R211x-HP Flexfabric 11900 Security Configuration Guide

277
troubleshooting port security mode cannot be
set, 105
tr
oubleshooting port security secure MAC
addresses, 105
tr
oubleshooting security AAA LDAP, 59
tr
oubleshooting security AAA RADIUS
accounting error, 59
tr
oubleshooting security AAA RADIUS
authentication failure, 58
tr
oubleshooting security AAA RADIUS packet
delivery failure, 58
tr
oubleshooting security IPsec IKE, 16 4
tr
oubleshooting security IPsec IKE negotiation
failure (no proposal match), 16 4
tr
oubleshooting security IPsec IKE negotiation
failure (no proposal or keychain referenced
correctly), 16 4
tr
oubleshooting security IPsec SA negotiation
failure (invalid identity info), 165
tr
oubleshooting security IPsec SA negotiation
failure (no transform set match), 165
wo
rking with SSH SFTP directories, 180
wo
rking with SSH SFTP files, 181
pr
ofile
security IPsec IKE configuration, 153
pr
oposal
security IPsec IKE configuration, 155
pr
otocols and standards
IPsec security protocol 50 (ESP), 128
I
Psec security protocol 51 (AH), 128
sec
urity 802.1X overview, 61
s
ecurity 802.1X related protocols, 62
s
ecurity AAA, 13
s
ecurity AAA HWTACACS, 7, 13
s
ecurity AAA RADIUS, 2, 13
sec
urity IPsec, 131
sec
urity IPsec IKE, 152
sec
urity LDAP, 9, 13
publi
c key
displaying, 122
f
ile import, 124
FI
PS compliance, 117
ho
st public key display, 12 0, 12 0
ho
st public key export to file, 119
ho
st public key save to file, 120
loc
al host public key distribution, 119
local k
ey pair creation, 118
loc
al key pair destruction, 12 0
managemen
t, 117 , 122
peer c
onfiguration, 121
peer ho
st public key import from file, 121
peer publi
c key entry, 121 , 122
sec
urity SSH client host public key
configuration, 173
sec
urity SSH password-publickey
authentication, 170
sec
urity SSH publickey authentication, 170
sec
urity SSH SFTP client publickey
authentication, 199
sec
urity SSH Stelnet client publickey
authentication, 195
sec
urity SSH Stelnet server publickey
authentication, 186
sec
urity SSH user configuration, 174
Q
QoS
security IPsec QoS pre-classify enable, 141
qu
iet
security MAC authentication quiet timer, 82
q
uiet timer
security 802.1X, 75
R
RA
DIUS
AAA configuration, 1, 17
AAA im
plementation, 2
AAA l
ocal user configuration, 18
AAA
MPLS L3VPN implementation, 13
AAA s
cheme configuration, 18
ac
counting server parameter specification, 24
ac
counting-on feature configuration, 30
at
tributes, 14
a
uthentication server specification, 24
c
lient/server model, 2
c
ommon standard attributes, 14
displa
ying, 31
e
xtended attributes, 6
HP pr
oprietary attributes, 15
HW
TACACS/RADIUS differences, 7
inf
ormation exchange security mechanism, 2
main
taining, 31