R21xx-HP FlexFabric 11900 Security Configuration Guide

199
public key import from file, 74
SCP file transfer with password authentication,
110
SFTP, 89
filtering
A R P p a c k e t s , 137, 138
FIPS
configuration changes, 145
configuration guidelines, 145
configuration restrictions, 145
displaying, 147
enabling, 146
self-test, 146
startup method, 144
triggering self-test, 147
FIPS compliance
password control, 60
public key management, 67
SSH configuration, 79, 155, 178
FIPS self-test
conditional self-test, 146
power-up self-test, 146
triggered self-test, 146
FIPS startup method
automatic reboot, 144
manual reboot, 144
fixed ARP configuration, 135
format
AAA HWTACACS username, 33
AAA RADIUS username, 24
RADIUS packet format, 4
forwarding
ARP restricted forwarding, 133
IP source guard configuration, 113 , 114
IPv4 source guard dynamic configuration with
DHCP relay, 121
IPv4 source guard dynamic configuration with
DHCP snooping, 120
IPv4 source guard static configuration, 118
IPv6 source guard static configuration, 122
FTP
local host public key distribution, 69
SFTP client publickey authentication
configuration, 107
SFTP directories, 88
SFTP files, 89
SFTP server connection termination, 89
SFTP server password authentication
configuration, 105
SSH SFTP client device configuration, 86
SSH SFTP client source IP address/interface, 87
SSH SFTP server connection establishment, 87
gateway protection configuration (ARP), 136
generating
SSH local DSA key pair, 79
SSH local RSA key pair, 79
H3C
RADIUS H3C proprietary attributes, 15
history (password control), 59
HW Terminal Access Controller Access Control
System. Use HWTACACS
HWTACACS
AAA configuration, 1, 16
AAA for SSH user, 43
AAA implementation, 7
AAA MPLS L3VPN implementation, 13
AAA scheme configuration, 18
accounting server specification, 31
authentication server specification, 30
authorization server specification, 30
differences between HWTACACS and RADIUS,
7
displaying, 35