Concept Guide
Protocol Overview......................................................................................................................................................... 824
Conguring Rapid Spanning Tree.................................................................................................................................824
Related Conguration Tasks................................................................................................................................... 824
Important Points to Remember....................................................................................................................................824
RSTP and VLT..........................................................................................................................................................825
Conguring Interfaces for Layer 2 Mode....................................................................................................................825
Enabling Rapid Spanning Tree Protocol Globally........................................................................................................826
Adding and Removing Interfaces.................................................................................................................................828
Modifying Global Parameters....................................................................................................................................... 828
Enabling SNMP Traps for Root Elections and Topology Changes.....................................................................830
Modifying Interface Parameters.................................................................................................................................. 830
Enabling SNMP Traps for Root Elections and Topology Changes...........................................................................830
Inuencing RSTP Root Selection.................................................................................................................................830
Conguring an EdgePort............................................................................................................................................... 831
Conguring Fast Hellos for Link State Detection...................................................................................................... 832
48 Software-Dened Networking (SDN)...................................................................................................... 833
49 Security...................................................................................................................................................834
AAA Accounting.............................................................................................................................................................834
Conguration Task List for AAA Accounting........................................................................................................ 834
AAA Authentication.......................................................................................................................................................836
Conguration Task List for AAA Authentication...................................................................................................837
Obscuring Passwords and Keys...................................................................................................................................840
AAA Authorization......................................................................................................................................................... 840
Privilege Levels Overview.......................................................................................................................................840
Conguration Task List for Privilege Levels...........................................................................................................841
RADIUS........................................................................................................................................................................... 845
RADIUS Authentication...........................................................................................................................................845
Conguration Task List for RADIUS...................................................................................................................... 846
Support for Change of Authorization and Disconnect Messages packets...................................................... 850
TACACS+........................................................................................................................................................................ 861
Conguration Task List for TACACS+....................................................................................................................861
TACACS+ Remote Authentication.........................................................................................................................863
Command Authorization.........................................................................................................................................864
Protection from TCP Tiny and Overlapping Fragment Attacks............................................................................... 864
Enabling SCP and SSH................................................................................................................................................. 864
Using SCP with SSH to Copy a Software Image................................................................................................ 865
Removing the RSA Host Keys and Zeroizing Storage ....................................................................................... 866
Conguring When to Re-generate an SSH Key ..................................................................................................866
Conguring the SSH Server Key Exchange Algorithm....................................................................................... 867
Conguring the HMAC Algorithm for the SSH Server....................................................................................... 867
Conguring the SSH Server Cipher List...............................................................................................................868
Conguring DNS in the SSH Server..................................................................................................................... 868
Secure Shell Authentication................................................................................................................................... 869
Troubleshooting SSH................................................................................................................................................871
26
Contents