White Papers

Table Of Contents
Chapter 46: Software-Defined Networking (SDN)..................................................................... 737
Chapter 47: Security..................................................................................................................738
AAA Accounting...............................................................................................................................................................738
Configuration Task List for AAA Accounting......................................................................................................738
RADIUS Accounting..................................................................................................................................................740
AAA Authentication........................................................................................................................................................ 745
Configuration Task List for AAA Authentication............................................................................................... 745
Obscuring Passwords and Keys...................................................................................................................................748
AAA Authorization...........................................................................................................................................................748
Privilege Levels Overview....................................................................................................................................... 748
Configuration Task List for Privilege Levels....................................................................................................... 749
RADIUS..............................................................................................................................................................................752
RADIUS Authentication............................................................................................................................................753
Configuration Task List for RADIUS..................................................................................................................... 754
TACACS+.......................................................................................................................................................................... 757
Configuration Task List for TACACS+................................................................................................................. 757
TACACS+ Remote Authentication........................................................................................................................758
Command Authorization..........................................................................................................................................759
Protection from TCP Tiny and Overlapping Fragment Attacks...........................................................................759
Enabling SCP and SSH.................................................................................................................................................. 760
Using SCP with SSH to Copy a Software Image.............................................................................................. 760
Removing the RSA Host Keys and Zeroizing Storage ..................................................................................... 761
Configuring When to Re-generate an SSH Key ................................................................................................ 761
Configuring the SSH Server Key Exchange Algorithm.................................................................................... 762
Configuring the HMAC Algorithm for the SSH Server.................................................................................... 762
Configuring the HMAC Algorithm for the SSH Client......................................................................................763
Configuring the SSH Server Cipher List..............................................................................................................763
Configuring the SSH Client Cipher List............................................................................................................... 764
Secure Shell Authentication................................................................................................................................... 764
Troubleshooting SSH................................................................................................................................................768
Telnet................................................................................................................................................................................. 768
VTY Line and Access-Class Configuration................................................................................................................768
VTY Line Local Authentication and Authorization.............................................................................................769
VTY Line Remote Authentication and Authorization........................................................................................769
VTY MAC-SA Filter Support...................................................................................................................................770
Support for Change of Authorization and Disconnect Messages packets....................................................... 770
Change of Authorization (CoA) packets............................................................................................................. 770
Disconnect Messages...............................................................................................................................................770
Attributes..................................................................................................................................................................... 771
Error-cause Values....................................................................................................................................................773
CoA Packet Processing............................................................................................................................................774
CoA or DM Discard................................................................................................................................................... 774
Disconnect Message Processing........................................................................................................................... 775
Configuring DAC........................................................................................................................................................775
Configuring the port number..................................................................................................................................776
Configuring shared key............................................................................................................................................ 776
Disconnecting administrative users logged in through RADIUS.................................................................... 776
22
Contents