Ssd Rules And User Authentication; Default Ssd Rules - Cisco 350XG series Administration Manual

10g stackable managed switches
Table of Contents

Advertisement

Security: Secure Sensitive Data Management
SSD Rules
NOTE
NOTE
NOTE
Cisco 350XG & 550XG Series 10G Stackable Managed Switches
the changes even if the rule is applicable. When a rule is changed (add,
delete, edit), a system will update all the affected CLI/GUI sessions.
When the SSD rule applied upon the session login is changed from within that
session, the user must log out and back in to see the change.
When doing a file transfer initiated by an XML or SNMP command, the underlying
protocol used is TFTP. Therefore, the SSD rule for insecure channel will apply.

SSD Rules and User Authentication

SSD grants SSD permission only to authenticated and authorized users and
according to the SSD rules. A device depends on its user authentication process
to authenticate and authorize management access. To protect a device and its
data including sensitive data and SSD configurations from unauthorized access, it
is recommended that the user authentication process on a device is secured. To
secure the user authentication process, you can use the local authentication
database, as well as secure the communication through external authentication
servers, such as a RADIUS server. The configuration of the secure communication
to the external authentication servers are sensitive data and are protected under
SSD.
The user credential in the local authenticated database is already protected by a
non SSD related mechanism
If a user from a channel issues an action that uses an alternate channel, the device
applies the read permission and default read mode from the SSD rule that match
the user credential and the alternate channel. For example, if a user logs in via a
secure channel and starts a TFTP upload session, the SSD read permission of the
user on the insecure channel (TFTP) is applied

Default SSD Rules

The device has the following factory default rules:
Table 1
Rule Key
User
Channel
Level
Secure XML
15
SNMP
Rule Action
Read
Default Read Mode
Permission
Plaintext Only
Plaintext
21
469

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

550xg series

Table of Contents