◦
Network Admission Control (NAC) Layer 2 802.1x validation of the antivirus condition or posture
of endpoint systems or clients before granting the devices network access.
NAC is not supported on LanLite images.
Note
◦
Network Edge Access Topology (NEAT) with 802.1X switch supplicant, host authorization with
CISP, and auto enablement to authenticate a switch outside a wiring closet as a supplicant to another
switch.
NEAT is not supported on LanLite images.
Note
◦
IEEE 802.1x with open access to allow a host to access the network before being authenticated.
This feature is not supported on LanLite images.
Note
◦
IEEE 802.1x authentication with downloadable ACLs and redirect URLs to allow per-user ACL
downloads from a Cisco Secure ACS server to an authenticated switch.
◦
Support for dynamic creation or attachment of an auth-default ACL on a port that has no configured
static ACLs.
This feature is not supported on LanLite images.
Note
◦
Flexible-authentication sequencing to configure the order of the authentication methods that a port
tries when authenticating a new host.
◦
Multiple-user authentication to allow more than one host to authenticate on an 802.1x-enabled
port.
•
, a proprietary feature for managing network security through a TACACS server for both
IPv4 and IPv6.
•
RADIUS for verifying the identity of, granting access to, and tracking the actions of remote users through
authentication, authorization, and accounting (AAA) services for both IPv4 and IPv6.
•
Enhancements to RADIUS, , and SSH to function over IPv6.
•
Secure Socket Layer (SSL) Version 3.0 support for the HTTP 1.1 server authentication, encryption, and
message integrity and HTTP client authentication to allow secure HTTP communications (requires the
cryptographic version of the software).
•
IEEE 802.1x Authentication with ACLs and the RADIUS Filter-Id Attribute.
•
Support for IP source guard on static hosts.
•
RADIUS Change of Authorization (CoA) to change the attributes of a certain session after it is
authenticated. When there is a change in policy for a user or user group in AAA, administrators can send
Consolidated Platform Configuration Guide, Cisco IOS Release 15.2(4)E (Catalyst 2960-X Switches)
751
Security Features Overview
Summary of Contents for Catalyst 2960 Series
Page 96: ......
Page 196: ......
Page 250: ......
Page 292: ......
Page 488: ......
Page 589: ...P A R T VI Cisco Flexible NetFlow Configuring NetFlow Lite page 509 ...
Page 590: ......
Page 619: ...P A R T VII QoS Configuring QoS page 539 Configuring Auto QoS page 645 ...
Page 620: ......
Page 750: ......
Page 1604: ......
Page 1740: ......
Page 2105: ...P A R T XII Configuring Cisco IOS IP SLAs Configuring Cisco IP SLAs page 2025 ...
Page 2106: ......
Page 2118: ......
Page 2164: ......