411
PKI certificate verification (w/o CRL
checking), 226
re
vocation list. Use CRL
c
hange cipher spec protocol (SSL), 342
CHAP/P
AP authentication
direct/cross-subnet portal authentication
process, 121
r
e-DHCP portal authentication process, 122
ch
ecking
IPsec ACL de-encapsulated packet check, 264
PK
I certificate verification (CRL checking), 226
PK
I certificate verification (w/o CRL
checking), 226
cl
assifying
IPsec QoS pre-classify enable, 267
cl
earing
IPsec packet DF bit clear, 268
cl
ient
802.1X authentication, 66, 90
8
02.1X authentication (access device
initiated), 65
8
02.1X authentication (client-initiated), 65
8
02.1X authentication client timeout timer, 82
8
02.1X authentication initiation, 65
8
02.1X basics, 90
80
2.1X configuration, 71 , 79
sec
urity portal authentication, 119
sec
urity portal authentication system
components, 118
S
SL client policy configuration, 344
command
AAA co
mmand accounting method, 12
AAA
command authorization method, 12
c
ommunication
peer public key entry, 211
c
omparing
802.1X EAP relay/termination
authentication, 67
co
mplexity checking (password control), 195
c
omposition checking (password control), 194
conditi
onal self-test, 389
co
nfiguring
802.1X, 71, 79
8
02.1X ACL assignment, 95
8
02.1X authentication, 90
8
02.1X authentication trigger, 83
8
02.1X Auth-Fail VLAN, 74, 87
80
2.1X authorization VLAN assignment, 93
8
02.1X basics, 90
8
02.1X critical VLAN, 76, 88
80
2.1X EAD assistant, 89, 97
8
02.1X guest VLAN, 73, 86
8
02.1X guest VLAN assignment, 93
8
02.1X online user handshake, 83
80
2.1X quiet timer, 85
AAA, 1, 16, 48
AAA HW
TACACS schemes, 32
AAA HW
TACACS server SSH user, 48
AAA I
SP domain accounting method, 45
AAA I
SP domain attribute, 42
AAA I
SP domain authentication method, 43
AAA I
SP domain authorization method, 44
AAA I
SP domain method, 41
AAA
LDAP administrator attributes, 39
AAA LD
AP scheme, 38
AAA LD
AP server IP address, 39
AAA
LDAP server SSH user authentication, 54
AAA
LDAP user attributes, 40
AAA l
ocal user, 18
AAA l
ocal user attributes, 19
AAA R
ADIUS accounting-on, 30
AAA
RADIUS Login-Service attribute check
method, 31
AAA R
ADIUS scheme, 22
AAA
RADIUS security policy server IP address, 30
AAA
RADIUS server SSH user
authentication+authorization, 51
AAA s
cheme, 18
AAA S
SH user local authentication+HWTACACS
authorization+RADIUS accounting, 49
AAA u
ser group attributes, 21
A
RP active acknowledgement, 363
AR
P attack detection (source
MAC-based), 361, 362
AR
P attack protection, 357
A
RP attack protection (unresolvable IP
attack), 357, 359
AR
P attack protection blackhole routing
(unresolvable IP attack), 358
AR
P attack protection source suppression
(unresolvable IP attack), 358
ARP de
tection, 364