ExtremeWare XOS 11.5 supports only the Summit X450 family of switches and the BlackDiamond 8800 series switch.
ExtremeWare XOS 11.5 Command Reference Guide
947
16
Security Commands
This chapter describes commands for:
●
Managing the switch using SSH2
●
Configuring switch user authentication through a RADIUS client
●
Configuring switch user authentication through
●
Protecting the switch from Denial of Service attacks
SSH
Secure Shell 2 (SSH2) is a feature of ExtremeWare XOS that allows you to encrypt session data between
a network administrator using SSH2 client software and the switch. Configuration and policy files may
also be transferred to the switch using the Secure Copy Program 2 (SCP2).
User Authentication
Remote Authentication Dial In User Service (RADIUS, RFC 2138) is a mechanism for authenticating and
centrally administrating access to network nodes. The ExtremeWare XOS RADIUS client
implementation allows authentication for SSH2, Telnet or console access to the switch.
Extreme switches are also capable of sending RADIUS accounting information. You can configure
RADIUS accounting servers to be the same as the authentication servers, but this is not required.
Terminal Access Controller Access Control System Plus () is a mechanism for providing
authentication, authorization, and accounting on a centralized server, similar in function to the RADIUS
client. The ExtremeWare XOS version of is used to authenticate prospective users who are
attempting to administer the switch. is used to communicate between the switch and an
authentication database.
NOTE
You cannot use RADIUS and at the same time.
Denial of Service
You can configure ExtremeWare XOS to protect your Extreme switches in the event of a denial of service
attack. During a typical denial of service attack, the CPU on the switch gets flooded with packets from
multiple attackers, potentially causing the switch to fail. To protect against this type of attack, you can
configure the software so that when the number of packets received is more than the configured
threshold limit of packets per second, a hardware ACL is enabled.