authentication (continued)
TACACS+ 41, 45, 47
defined 41
key 45
login 47
authentication key 45
authentication, defined 41
authorization 41, 50, 90
with RADIUS 90
with TACACS+ 41, 50
authorization, defined 41
automatic 235
B
Berkeley r-tools replacement 116
binding configuration 235
automatic 235
manual 235
binding database 214
address, DHCP server 214
See DHCP, Cisco IOS server database 214
binding table 235
bindings 214, 235
address, Cisco IOS DHCP server 214
IP source guard 235
bridged packets, ACLs on 192
C
CA trustpoint 126, 129
configuring 129
defined 126
changing the default for lines 33
CipherSuites 127
Cisco IOS DHCP server 214
See DHCP, Cisco IOS DHCP server 214
CoA Request Commands 65
commands, setting privilege levels 31
communication, global 83, 93
communication, per-server 83
Configuration Examples for Setting Passwords and Privilege
Levels command 35
configuration files 26
password recovery disable considerations 26
configuration guidelines 128, 237
configuring 45, 47, 50, 52, 83, 86, 90, 92, 93, 116, 129, 131, 134
accounting 52, 92
authentication 86
authentication key 45
authorization 50, 90
configuring (continued)
communication, global 83, 93
communication, per-server 83
login authentication 47
multiple UDP ports 83
configuring a secure HTTP client 134
configuring a secure HTTP server 131
Configuring the Switch for Vendor-Proprietary RADIUS Server
Communication 103
Example command 103
Configuring the Switch to Use Vendor-Specific RADIUS
Attributes 103
Examples command 103
Configuring VACL Logging 177
customizeable web pages, web-based authentication 365
D
default configuration 20, 45, 69, 128
password and privilege level 20
RADIUS 69
SSL 128
TACACS+ 45
default web-based authentication configuration 369
802.1X 369
defined 41, 126
defining AAA server groups 88
described 125, 235
DHCP 209, 218
enabling 209, 218
relay agent 218
server 209
DHCP option 82 211, 219, 226
displaying 226
forwarding address, specifying 219
helper address 219
overview 211
DHCP server port-based address allocation 227, 229
default configuration 227
enabling 229
DHCP snooping 210, 211, 235
accepting untrusted packets form edge switch 210
option 82 data insertion 211
trusted interface 210
untrusted messages 210
DHCP snooping binding database 214, 215, 222, 227
adding bindings 227
binding file 215
format 215
location 215
configuration guidelines 222
configuring 227
Catalyst 2960-X Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX
IN-2 OL-29048-01
Index