Alcatel OS6400-24 Guía de usuario Pagina 15

  • Descarga
  • Añadir a mis manuales
  • Imprimir
  • Pagina
    / 55
  • Tabla de contenidos
  • MARCADORES
  • Valorado. / 5. Basado en revisión del cliente
Vista de pagina 14
August 2008
OmniSwitch 6400 ------ Release 6.3.3.R01 Page 15 of 55
Modifying specific ACL entries without having to enter the entire ACL each time to make a change.
The ability to add and display ACL comments.
ACL logging extensions to display Layer 2 through 4 packet information associated with an ACL.
ARP Defense Optimization
This feature enchances how the OmniSwitch can respond to an ARP DoS attack by not adding entires to
the forwarding table until the net hop ARP entry can be resolved.
ARP Poisoning Detection
This feature detects the presence of an ARP-Poisoning host on the network using configured restricted IP
addresses for which the switch, on sending an ARP request, should not get back an ARP response. If an
ARP response is received, the event is logged and the user is alerted using an SNMP trap.
By default ARP requests are not added to the ARP cache. Only router solicited ARP requests will be added
to the cache.
Authenticated Switch Access
Authenticated Switch Access (ASA) is a way of authenticating users who want to manage the switch. With
authenticated access, all switch login attempts using the console or modem port, Telnet, FTP, SNMP, or
HTTP require authentication via the local user database or via a third-party server. The type of server may
be an authentication-only mechanism or an authentication, authorization, and accounting (AAA) mecha-
nism.
AAA servers are able to provide authorization for switch management users as well as authentication.
(They also may be used for accounting.) User login information and user privileges may be stored on the
servers. The following AAA servers are supported on the switch:
Remote Authentication Dial-In User Service (RADIUS). Authentication using this type of server was
certified with Funk/Juniper Steel Belted RADIUS server (any industry standard RADIUS server
should work).
Lightweight Directory Access Protocol (LDAP).
Terminal Access Controller Access Control System (TACACS+).
Authentication-only servers are able to authenticate users for switch management access, but authorization
(or what privileges the user has after authenticating) are determined by the switch. Authentication- only
servers cannot return user privileges to the switch. The authentication-only server supported by the switch
is ACE/Server, which is a part of RSA Security’s SecurID product suite. RSA Security’s ACE/ Agent is
embedded in the switch.
By default, switch management users may be authenticated through the console port via the local user
database. If external servers are configured for other management interfaces but the servers become
unavailable, the switch will poll the local user database for login information if the switch is configured for
local checking of the user database. The database includes information about whether or not a user is able
to log into the switch and what kinds of privileges or rights the user has for managing the switch.
Vista de pagina 14
1 2 ... 10 11 12 13 14 15 16 17 18 19 20 ... 54 55

Comentarios a estos manuales

Sin comentarios