586
CN4093 Application Guide for ENOS 8.4
Creating a Policy Setting
The
policy
setting
can
be
either
secure
(IOM
is
in
secure
mode)
or
legacy
(IOM
is
in
legacy
mode).
In
secure
mode,
only
communication
protocols
that
are
deemed
secure
can
be
used;
most
protocols
that
are
not
deemed
secure
are
disabled.
In
legacy
mode
setting,
all
protocols
are
allowed
(LIOM
behavior).
To
display
the
current
policy
setting,
enter:
Note:
Security
policy
can
be
applied
only
from
CMM.
You
must
reboot
the
IOM
for
a
new
policy
setting
to
be
applied.
Protocols Affected by the Policy Setting
This
section
explains
which
protocols
can
and
cannot
operate
in
secure
mode
on
the
CN4093
10
Gb
Converged
Scalable
Switch.
Insecure Protocols
When
you
are
in
Secure
Mode,
the
following
protocols
are
deemed
“insecure”
and
are
disabled:
HTTP
LDAP
Client
SNMPv1
SNMPv2
Telnet
(server
and
client)
FTP
(server
and
client)
Radius
(client)
TFTP
Server
Except
for
the
TFTP
server,
these
protocols
cannot
be
enabled
when
the
switch
is
operating
in
Secure
Mode
because
the
commands
to
enable
or
disable
them
are
no
longer
enabled.
The
following
protocols,
although
deemed
“insecure,”
are
enabled
by
default
and
can
be
disabled.
DHCP
client
SysLog
Note:
Service
Location
Protocol
(SLP)
Discovery
is
also
deemed
“insecure”
but
is
unaffected
by
Secure
Mode.
SLP
has
the
same
default
settings
as
in
Legacy
Mode.
If
you
can
enable
or
disable
SLP
in
Legacy
Mode,
you
can
enable
or
disable
it
the
same
way
in
Secure
Mode.
The
following
supported
protocols
are
not
enabled
by
default
but
can
always
be
enabled
in
Secure
Mode.
DNS
Resolution
CN 4093(config)#
show boot security-policy
Summary of Contents for Flex System Fabric CN4093
Page 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Page 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Page 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Page 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Page 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Page 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Page 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Page 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Page 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Page 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Page 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Page 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Page 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Page 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Page 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Page 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Page 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Page 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Page 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Page 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Page 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Page 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Page 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Page 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Page 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Page 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Page 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Page 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Page 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Page 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Page 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Page 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Page 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Page 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Page 633: ......
Page 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...