Access Security Guide K/KA/KB.15.15

show, 93
SNMP
password and username configuration, 20
SNMPv3
saving security credentials to configuration file, 46, 47
security credentials not supported in downloaded file,
31
SSH
authentication, client public key;SSH:authentication,
user password, 254
caution, security, 235
CLI commands, 228
client behavior, 233
client public key, clearing, 250
client public key, displaying, 249
client public-key authentication, 236
client public-key, creating file, 247
client: copy client-known-hosts file, 251
client: copy host public key, 253
client: copy private key, 251
client: initiate session, 246
client: remove client key pair, 253
client: remove client known hosts file, 253
client: view open sessions, 254
configuring authentication, 236
configuring key lengths, 230
crypto key, 229
disabling, 229
enable, 233
enabling, 233
erase host key pair, 229
generating key pairs, 228
host key pair;SSH:generate host key pair, 229
key, babble, 229
key, fingerprint, 229
keys, zeroing, 229
keysize, 230
known-host file, 231, 232
man-in-the-middle spoofing, 233
OpenSSH, 243
operating rules, 244
password-only authentication, 236
passwords, assigning, 228
prerequisites, 243
private keys not saved to configuration file, 31
public key, 231, 243
public key, displaying, 232
public key, saving to configuration file, 46
reserved IP port numbers, 235
security, 235
switch key to client, 230
unauthorized access, 250
version;SSH:SSHv2;, 254
view open sessions, 254
zeroing a key, 229
zeroize, 229
SSL
cert; cert, RSA key; RSA key, cert, 229
version;SSL:SSLv3;, 258
version;SSL:TLSv1;, 258
Standby Management Module
password, 503
startrange default settings
port-access, 75
T
TACACS
aaa parameters, 138
authentication, 122
authentication process, 135
authentication request
timeout, 127
authentication, local, 136
authorized IP managers, effect, 135
configuration
on switch, 124
configuration, authentication, 124
configuration, server access;TACACS:server access;,
125
configuration, timeout, 129
configuration, viewing, 130
encryption key, 122, 125, 126
encryption key, general operation, 133
encryption key, global, 128
encryption key, saving to configuration file, 46
encryption key;TACACS:configuration, encryption key,
128
general operation, 134
IP address, server, 125
local manager password requirement, 135
messages, 134
precautions
TACACS testing, 122
preventing switch
lockout;test;troubleshooting:authentication via Telnet,
126
privilege level code, 123
server priority, 132
serverspecific encryption key, 129
setup, general, 122
show authentication, 124
single login; TACACS: single sign-on, 124
TFTP, configuration;TACACS:encryption key exclusion,
135
timeout;, 125
troubleshooting, 122
unauthorized access, preventing
manager password recommended, 123
TACACS+
key string with tilde character, 127
troubleshooting
authorized IP managers, 421
diagnostic level, 503
error messages, 504
flash, 503
zeroizing, 503
Tsecurity credentials
copying configurations on the switch, 51
534 Index