Getting Started
Overview of Access Security Features
Table 1-1. Management Access Security Protection
Security Feature Offers Protection Against Unauthorized Client Access to
Switch Management Features
Offers Protection
Against
Unauthorized Client
Access to the
Network
Connection Telnet SNMP
(Net Mgmt)
Web
Browser
SSH
Client
Local Manager and Operator
Usernames and Passwords
1
PtP: Yes No Yes Yes
Yes No Yes Yes
No
NoRemote:
TACACS+
1
PtP: Yes No No Yes
Yes No No Yes
No
NoRemote:
RADIUS
1
PtP: Yes No No Yes
Yes No No Yes
No
NoRemote:
SSH
Ptp: Yes No No Yes
Yes No No Yes
No
NoRemote:
SSL
Ptp: No No Yes No
No No Yes No
No
NoRemote:
Port-Based Access Control (802.1X) PtP: Yes Yes Yes Yes
No No No No
Yes
NoRemote:
Port Security (MAC address)
PtP: Yes Yes Yes Yes
Yes Yes Yes Yes
Yes
Yes Remote:
Authorized IP Managers
PtP: Yes Yes Yes Yes
Yes Yes Yes Yes
No
NoRemote:
1
The local Manager/Operator, TACACS+, and RADIUS options (direct connect or modem access) also offer protection
for serial port access.
General Switch Traffic Security Guidelines
Where the switch is running multiple security options, it implements network
traffic security based on the OSI (Open Systems Interconnection model)
precedence of the individual options, from the lowest to the highest. The
following list shows the order in which the switch implements configured
security features on traffic moving through a given port.
1. Disabled/Enabled physical port
2. MAC lockout (applies to all ports on the switch)
3. MAC lockdown
4. Port security
5. Authorized IP Managers
6. Application features at higher levels in the OSI model, such as SSH
(The above list does not address the mutually exclusive relationship that
exists among some security features.)
1-4