© Copyright Lenovo 2017
Chapter 1: Switch Administration
53
Only
protocols/algorithms
compliant
with
NIST
SP
800
‐
131A
specification
are
used/enabled
on
the
switch.
Please
see
the
NIST
SP
800
‐
131A
publication
for
details.
The
following
table
lists
the
acceptable
protocols
and
algorithms:
Table 4.
Acceptable
Protocols
and
Algorithms
Protocol/Function Strict Mode Algorithm
Compatibility Mode Algorithm
BGP
BGP does not comply with NIST SP
800-131A specification. When in strict
mode, BGP is disabled. However, it can
be enabled, if required.
Acceptable
Certificate
Generation
RSA-2048
SHA-256
RSA 2048
SHA 256
Certificate
Acceptance
RSA 2048 or higher
SHA 224 or higher
RSA
SHA, SHA2
HTTPS
TLS 1.2 only
See
;
TLS 1.0, 1.1, 1.2
See
IKE
Key Exchange
DH Group 24
DH group 1, 2, 5, 14, 24
Encryption
3DES, AES-128-CBC
3DES, AES-128-CBC
Integrity
HMAC-SHA1
HMAC-SHA1, HMAC-MD5
IPSec
AH
HMAC-SHA1
HMAC-SHA1, HMAC-MD5
ESP
3DES, AES-128-CBC, HMAC-SHA1 3DES, AES-128-CBC,
HMAC-SHA1, HMAC-MD5
LDAP
LDAP does not comply with NIST SP
800-131A specification. When in strict
mode, LDAP is disabled. However, it
can be enabled, if required.
Acceptable
OSPF
OSPF does not comply with NIST SP
800-131A specification. When in strict
mode, OSPF is disabled. However, it
can be enabled, if required.
Acceptable
RADIUS
RADIUS does not comply with NIST
SP 800-131A specification. When in
strict mode, RADIUS is disabled. How-
ever, it can be enabled, if required.
Acceptable
Random Number
Generator
NIST SP 800-90A AES CTR DRBG
NIST SP 800-90A AES CTR DRBG
Secure NTP
Secure NTP does not comply with
NIST SP 800-131A specification.
When in strict mode, secure NTP is dis-
abled. However, it can be enabled, if
required.
Acceptable
SLP
SHA-256 or higher
RSA/DSA 2048 or higher
Summary of Contents for Flex System Fabric CN4093
Page 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Page 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Page 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Page 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Page 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Page 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Page 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Page 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Page 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Page 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Page 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Page 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Page 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Page 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Page 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Page 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Page 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Page 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Page 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Page 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Page 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Page 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Page 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Page 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Page 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Page 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Page 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Page 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Page 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Page 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Page 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Page 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Page 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Page 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Page 633: ......
Page 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...