466
loose (URPF check), 437
NTK (port security), 179
performing 802.1X authentication (port security),
175
performing MAC authentication (port security),
175
port security, 174
setting local user password in interactive mode,
203
setting security mode (port security), 178
settings changed by enabling FIPS, 440
strict (URPF check), 437
submitting PKI certificate request (auto mode), 225
submitting PKI certificate request (manual mode),
225
MPLS
AAA across MPLS L3VPNs, 10
L3VPN IPsec RRI, 247
SSH2.0 connection across VPNs, 308
multicast (802.1X trigger function), 88
multi-channel protocol (ASPF), 347
naming local security gateway (IKE), 289
Naptha attack protection, 406
NAS
configuring NAS ID-VLAN binding (AAA), 47
ID profile (RADIUS), 131
Port-Type (RADIUS), 131
NAT
ALG configuration, 356, 358
FTP ALG configuration, 358
IKE aggressive mode configuration, 299
NBT ALG configuration, 360
session management configuration, 361
SIP/H.323 ALG configuration, 359
NBT ALG configuration, 360
ND attack defense
configuration, 435
enabling source MAC consistency check for
packet, 436
need to know (NTK), 173
network
802.1X architecture, 72
AAA across MPLS L3VPNs, 10
access device (portal), 116
authentication client (portal), 116
authentication/accounting server (portal), 116
configuring an authentication source subnet, 129
configuring RADIUS related attributes, 131
EAD fast deployment configuration, 99, 100
EAD free IP, 99
enabling Layer 3 portal authentication, 128
enabling portal authentication, 127
logging off portal users, 138
port security autoLearn configuration, 183
port security configuration, 173, 183
port security macAddressElseUserLoginSecure
configuration, 190
port security userLoginWithOUI configuration, 185
portal authentication across VPNs, 125
security policy server (portal), 116
server (portal), 116
setting max number of online portal users, 130
SFTP configuration, 329
specifying NAS ID profile for an interface, 131
specifying NAS-Port-Type for an interface, 131
specifying portal server, 127
specifying portal server for Layer 3 authentication,
127
specifying user authentication domain (portal),
130
SSH2.0 client configuration, 323
SSH2.0 configuration, 305