New in This Document

The following table describes changes to this guide for the FastIron 10.0.20 software release.

Summary of Changes in FastIron Release 10.0.20b_cd1

Feature

Description

Reference

Introduction of ICX 8100 support New: Support for ICX 8100 devices is introduced. All chapters
Rate limit behavior change Updated: For ICX 8100 and ICX 8200 updated ACL rate-limiting behavior to apply rate-limits on a per-rule basis instead of the 'cumulative application across all the matching rules in prior releases. ACL-based Rate Limiting
Radius Authentication Key Length The key-string in the radius-server key command can be from 1 through 128 characters in length. Identifying the RADIUS Server to the RUCKUS Device
Updates to address defects Updated: Minor updates have been introduced throughout the guide to address defects. All chapters
Minor editorial updates Updated: Minor editorial updates were made throughout the guide. All chapters

Summary of Changes in FastIron Release 10.0.20a

Feature

Description

Reference

Distributed Denial-of-Service (DDoS) New: A DDoS attack is a specific denial-of-service (DoS) attack and happens when multiple sources overwhelm a network, disrupting regular traffic. DDoS UDP rate limit and prevention of DDoS attack using Gratuitous ARP packets are introduced on ICX 8200 devices. Distributed Denial of Service Protection Overview
Keepalive for MAC Authentication Clients New: This feature allows the switch to check if the MAC authenticated client is still active or not by spending keep alive messages, which prevents the authentication session from timing out. Keepalive for MAC Authentication Clients
Dynamic ACL with Traffic Policy Beginning with FastIron 10.0.20a, rate limiting is supported for IPv4 and IPv6 ingress ACL-based traffic policies on IEEE 802.1X and MAC authentication enabled ports. ACL-based Rate Limiting
RADIUS status-server enhancements

Provides the ability to disable RADIUS status-server messages. By default, status-server messages are enabled, and server status is continually checked, resulting in a high number of log messages. As an option, you can use the status-server off setting to disable the status-server messages for the configured RADIUS server host.

Configuring the status-server on/off
Updates to address defects Updated: Minor updates have been introduced throughout the guide to address defects. All chapters
Minor editorial updates Updated: Minor editorial updates were made throughout the guide. All chapters

Summary of Changes in FastIron Release 10.0.20

Feature

Description

Reference

BSI C5 Cloud Mode
Marked out because not *introduced in this stream; introduced in 09.0.10j patch and 10.0.10c patch, which would carry forward to this release by default.
New: Enhancements have been added in support of the German Federal Office for Information Security (BSI) cloud computing requirements (C5). The new BSI Cloud mode supports onboarding to SmartZone using an ECDSA certificate. BSI C5 Cloud Mode

and RUCKUS FastIron Command Reference

Additional SSH encryption options
Marked out because not *introduced in this stream; introduced in 09.0.10j patch and 10.0.10c patch, which would carry forward to this release by default. Contents are also incorrect, under description.
New: The ip ssh host-key-method command introduces an option for enabling or disabling host key algorithms. The ip ssh key-exchange-method command is updated to include new secure key-exchange methods for SSH connections. The ip ssh encryption command allows selection of a range of new encryption algorithms. SSHv2 Supported Features

and Setting Optional Parameters

RADIUS priority New: You can specify the connection priority when configuring multiple RADIUS servers for 802.1x, MAC authentication, or Web authentication. Specifying RADIUS Server Priority
RADIUS location attribute New: A vendor-specific attribute (VSA) for a RUCKUS location can be configured for RADIUS authentication requests. The RUCKUS location is configured with the new host-location command. Configuring the Host Location
Flexible authentication accepts a VLAN group attribut New: If you configure a VLAN group with the vlan-group command, it is included in RUCKUS VSA options in RADIUS request messages. The VLAN group is supported by the Tunnel-Private-Group-ID (TPGID) attribute. Configuring the RADIUS Server to Support Dynamic VLAN Assignment for Authentication
Allow an "auth-fail" client to remain in the default VLAN (Flexible authentication) New: In Flexible authentication, the action in response to a failed authentication can be configured as "permit" to place the client in the authentication default VLAN. The failure is logged, but the client is not blocked. The "permit" option can be configured globally or at the interface level. Configuring Flexible Authentication Globally or

Configuring Flexible Authentication on an Interface

Apply an ACL to multiple interfaces simultaneously New: You can apply an existing ACL to a range of interfaces simultaneously. Applying ACLs on Multiple Interfaces Simultaneously
Updates to address defects Updated: Minor updates have been introduced throughout the guide to address defects. All chapters
Minor editorial updates Updated: Minor editorial updates were made throughout the guide. All chapters