.0.10b
|
Feature |
Description |
Reference |
|---|---|---|
| MACsec enhancements | Configurable MKA keychains applied at the interface level are introduced as an alternative to the individually configured pre-shared key. | Media Access Control Security |
| RADIUS Security enhancements | RADIUS server security (RADsec) is supported for Flexible authentication from this release. Previously, RADsec was supported only for Console login. | Configuring an SSL Profile for Use with RADIUS
Server Hosts Specifying Different Servers for Individual AAA Functions |
| SSH access support for SHA-2 with 384 bits | An ICX device can be accessed using an ECDSA algorithm with 384-bit or 256-bit key sizes while connecting through SSH. | SSHv2 Supported Features |
Note: FastIron releases 09.0.00, 09.0.00a, and 09.0.10 are no longer available for download due to the discovery of a critical defect.
Refer to TSB 2022-001 – FastIron 09.0.00 and 09.0.10 - Risk of Filesystem Corruption on the Technical Support Bulletins page for more details.
RUCKUS recommends upgrading to FastIron release 09.0.10a or later for all ICX switches currently running any of the afore-mentioned releases.
All the software features supported in FastIron release 09.0.00, 09.0.00a, and 09.0.10 remain available and supported in FastIron release 09.0.10a and later releases unless specifically noted.
For completeness, the feature descriptions for all changes introduced in the unavailable releases; that is, FastIron 09.0.00, 09.0.00a, and 09.0.10, are included in this section.
Summary of Changes in FastIron Release 09.0.10a
|
Feature |
Description |
Reference |
|---|---|---|
| TCP keychain | A TCP authentication keychain can be configured. Settings can be applied to MSDP and BGP sessions. | TCP Keychain Options |
| Web authentication redirect page customization | Remove or modify UserID or Password labels on the authentication redirect page. | Web Authentication Options |
| Web authentication honoring the RADIUS-returned VLAN | Honor a RADIUS-returned VLAN for Web Authentication clients. | Web Authentication Options |
| New SSH key exchange method | The DH Group-14 SHA 256 key exchange method is supported for general use. Previously, this method was supported only in FIPS mode. | Optional Parameters Overview in the SSH chapter |
| This release introduces a set of changes to simplify the management of ICX devices. | The changes include support for user and password based access only, a unified approach to management access control, and the deprecation of now obsolete commands. | Changes occur throughout the guide. Refer to subsequent entries in this table and to the FastIron 09.0.10a Release Notes for more information. |
| Changes to user account management |
From this release, all access to ICX devices is via username and password only. Login without a username or without a password is not allowed. |
Managing User Accounts |
| Management access control | The management
access command has been introduced to control management
protocol access to ICX switches. This function replaces the ability to
bind ACLs to management protocols as a means to control access. |
The RUCKUS FastIron
Management Configuration Guide for information on
restricting management protocol access using the The FastIron 09.0.10a for RUCKUS ICX Switches Release Notes for information on new features The RUCKUS FastIron Command Reference for information on deprecated, modified, and new commands |
| Changes to Authentication-method Lists | The following authentication methods are no longer supported: | |
| Changes to AAA Authentication |
The following authentication methods are no longer supported: |
|
| Web authentication white-lists | Web authentication allows additional sites that may be required during authentication as IPv4 address or FQDN entries in a web authentication white-list, generally referred to as "walled-garden" web authentication. | Configuring Web Authentication Options |
| Changes to ICX digital certificate commands and parameters | Self signed certificate generation is no longer supported. TFTP can be used for importing certificates. HTTPS is enabled by default. Only RSA keys can be used. Available maximum key sizes are 4096 (the default) and 2048 bits. Some SSL certificate commands have changed. | |
| Changes to HTTP and HTTPS | HTTPS is enabled by default. | HTTP and HTTPS |
| Unsupported hardware | This release and future releases do not support ICX 7750 devices. | References have been removed throughout the guide. |
| Unsupported protocol | This release and future releases do not support TACACS. TACACS+ is still supported. | References have been removed throughout the guide. |
| Unsupported feature | This release and future releases do not support Campus Fabric (SPX). | References have been removed throughout the guide. |