Entering Aggregate Control Plane Configuration Mode
After you create a class of traffic and define the service policy for the control plane, you need to apply the policy to either the aggregate control plane interface or one of the subinterfaces. After you enter the control-plane command, you can define aggregate CoPP policies for the RP. You can configure a service policy to police all traffic destined to the control plane from all line cards on the router (aggregate control plane services). Note Aggregate control plane services manage traffic...
Mitigating Pvlan Proxy Attacks
Router(config) access-list 101 deny ip 172.30.1.0 0.0.0.255 172.30.1.0 0.0.0.255 router(config) access-list 101 permit ip any any router(config-if) ip access-group 101 in Build ACL for subnet and apply ACL to interface 2007 Cisco Systems, Inc. All rights reseived. SNRS v2.0 1-20 Configure access control lists (ACLs) on the router port to mitigate PVLAN attacks. An example of using ACLs on the router port is if a server farm segment existed on subnet 172.30.1.0 24 and target C was in the server...
What Is EAP
EAP the Extensible Authentication Protocol A flexible transport protocol used to carry arbitrary authentication information not the authentication method itself Typically runs directly over data-link layers such as PPP or IEEE 802 media Originally specified in RFC 2284, obsolete by RFC 3748 Supports multiple authentication types 2007 Cisco Systems, Inc. All rights reserved SNRS v2.0 2-10 EAP, based on IETF 802.1x, is an end-to-end framework that allows the creation of authentication types...
Cisco Certified Security Professional
Expand Your Professional Options and Advance Your Career Professional level recognition in Cisco Certified Security Professional Cisco Certified Security Professional Cisco Certified Security Professional 2007 Cisco Systems, Inc. All rights re Recommended Training Through Cisco Learning Partners Securing Cisco Network Devices (SND) Securing Networks with Cisco Routers and Switches (SNRS) Securing Networks with PIX and ASA (SNPA) Implementing Cisco Intrusion Prevention Systems (IPS) Securing...
Configuring Port Security
Switch(config-if) switchport mode access Set the interface mode as access switch(config-if) switchport port-security Enable port security on the interface switchport port-security maximum value Set the maximum number of secure MAC addresses for the interface (optional) 2007 Cisco Systems, Inc. All rights reserved. SNRS V2.0 1-8 Complete these steps to configure port security on an interface. Step 1 Enter interface configuration mode. switch(config) interface FastEthernet 0 8 Step 2 Configure...
TACACS and Radius Comparison
Authentication Authorization 1645 and 1812 Encrypts only passwords up to 16 bytes Separate control of each AAA service 2007 Cisco Systems, Inc. All rights reserved. SNRS v2.0 2-15 2007 Cisco Systems, Inc. All rights reserved. SNRS v2.0 2-15 Cisco Secure ACS conforms to the TACACS+ protocol as defined by Cisco Systems. Cisco Secure ACS conforms to the RADIUS protocol as defined in these RFCs RFC 2138, Remote Authentication Dial In User Service (RADIUS) RFC 2139, RADIUS Accounting RFC 2284, PPP...
Defining a CoPP Service Policy
Use the policy-map global configuration command to specify the service policy name, and use the configuration commands to associate a traffic class that was configured with the class-map command. The traffic class is associated with the service policy when you use the class command. You must then issue the class command after entering policy map configuration mode. After entering the class command, you are automatically in policy map class configuration mode. Follow these steps to define a...
PEAP with MSCHAPv2
EAP Request TLS start EAP Response TLS client hello EAP Request TLS start EAP Response TLS client hello EAP Response TLS Server Hello, Server Cert, Server Key Exchange, Server Hello Done EAP Response Cert Verify, Change Ciph Spec EAP Request TLS Change_Ciph_Spec Identity Request EAP-MS-CHAPv2 Challenge EAP-MS-CHAPV2 Response Identity response EAP-MS-CHAPv2 Challenge This diagram illustrates PEAP with MS-CHAPv2 message exchange between the supplicant, authenticator, and authentication server....
Web Interface
2 S Kh ffiFjvunte Medu 0 G- S Select Log Off to end the administration session. r CiscoSecure ACS v4.0 offers support for multiple AAA Clients and advanced TACACS+ and RADIUS features. It also supports several methods of authorization, authentication, and accounting (AAA) including several one-time-password cards. For more information on CiscoSecure products and upgrades, please visit http www.cisco.com. Copyright 2005 Cisco Systems, Inc. Copyright 1991-1992 RSA Data Security, Inc. MD5...
Working in Cisco Secure ACS
3 11 t3 Search 111 Favorites Media S Select Log Off to end the administration session. r CiscoSecure ACS v4.0 offers support for multiple AAA Clients and advanced TACACS+ and RADIUS features. It also supports several methods of authorization, authentication, and accounting (AAA) including several one-time-password cards. For more information on CiscoSecure products and upgrades, please visit http www.cisco.com. Copyright 2005 Cisco Systems, Inc. Copyright 1991-1992 RSA Data Security, Inc. MD5...

