846
ExtremeWare 7.7 Command Reference Guide
Security Commands
Route maps
are used to modify or filter routes redistributed between two routing domains. They are also
used to modify or filter the routing information exchanged between the domains.
NOTE
Route maps are supported only on the “i” series switches.
MAC Address Security
The switch maintains a database of all media access control (MAC) addresses received on all of its
ports. It uses the information in this database to decide whether a frame should be forwarded or
filtered. You can control the way the forwarding database (FDB) is learned and populated. By managing
entries in the FDB, you can block, assign priority (queues), and control packet flows on a per-address
basis.
You can limit the number of dynamically learned MAC addresses allowed per virtual port or “lock” the
FDB entries for a virtual port, so that the current entries will not change, and no additional addresses
can be learned on the port. Commands for these functions are described in Chapter 4. In addition, you
can set a timer on the learned addresses that limits the length of time the learned addresses will be
maintained if devices are disconnected or become inactive. Commands for this function are described in
this chapter.
SSH
Secure Shell 2 (SSH2) is a feature of ExtremeWare that allows you to encrypt session data between a
network administrator using SSH2 client software and the switch, or to send encrypted data from the
switch to an SSH2 client on a remote system. Image and configuration files may also be transferred to
the switch using the Secure Copy Program 2 (SCP2).
User Authentication
Remote Authentication Dial In User Service (RADIUS, RFC 2138) is a mechanism for authenticating and
centrally administrating access to network nodes. The ExtremeWare RADIUS client implementation
allows authentication for telnet, Vista, or console access to the switch.
Extreme switches can send RADIUS accounting information. You can configure RADIUS accounting
servers to be the same as the authentication servers, but this is not required. The switch provides the
following client attribute information to the RADIUS accounting server:
•
User-Name
•
NAS-IP-Address
•
NAS-Port
•
NAS-Port-Type
•
Acct-Status-Type
•
Acct-Session-ID
•
Acct-Session-Time
Summary of Contents for ExtremeWare 7.7
Page 60: ...60 ExtremeWare 7 7 Command Reference Guide Contents ...
Page 72: ...72 ExtremeWare 7 7 Command Reference Guide Command Reference Overview ...
Page 404: ...404 ExtremeWare 7 7 Command Reference Guide VLAN Commands ...
Page 472: ...472 ExtremeWare 7 7 Command Reference Guide QoS Commands ...
Page 492: ...492 ExtremeWare 7 7 Command Reference Guide NAT Commands ...
Page 890: ...890 ExtremeWare 7 7 Command Reference Guide Security Commands ...
Page 1130: ...1130 ExtremeWare 7 7 Command Reference Guide Security Commands ...
Page 1164: ...1164 ExtremeWare 7 7 Command Reference Guide Configuration and Image Commands ...
Page 1436: ...1436 ExtremeWare 7 7 Command Reference Guide Wireless Commands ...
Page 1490: ...1490 ExtremeWare 7 7 Command Reference Guide EAPS Commands ...
Page 1576: ...1576 ExtremeWare 7 7 Command Reference Guide ESRP Commands ...
Page 1774: ...1774 ExtremeWare 7 7 Command Reference Guide IP Unicast Commands ...
Page 1914: ...1914 ExtremeWare 7 7 Command Reference Guide IGP Commands ...
Page 2000: ...2000 ExtremeWare 7 7 Command Reference Guide BGP Commands i Series Switches Only ...
Page 2140: ...2140 ExtremeWare 7 7 Command Reference Guide IPX Commands i Series Platforms Only ...
Page 2156: ...2156 ExtremeWare 7 7 Command Reference Guide ARM Commands BlackDiamond Switch Only ...
Page 2168: ...2168 ExtremeWare 7 7 Command Reference Guide Remote Connect Commands ...
Page 2346: ...2346 ExtremeWare 7 7 Command Reference Guide PoS Commands BlackDiamond Switch Only ...
Page 2446: ...2446 ExtremeWare 7 7 Command Reference Guide LLDP Commands ...
Page 2496: ...2496 ExtremeWare 7 7 Command Reference Guide H VPLS Commands BlackDiamond Switch Only ...
Page 2620: ...2620 ExtremeWare 7 7 Command Reference Guide Index of Commands ...