254
maintaining ARP detection, 232
maintaining defense against IP packet attack, 225
maintaining source MAC address-based ARP
attack detection, 227
assigning
ACL (802.1X), 74
VLAN (802.1X), 71
VLAN (MAC), 97
asymmetric key
configuring local pair on local device, 139
creating local pair, 139
destroying local pair, 141
attribute
configuring ISP domain (AAA), 37
EAP-Message (802.1X), 65
extended (RADIUS), 6
Message-Authentication (802.1X), 66
RADIUS, 11
authentication
access device as initiator (802.1X), 66
approaches (MAC), 96
client as initiator (802.1X), 66
comparison of EAP relay and EAP termination
modes (802.1X), 67
configuring (802.1X), 83
configuring first-time authentication support
(SSH2.0), 175
configuring ISP domain method (AAA), 38
configuring MAC authentication, 96
domain (MAC authentication), 99
EAP relay (802.1X), 67
EAP termination (802.1X), 70
enabling periodic online user re-authentication
function (802.1X), 80
initiating (802.1X), 66
level switching authentication for Telnet user
(HWTACACS), 56
mechanism (RADIUS), 2
Message-Authentication attribute (802.1X), 66
procedures (802.1X), 66
RADIUS server for SSH/Telnet user (AAA), 47
setting maximum number of authentication request
attempts (802.1X), 77
setting timeout timers (802.1X), 77
SSH2.0, 169
timers (MAC), 97
using 802.1X authentication with other features,
71
using MAC authentication with other features, 97
Authentication, Authorization, and Accounting.
See
AAA
auth-fail VLAN
support (port security), 110
authorization
configuring ISP domain method (AAA), 39
port status (802.1X), 63
RADIUS server for SSH/Telnet user (AAA), 47
setting port authorization state (802.1X), 75
CAR parameters
configuring interpretation of class attribute
(RADIUS), 29
certificate (PKI)
authority (CA) policy, 147
configuring attribute-based access control policy,
164
configuring PKI certificate verification, 155
configuring request from CA running RSA Keon,
158
configuring request from CA running Windows
®
2003 Server
™
,
161
deleting, 156
digital, 147
retrieving manually, 154
revocation list (CRL), 147