ExtremeWare 7.7 Command Reference Guide
845
11
Security Commands
This chapter describes commands for:
•
Creating and configuring routing access policies
•
Creating and configuring IP access lists
•
Creating and configuring route maps (“
i
” series switches only)
•
Managing MAC address access to the switch
•
Managing the switch using SSH2
•
Setting up switch user authentication through a RADIUS client
•
Setting up switch user authentication through
•
Protecting the switch from denial of service (DoS) attacks
•
Configuring network login
•
Configuring Trusted MAC or OUI configuration
•
Configuring secure access for all wired and wireless stations through Unified Access™ Security
Controlling Access
Access policies
are a generalized category of features that affect forwarding and route forwarding
decisions. Access policies are used primarily for security and quality of service (QoS) purposes.
IP access lists
(also referred to as access lists or ACLs) consist of IP access rules. They are used to
perform packet filtering and forwarding decisions on incoming traffic. Each packet arriving on an
ingress port is compared to the access list in sequential order and is either forwarded to a specified QoS
profile or dropped. Using access lists has no impact on switch performance.
Access lists are typically applied to traffic that crosses layer 3 router boundaries, but it is possible to use
access lists within a layer 2 VLAN. Extreme products are capable of performing this function with no
additional configuration.
Routing access policies
are used to control the advertisement or recognition of routing protocols, such as
RIP, OSPF, IS-IS, or BGP. (IS-IS and BGP are supported only on “
i
” series switches.) Routing access
policies can be used to “hide” entire networks or to trust only specific sources for routes or ranges of
routes. The capabilities of routing access policies are specific to the type of routing protocol involved,
but are sometimes more efficient and easier to implement than access lists.
Содержание ExtremeWare 7.7
Страница 60: ...60 ExtremeWare 7 7 Command Reference Guide Contents ...
Страница 72: ...72 ExtremeWare 7 7 Command Reference Guide Command Reference Overview ...
Страница 404: ...404 ExtremeWare 7 7 Command Reference Guide VLAN Commands ...
Страница 472: ...472 ExtremeWare 7 7 Command Reference Guide QoS Commands ...
Страница 491: ...show nat ExtremeWare 7 7 Command Reference Guide 491 Platform Availability This command is available on all platforms ...
Страница 492: ...492 ExtremeWare 7 7 Command Reference Guide NAT Commands ...
Страница 890: ...890 ExtremeWare 7 7 Command Reference Guide Security Commands ...
Страница 1043: ...enable ssh2 ExtremeWare 7 7 Command Reference Guide 1043 Platform Availability This command is available on all platforms ...
Страница 1066: ...1066 ExtremeWare 7 7 Command Reference Guide Security Commands Platform Availability This command is available on all platforms ...
Страница 1076: ...1076 ExtremeWare 7 7 Command Reference Guide Security Commands Platform Availability This command is available on all platforms ...
Страница 1130: ...1130 ExtremeWare 7 7 Command Reference Guide Security Commands ...
Страница 1164: ...1164 ExtremeWare 7 7 Command Reference Guide Configuration and Image Commands ...
Страница 1436: ...1436 ExtremeWare 7 7 Command Reference Guide Wireless Commands ...
Страница 1481: ...show eaps ExtremeWare 7 7 Command Reference Guide 1481 Platform Availability This command is available on all platforms ...
Страница 1484: ...1484 ExtremeWare 7 7 Command Reference Guide EAPS Commands Platform Availability This command is available on all platforms ...
Страница 1490: ...1490 ExtremeWare 7 7 Command Reference Guide EAPS Commands ...
Страница 1538: ...1538 ExtremeWare 7 7 Command Reference Guide ESRP Commands Platform Availability This command is available on all platforms ...
Страница 1576: ...1576 ExtremeWare 7 7 Command Reference Guide ESRP Commands ...
Страница 1614: ...1614 ExtremeWare 7 7 Command Reference Guide STP Commands Platform Availability This command is available on all platforms ...
Страница 1621: ...enable stpd ports ExtremeWare 7 7 Command Reference Guide 1621 Platform Availability This command is available on all platforms ...
Страница 1774: ...1774 ExtremeWare 7 7 Command Reference Guide IP Unicast Commands ...
Страница 1824: ...1824 ExtremeWare 7 7 Command Reference Guide IGP Commands Platform Availability This command is available on all platforms ...
Страница 1884: ...1884 ExtremeWare 7 7 Command Reference Guide IGP Commands Platform Availability This command is available on all platforms ...
Страница 1914: ...1914 ExtremeWare 7 7 Command Reference Guide IGP Commands ...
Страница 2000: ...2000 ExtremeWare 7 7 Command Reference Guide BGP Commands i Series Switches Only ...
Страница 2140: ...2140 ExtremeWare 7 7 Command Reference Guide IPX Commands i Series Platforms Only ...
Страница 2156: ...2156 ExtremeWare 7 7 Command Reference Guide ARM Commands BlackDiamond Switch Only ...
Страница 2168: ...2168 ExtremeWare 7 7 Command Reference Guide Remote Connect Commands ...
Страница 2180: ...2180 ExtremeWare 7 7 Command Reference Guide ATM Commands BlackDiamond 6800 Series Platforms Only ...
Страница 2236: ...2236 ExtremeWare 7 7 Command Reference Guide T1 E1 and T3 WAN Commands Alpine 3800 Series Platforms ...
Страница 2346: ...2346 ExtremeWare 7 7 Command Reference Guide PoS Commands BlackDiamond Switch Only ...
Страница 2410: ...2410 ExtremeWare 7 7 Command Reference Guide Power Over Ethernet Commands Summit 300 and 400 24p Switches and Alpine PoE Module ...
Страница 2446: ...2446 ExtremeWare 7 7 Command Reference Guide LLDP Commands ...
Страница 2496: ...2496 ExtremeWare 7 7 Command Reference Guide H VPLS Commands BlackDiamond Switch Only ...
Страница 2620: ...2620 ExtremeWare 7 7 Command Reference Guide Index of Commands ...