match {ip | ipv6} address 298
match access-group name 473, 474, 481, 482, 483, 485
match exception {ip | ipv6} icmp redirect 473, 474
match exception {ip | ipv6} icmp unreachable 473, 474
match exception {ip | ipv6} option 473, 474
match mac address 298
match protocol arp 473, 474
N
no {periodic | absolute} 281, 282
no aaa authentication login {console | default | fallback error local 12,
19
no aaa authentication login ascii-authentication 24, 25, 26
no dot1x system-auth-control 198
no feature dot1x 199
no feature ssh 130, 131, 143, 145, 146
no feature tacacs+ 98
no host 274, 275, 276
no ip access-list 239, 240
no ipv6 access-list 239, 240
no key chain 422
no mac access-list 290
no object-group {ip address | ipv6 address | ip port} 278
no ssh key dsa 146
no ssh key rsa 146
no time-range 283
no vlan access-map 299, 300
O
object-group ip address 274, 275
object-group ip port 277
object-group ipv6 address 275, 276
P
password prompt username 32
password strength-check 159, 160
periodic 281
permit 233, 234, 235, 236, 237
permit | deny 287
permit http-method 265
permit interface 166, 167
permit ip 259
permit udf 259
permit vlan 168
permit vrf 169, 170
police 475, 476, 481, 483, 484, 485
police cir 475, 476, 481, 483, 484, 485
policy-map 469
policy-map type control-plane 475
port security 303, 306, 309, 310
default settings 309
description 303
port security (continued)
guidelines 310
limitations 310
MAC address learning 303
MAC move 306
violations 306
ports 180
authorization states for 802.1X 180
R
RADIUS accounting 202
enabling for 802.1X authentication 202
radius commit 45, 51, 52, 53, 55, 56, 60, 61
radius-server deadtime 57, 58, 59, 60
radius-server directed-request 51, 52
radius-server host 33, 45, 47, 49, 54, 55, 56, 59
radius-server host accounting 55, 56
radius-server host acct-port 55, 56
radius-server host auth-port 55, 56
radius-server host authentication 55, 56
radius-server host idle-time 59
radius-server host password 59
radius-server host retransmit 54
radius-server host test 59
radius-server host timeout 54
radius-server host username 59
radius-server key 33, 46
radius-server retransmit 52, 53
radius-server test {idle-time} 57, 58
radius-server test {password} 57, 58
radius-server test {username} 57, 58
radius-server timeout 52, 53
reload 241, 247, 249, 250, 258, 481, 482, 483, 484
resequence {ip | ipv6} access-list 238
resequence mac access-list 289
resequence time-range 283
role commit 163, 164, 165, 166, 167, 168, 169, 170
role feature-group name 165
role name 163, 166, 167, 168, 169, 170
role name priv 96, 97
rule {deny | permit ) command 163
rule {deny | permit} {read | read-write} 163
rule {deny | permit} {read | read-write} feature 163
rule {deny | permit} {read | read-write} feature-group 163, 164
rule {deny | permit} {read | read-write} oid 163, 164
rule {deny | permit} command 96, 97
S
sak-expiry-time 509, 510
scale-factor 478, 479
secure MAC addresses 303
learning 303
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
IN-4
INDEX