Tcp Flags - Edge Port Security - Brocade Communications Systems ICX 6650 Security Configuration Manual

Hide thumbs Also See for ICX 6650:
Table of Contents

Advertisement

TCP Flags - edge port security

The method1 parameter specifies the primary authentication method. The remaining optional
method parameters specify additional methods to try if an error occurs with the primary method. A
method can be one of the values listed in the Method Parameter column in the following table.
TABLE 11
Method parameter
line
enable
local
tacacs
tacacs+
radius
none
TCP Flags - edge port security
The edge port security feature works in combination with IP ACL rules, and supports all 6 TCP flags
present in the offset 13 of the TCP header:
TCP flags can be combined with other ACL functions (such as dscp-marking and traffic policies),
giving you greater flexibility when designing ACLs.
The TCP flags feature offers two options, match-all and match-any:
60
Authentication method values
Description
Authenticate using the password you configured for Telnet access. The Telnet password is
configured using the enable telnet password... command. Refer to
password"
Authenticate using the password you configured for the Super User privilege level. This
password is configured using the enable super-user-password... command. Refer to
"Setting passwords for management privilege levels"
Authenticate using a local user name and password you configured on the device. Local
user names and passwords are configured using the username... command. Refer to
user account configuration"
Authenticate using the database on a TACACS server. You also must identify the server to
the device using the tacacs-server command.
Authenticate using the database on a TACACS+ server. You also must identify the server to
the device using the tacacs-server command.
Authenticate using the database on a RADIUS server. You also must identify the server to
the device using the radius-server command. Refer to
Do not use any authentication method. The device automatically permits access.
+|- urg = Urgent
+|- ack = Acknowledge
+|- psh = Push
+|- rst = Reset
+|- syn = Synchronize
+|- fin = Finish
Match-any - Indicates that incoming TCP traffic must be matched against any of the TCP flags
configured as part of the match-any ACL rule. In CAM hardware, the number of ACL rules will
match the number of configured flags.
Match-all - Indicates that incoming TCP traffic must be matched against all of the TCP flags
configured as part of the match-all ACL rule. In CAM hardware, there will be only one ACL rule
for all configured flags.
on page 13.
on page 21.
"Setting a Telnet
on page 14.
"RADIUS security"
on page 41.
Brocade ICX 6650 Security Configuration Guide
"Local
53-1002601-01

Advertisement

Table of Contents
loading

Table of Contents