© Copyright Lenovo 2018
Chapter 37: Secure Input/Output Module
525
Creating a Policy Setting
The
policy
setting
can
be
either
secure
(IOM
is
in
secure
mode)
or
legacy
(IOM
is
in
legacy
mode).
In
secure
mode,
only
communication
protocols
that
are
deemed
secure
can
be
used;
most
protocols
that
are
not
deemed
secure
are
disabled.
In
legacy
mode
setting,
all
protocols
are
allowed
(LIOM
behavior).
To
display
the
current
policy
setting,
enter:
Note:
Security
policy
can
be
applied
only
from
CMM.
You
must
reboot
the
IOM
for
a
new
policy
setting
to
be
applied.
Protocols Affected by the Policy Setting
This
section
explains
which
protocols
can
and
cannot
operate
in
secure
mode
on
the
NE2552E
Flex
Switch.
Insecure Protocols
When
you
are
in
Secure
Mode,
the
following
protocols
are
deemed
“insecure”
and
are
disabled:
HTTP
LDAP
Client
SNMPv1
SNMPv2
Telnet
(server
and
client)
FTP
(server
and
client)
Radius
(client)
TFTP
Server
Except
for
the
TFTP
server,
these
protocols
cannot
be
enabled
when
the
switch
is
operating
in
Secure
Mode
because
the
commands
to
enable
or
disable
them
are
no
longer
enabled.
The
following
protocols,
although
deemed
“insecure,”
are
enabled
by
default
and
can
be
disabled.
DHCP
client
SysLog
Note:
Service
Location
Protocol
(SLP)
Discovery
is
also
deemed
“insecure”
but
is
unaffected
by
Secure
Mode.
SLP
has
the
same
default
settings
as
in
Legacy
Mode.
If
you
can
enable
or
disable
SLP
in
Legacy
Mode,
you
can
enable
or
disable
it
the
same
way
in
Secure
Mode.
The
following
supported
protocols
are
not
enabled
by
default
but
can
always
be
enabled
in
Secure
Mode.
DNS
Resolution
NE2552E(config)#
show boot security-policy
Summary of Contents for ThinkSystem NE2552E
Page 27: ... Copyright Lenovo 2018 27 Part 1 Getting Started ...
Page 28: ...28 NE2552E Application Guide for ENOS 8 4 ...
Page 70: ...70 NE2552E Application Guide for ENOS 8 4 ...
Page 85: ... Copyright Lenovo 2018 85 Part 2 Securing the Switch ...
Page 86: ...86 NE2552E Application Guide for ENOS 8 4 ...
Page 112: ...112 NE2552E Application Guide for ENOS 8 4 ...
Page 134: ...134 NE2552E Application Guide for ENOS 8 4 ...
Page 154: ...154 NE2552E Application Guide for ENOS 8 4 ...
Page 194: ...194 NE2552E Application Guide for ENOS 8 4 ...
Page 218: ...218 NE2552E Application Guide for ENOS 8 4 ...
Page 234: ...234 NE2552E Application Guide for ENOS 8 4 ...
Page 238: ...238 NE2552E Application Guide for ENOS 8 4 ...
Page 239: ... Copyright Lenovo 2018 239 Part 4 Advanced Switching Features ...
Page 240: ...240 NE2552E Application Guide for ENOS 8 4 ...
Page 242: ...242 NE2552E Application Guide for ENOS 8 4 ...
Page 278: ...278 NE2552E Application Guide for ENOS 8 4 ...
Page 284: ...284 NE2552E Application Guide for ENOS 8 4 ...
Page 314: ...314 NE2552E Application Guide for ENOS 8 4 ...
Page 338: ...338 NE2552E Application Guide for ENOS 8 4 ...
Page 374: ...374 NE2552E Application Guide for ENOS 8 4 ...
Page 388: ...388 NE2552E Application Guide for ENOS 8 4 ...
Page 418: ...418 NE2552E Application Guide for ENOS 8 4 ...
Page 430: ...430 NE2552E Application Guide for ENOS 8 4 ...
Page 432: ...432 NE2552E Application Guide for ENOS 8 4 ...
Page 436: ...436 NE2552E Application Guide for ENOS 8 4 ...
Page 460: ...460 NE2552E Application Guide for ENOS 8 4 ...
Page 461: ... Copyright Lenovo 2018 461 Part 7 Network Management ...
Page 462: ...462 NE2552E Application Guide for ENOS 8 4 ...
Page 476: ...476 NE2552E Application Guide for ENOS 8 4 ...
Page 498: ...498 NE2552E Application Guide for ENOS 8 4 ...
Page 520: ...520 NE2552E Application Guide for ENOS 8 4 ...
Page 534: ...534 NE2552E Application Guide for ENOS 8 4 ...
Page 536: ...536 NE2552E Application Guide for ENOS 8 4 ...
Page 544: ...544 NE2552E Application Guide for ENOS 8 4 ...
Page 549: ... Copyright Lenovo 2018 549 Part 9 Appendices ...
Page 550: ...550 NE2552E Application Guide for ENOS 8 4 ...
Page 566: ...566 NE2552E Application Guide for ENOS 8 4 ...
Page 572: ...572 NE2552E Application Guide for ENOS 8 4 ...
Page 573: ......
Page 574: ...Part Number 01KN246 Printed in USA IP P N 01KN246 ...