Connectivity Guide

Table Of Contents
Chapter 10: Security.................................................................................................................. 751
User re-authentication...................................................................................................................................................752
Password strength..........................................................................................................................................................752
Role-based access control............................................................................................................................................752
Assign user role............................................................................................................................................................... 753
Bootloader Protection....................................................................................................................................................753
Linuxadmin User Configuration....................................................................................................................................754
RADIUS authentication..................................................................................................................................................755
RADIUS over TLS authentication................................................................................................................................756
TACACS+ authentication.............................................................................................................................................. 757
Unknown user role.......................................................................................................................................................... 758
SSH server........................................................................................................................................................................758
Virtual terminal line......................................................................................................................................................... 759
Control access to VTY............................................................................................................................................. 759
Enable AAA accounting................................................................................................................................................. 760
Enable user lockout........................................................................................................................................................ 760
Limit concurrent login sessions.................................................................................................................................... 761
Enable login statistics..................................................................................................................................................... 761
Privilege levels overview............................................................................................................................................... 762
Configure privilege levels for users.......................................................................................................................762
Configure enable password.................................................................................................................................... 763
Audit log............................................................................................................................................................................ 764
Security commands........................................................................................................................................................ 765
aaa accounting...........................................................................................................................................................765
aaa authentication login...........................................................................................................................................766
aaa re-authenticate enable..................................................................................................................................... 766
boot protect disable username.............................................................................................................................. 767
boot protect enable username password............................................................................................................ 767
clear logging audit..................................................................................................................................................... 767
crypto ssh-key generate..........................................................................................................................................768
disable.......................................................................................................................................................................... 768
enable...........................................................................................................................................................................769
enable password........................................................................................................................................................769
ip access-class........................................................................................................................................................... 770
ip radius source-interface........................................................................................................................................770
ip tacacs source-interface...................................................................................................................................... 770
ipv6 access-class....................................................................................................................................................... 771
ip ssh server challenge-response-authentication...............................................................................................771
ip ssh server cipher....................................................................................................................................................771
ip ssh server enable.................................................................................................................................................. 772
ip ssh server hostbased-authentication...............................................................................................................772
ip ssh server kex........................................................................................................................................................ 773
ip ssh server mac.......................................................................................................................................................773
ip ssh server password-authentication................................................................................................................ 774
ip ssh server port.......................................................................................................................................................774
ip ssh server pubkey-authentication.....................................................................................................................775
ip ssh server vrf......................................................................................................................................................... 775
line vty..........................................................................................................................................................................775
logging audit enable.................................................................................................................................................. 776
Contents
15