R211x-HP Flexfabric 11900 Security Configuration Guide

261
security ARP unresolvable IP attack
protection, 217
sec
urity crypto engine, 240
sec
urity FIPS, 246
sec
urity host public key, 12 0, 120
sec
urity IP source guard, 210
sec
urity IPsec, 14 3
sec
urity IPsec IKE, 160
sec
urity IPv4 source guard, 210
sec
urity IPv6 source guard, 210
sec
urity MAC authentication, 83
s
ecurity password control, 113
sec
urity public key, 122
sec
urity SSH, 183
sec
urity SSH SFTP help information, 181
sec
urity uRPF, 238
distr
ibuting
security local host public key, 119
domain
sec
urity 802.1X mandatory port authentication
domain, 74
s
ecurity AAA ISP domain accounting methods
configuration, 44
s
ecurity AAA ISP domain attribute
configuration, 42
sec
urity AAA ISP domain authentication
methods, 42
s
ecurity AAA ISP domain authorization
methods, 43
sec
urity MAC authentication specification, 81
Don't F
ragment bit. See DF bit
DoS at
tack (uRPF), 234
DP
D
security IPsec IKE configuration, 158
DS
A
security IPsec IKE signature authentication, 151
sec
urity public key management, 117 , 122
sec
urity SSH client host public key
configuration, 173
sec
urity SSH DSA host key pair, 171
sec
urity SSH Stelnet client publickey
authentication, 195
dst
-mac validity check (ARP), 226
dyn
amic
security IP source guard dynamic binding
entry, 206
s
ecurity IPv4 source guard dynamic configuration
with DHCP relay, 214
s
ecurity IPv4 source guard dynamic configuration
with DHCP snooping, 213
E
EA
P
security 802.1X EAP over RADIUS, 63
s
ecurity 802.1X EAP relay enable, 70
sec
urity 802.1X EAP termination enable, 70
sec
urity 802.1X packet format, 62
sec
urity 802.1X RADIUS EAP-Message attribute, 64
sec
urity 802.1X RADIUS Message-Authentication
attribute, 64
sec
urity 802.1X relay authentication, 66
s
ecurity 802.1X relay termination, 67
sec
urity 802.1X relay/termination authentication
mode, 65
EA
POL
security 802.1X authentication (access device
initiated), 64
sec
urity 802.1X authentication (client-initiated), 64
sec
urity 802.1X packet format, 63
EC
DSA
security public key management, 117 , 122
enabli
ng
port security, 92
por
t security MAC move, 96
sec
urity 802.1X, 70
s
ecurity 802.1X EAP relay, 70
sec
urity 802.1X EAP termination, 70
sec
urity 802.1X periodic online user
re-authentication, 75
s
ecurity AAA RADIUS session-control feature, 45
sec
urity AAA RADIUS SNMP notification, 31
s
ecurity ARP blackhole routing, 217
sec
urity IPsec ACL de-encapsulated packet
check, 14 0
sec
urity IPsec IKE invalid SPI recovery, 159
sec
urity IPsec packet logging, 142
sec
urity IPsec QoS pre-classify, 141
sec
urity IPv4 source guard on interface, 207
sec
urity IPv6 source guard on interface, 209
sec
urity MAC authentication, 80
s
ecurity password control, 109
sec
urity SFTP server function, 172