Users Guide

Configuring Rapid Spanning Tree................................................................................................................................695
Related Configuration Tasks..................................................................................................................................695
Important Points to Remember...................................................................................................................................695
RSTP and VLT......................................................................................................................................................... 696
Configuring Interfaces for Layer 2 Mode...................................................................................................................696
Enabling Rapid Spanning Tree Protocol Globally.......................................................................................................697
Adding and Removing Interfaces................................................................................................................................ 699
Modifying Global Parameters.......................................................................................................................................699
Enabling SNMP Traps for Root Elections and Topology Changes.................................................................... 701
Modifying Interface Parameters...................................................................................................................................701
Enabling SNMP Traps for Root Elections and Topology Changes.......................................................................... 701
Influencing RSTP Root Selection................................................................................................................................. 701
Configuring an EdgePort.............................................................................................................................................. 702
Configuring Fast Hellos for Link State Detection......................................................................................................703
45 Software-Defined Networking (SDN)......................................................................................................704
46 Security...................................................................................................................................................705
AAA Accounting.............................................................................................................................................................705
Configuration Task List for AAA Accounting....................................................................................................... 705
AAA Authentication....................................................................................................................................................... 707
Configuration Task List for AAA Authentication..................................................................................................708
Obscuring Passwords and Keys.................................................................................................................................... 711
AAA Authorization...........................................................................................................................................................711
Privilege Levels Overview........................................................................................................................................ 711
Configuration Task List for Privilege Levels..........................................................................................................712
RADIUS............................................................................................................................................................................716
RADIUS Authentication........................................................................................................................................... 716
Configuration Task List for RADIUS.......................................................................................................................717
TACACS+....................................................................................................................................................................... 720
Configuration Task List for TACACS+..................................................................................................................720
TACACS+ Remote Authentication........................................................................................................................722
Command Authorization......................................................................................................................................... 723
Protection from TCP Tiny and Overlapping Fragment Attacks.............................................................................. 723
Enabling SCP and SSH..................................................................................................................................................723
Using SCP with SSH to Copy a Software Image................................................................................................ 724
Removing the RSA Host Keys and Zeroizing Storage .......................................................................................725
Configuring When to Re-generate an SSH Key ................................................................................................. 725
Configuring the SSH Server Key Exchange Algorithm.......................................................................................726
Configuring the HMAC Algorithm for the SSH Server.......................................................................................726
Configuring the SSH Server Cipher List............................................................................................................... 727
Secure Shell Authentication................................................................................................................................... 727
Troubleshooting SSH.............................................................................................................................................. 730
Telnet.............................................................................................................................................................................. 730
VTY Line and Access-Class Configuration..................................................................................................................731
VTY Line Local Authentication and Authorization................................................................................................731
Contents
23