beautypg.com

Brocade FastIron Ethernet Switch Security Configuration Guide User Manual

Page 10

background image

Web Authentication............................................................................................................ 291

Supported Web Authentication features..................................................... 291
Web authentication overview...................................................................... 291
Web authentication configuration considerations....................................... 292
Web authentication configuration tasks...................................................... 294
Enabling and disabling web authentication.................................................295
Web authentication mode configuration......................................................295

Using local user databases.............................................................296
Passcodes for user authentication..................................................299
Automatic authentication.................................................................304

Web authentication options configuration................................................... 304

Enabling RADIUS accounting for web authentication.....................304
Changing the login mode (HTTPS or HTTP).................................. 305
Specifying trusted ports...................................................................305
Specifying hosts that are permanently authenticated .................... 305
Configuring the re-authentication period.........................................306
Defining the web authentication cycle.............................................306
Limiting the number of web authentication attempts.......................306
Clearing authenticated hosts from the webauthentication table..... 307
Setting and clearing the block duration for webauthentication

attempts.....................................................................................307

Manually blocking and unblocking a specific host.......................... 307
Limiting the number of authenticated hosts.................................... 308
Filtering DNS queries......................................................................308
Forcing re-authentication when ports are down..............................308
Forcing re-authentication after an inactive period...........................309
Defining the web authorization redirect address.............................309
Deleting a web authentication VLAN.............................................. 310
Web authentication pages.............................................................. 310

Displaying web authentication information..................................................317

Displaying the web authentication configuration.............................317
Displaying a list of authenticated hosts...........................................319
Displaying a list of hosts attempting to authenticate....................... 320
Displaying a list of blocked hosts.................................................... 320
Displaying a list of local user databases......................................... 321
Displaying a list of users in a local user database.......................... 321
Displaying passcodes..................................................................... 321

DoS Attack Protection.........................................................................................................323

Supported DoS protection features.............................................................323
Smurf attacks.............................................................................................. 323

Avoiding being an intermediary in a Smurf attack...........................324
Avoiding being a victim in a Smurf attack....................................... 324

TCP SYN attacks........................................................................................ 326

TCP security enhancement ............................................................327
Displaying statistics about packets dropped because of DoS

attacks....................................................................................... 328

DHCP................................................................................................................................. 331

Supported DHCP packet inspection and tracking features.........................331
Dynamic ARP inspection ............................................................................331

ARP poisoning................................................................................ 331
About Dynamic ARP Inspection......................................................332
Configuration notes and feature limitations for DAI........................ 333

10

FastIron Ethernet Switch Security Configuration Guide

53-1003088-03