General Switch Traffic Security Guidelines - ProCurve 2600 Series Getting Started

Table of Contents

Advertisement

Getting Started
Overview of Access Security Features
Table 1-1.
Management Access Security Protection
Security Feature
Local Manager and Operator
Usernames and Passwords
1
TACACS+
1
RADIUS
SSH
SSL
Port-Based Access Control (802.1X)
Port Security (MAC address)
Authorized IP Managers
1
The local Manager/Operator, TACACS+, and RADIUS options (direct connect or modem access) also offer protection
for serial port access.
1-4
Offers Protection Against Unauthorized Client Access to
Connection
PtP:
1
Remote:
PtP:
Remote:
PtP:
Remote:
Ptp:
Remote:
Ptp:
Remote:
PtP:
Remote:
PtP:
Remote:
PtP:
Remote:

General Switch Traffic Security Guidelines

Where the switch is running multiple security options, it implements network
traffic security based on the OSI (Open Systems Interconnection model)
precedence of the individual options, from the lowest to the highest. The
following list shows the order in which the switch implements configured
security features on traffic moving through a given port.
1.
Disabled/Enabled physical port
2.
MAC lockout (applies to all ports on the switch)
3.
MAC lockdown
4.
Port security
5.
Authorized IP Managers
6.
Application features at higher levels in the OSI model, such as SSH
(The above list does not address the mutually exclusive relationship that
exists among some security features.)
Switch Management Features
Telnet
SNMP
Web
(Net Mgmt)
Browser
Yes
No
Yes
No
Yes
No
Yes
No
Yes
No
Yes
No
Yes
No
Yes
No
No
No
No
No
Yes
Yes
No
No
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Offers Protection
Against
Unauthorized Client
SSH
Access to the
Client
Network
Yes
Yes
Yes
Yes
No
Yes
No
Yes
No
Yes
No
Yes
No
Yes
No
Yes
Yes
No
Yes
No
Yes
Yes
No
No
Yes
Yes
Yes
Yes
Yes
Yes
Yes
Yes
No
No
No
No
No
No
No
No
No
No
Yes
No
Yes
Yes
No
No

Advertisement

Table of Contents
loading

Table of Contents