match {ip | ipv6} address
match access-group name
match exception {ip | ipv6} icmp redirect
match exception {ip | ipv6} icmp unreachable
match exception {ip | ipv6} option
match mac address
match protocol arp
N
no {periodic | absolute}
no aaa authentication login {console | default | fallback error local
no aaa authentication login ascii-authentication
no dot1x system-auth-control
no feature dot1x
no feature ssh
no feature
no host
no ip access-list
no ipv6 access-list
no key chain
no mac access-list
no object-group {ip address | ipv6 address | ip port}
no ssh key dsa
no ssh key rsa
no time-range
no vlan access-map
O
object-group ip address
object-group ip port
object-group ipv6 address
P
password prompt username
password strength-check
periodic
permit
permit | deny
permit http-method
permit interface
permit ip
permit udf
permit vlan
permit vrf
police
police cir
policy-map
policy-map type control-plane
port security
default settings
description
port security
(continued)
guidelines
limitations
MAC address learning
MAC move
violations
ports
authorization states for 802.1X
R
RADIUS accounting
enabling for 802.1X authentication
radius commit
45, 51, 52, 53, 55, 56, 60, 61
radius-server deadtime
radius-server directed-request
radius-server host
33, 45, 47, 49, 54, 55, 56, 59
radius-server host accounting
radius-server host acct-port
radius-server host auth-port
radius-server host authentication
radius-server host idle-time
radius-server host password
radius-server host retransmit
radius-server host test
radius-server host timeout
radius-server host username
radius-server key
radius-server retransmit
radius-server test {idle-time}
radius-server test {password}
radius-server test {username}
radius-server timeout
reload
241, 247, 249, 250, 258, 481, 482, 483, 484
resequence {ip | ipv6} access-list
resequence mac access-list
resequence time-range
role commit
163, 164, 165, 166, 167, 168, 169, 170
role feature-group name
role name
role name priv
rule {deny | permit ) command
rule {deny | permit} {read | read-write}
rule {deny | permit} {read | read-write} feature
rule {deny | permit} {read | read-write} feature-group
rule {deny | permit} {read | read-write} oid
rule {deny | permit} command
S
sak-expiry-time
scale-factor
secure MAC addresses
learning
Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 9.x
IN-4
INDEX