02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 7 Security<br />

Security features are supported on plat<strong>for</strong>ms c e s<br />

This chapter discusses several ways to provide access security to <strong>the</strong> <strong>Force10</strong> system. Plat<strong>for</strong>m specific<br />

features are identified by <strong>the</strong> c, e or s icons (as shown below).<br />

• AAA Accounting on page 133<br />

• AAA Au<strong>the</strong>ntication on page 136<br />

• AAA Authorization on page 139<br />

• RADIUS on page 145<br />

• TACACS+ on page 150<br />

• VTY Line and Access-Class <strong>Configuration</strong> on page 155<br />

• SCP and SSH on page 158<br />

• Enabling and Disabling <strong>the</strong> Telnet Daemon on page 167<br />

• Secure Shell on page 163<br />

• Trace List on page 167 — e<br />

• Protecting Against TCP Tiny and Overlapping Fragment Attack on page 173<br />

For details on all commands discussed in this chapter, see <strong>the</strong> Security Commands chapter in <strong>the</strong> <strong>FTOS</strong><br />

Command Reference.<br />

AAA Accounting<br />

AAA Accounting is part of <strong>the</strong> AAA security model (Accounting, Au<strong>the</strong>ntication, and Authorization),<br />

which includes services <strong>for</strong> au<strong>the</strong>ntication, authorization, and accounting. For details on commands related<br />

to AAA security, refer to <strong>the</strong> Security chapter in <strong>the</strong> <strong>FTOS</strong> Command Reference.<br />

AAA Accounting enables tracking of services that users are accessing and <strong>the</strong> amount of network<br />

resources being consumed by those services. When AAA Accounting is enabled, <strong>the</strong> network server<br />

reports user activity to <strong>the</strong> security server in <strong>the</strong> <strong>for</strong>m of accounting records. Each accounting record is<br />

comprised of accounting AV pairs and is stored on <strong>the</strong> access control server.<br />

As with au<strong>the</strong>ntication and authorization, you must configure AAA Accounting by defining a named list of<br />

accounting methods, and <strong>the</strong>n apply that list to various interfaces.<br />

<strong>Configuration</strong> Task List <strong>for</strong> AAA Accounting<br />

The following sections present <strong>the</strong> AAA Accounting configuration tasks:<br />

• Enabling AAA Accounting on page 134 (mandatory)<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 133

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!