authentication (continued)
TACACS+ 39, 43, 45
defined 39
key 43
login 45
authentication key 43
authentication, defined 39
authorization 39, 47, 71
with RADIUS 71
with TACACS+ 39, 47
authorization, defined 39
automatic 185
B
Berkeley r-tools replacement 88
binding configuration 185
automatic 185
manual 185
binding database 170
address, DHCP server 170
See DHCP, Cisco IOS server database 170
binding table 185
bindings 170, 185
address, Cisco IOS DHCP server 170
IP source guard 185
bridged packets, ACLs on 151
C
CA trustpoint 94, 96
configuring 96
defined 94
changing the default for lines 32
CipherSuites 95
Cisco IOS DHCP server 170
See DHCP, Cisco IOS DHCP server 170
CoA Request Commands 58
commands, setting privilege levels 31
communication, global 65, 73
communication, per-server 65
Configuration Examples for Setting Passwords and Privilege
Levels command 35
configuration files 27
password recovery disable considerations 27
configuration guidelines 96, 187
configuring 43, 45, 47, 48, 65, 66, 71, 72, 73, 88, 96, 99, 102
accounting 48, 72
authentication 66
authentication key 43
authorization 47, 71
configuring (continued)
communication, global 65, 73
communication, per-server 65
login authentication 45
multiple UDP ports 65
configuring a secure HTTP client 102
configuring a secure HTTP server 99
Configuring the Switch for Vendor-Proprietary RADIUS Server
Communication 80
Example command 80
Configuring the Switch to Use Vendor-Specific RADIUS
Attributes 80
Examples command 80
customizeable web pages, web-based authentication 306
D
default configuration 22, 43, 62, 96
password and privilege level 22
RADIUS 62
SSL 96
TACACS+ 43
default web-based authentication configuration 310
802.1X 310
defined 39, 94
defining AAA server groups 68
described 93, 96, 185
DHCP 165, 173
enabling 165, 173
relay agent 173
server 165
DHCP option 82 167, 174, 180
displaying 180
forwarding address, specifying 174
helper address 174
overview 167
DHCP server port-based address allocation 181, 183
default configuration 181
enabling 183
DHCP snooping 166, 167, 185
accepting untrusted packets form edge switch 166
option 82 data insertion 167
trusted interface 166
untrusted messages 166
DHCP snooping binding database 170, 171, 176, 182
adding bindings 182
binding file 170, 171
format 171
location 170
configuration guidelines 176
configuring 182
described 170
Catalyst 2960-XR Switch Security Configuration Guide, Cisco IOS Release 15.0(2)EX1
IN-2 OL-29434-01
Index