beautypg.com

H3C Technologies H3C S6300 Series Switches User Manual

Page 386

background image

371

security 802.1X authentication,

65

,

66

interface

enabling portal authentication,

96

referencing portal Web server,

97

Internet

security SSL configuration,

306

,

307

Internet Key Exchange. See

IKE

intrusion protection

blockmac mode,

149

disableport mode,

149

disableport-temporarily mode,

149

port security feature,

143

IP

security. Use

IPsec

security ARP unresolvable IP attack

protection,

322

,

324

security ARP unresolvable IP attack protection

(blackhole routing),

323

security ARP unresolvable IP attack protection

(source suppression),

323

security ARP unresolvable IP attack protection

display,

324

IP addressing

security AAA HWTACACS outgoing packet

source IP address,

35

security AAA LDAP server IP address

configuration,

39

security AAA RADIUS outgoing packet source IP

address,

28

security AAA RADIUS security policy server IP
address configuration,

30

security ARP attack protection

configuration,

322

security ARP filtering configuration,

336

security ARP gateway protection,

335

security ARP user/packet validity check,

332

security MFF server IP address

specification,

341

SSH packet source IP address,

275

SSH SFTP packet source IP address,

278

IP source guard

configuration,

311

,

312

,

316

displaying,

316

dynamic binding entry,

312

IPv4. See

IPv4 source guard

IPv6. See

IPv6 source guard

maintaining,

316

static binding entry,

311

ip validity check (ARP),

330

IPsec

ACL configuration,

223

ACL de-encapsulated packet check,

231

ACL IPsec anti-replay configuration,

232

ACL rule keywords,

223

ACL-based implementation,

222

ACL-based IPsec,

221

application-based IPsec,

221

authentication,

220

authentication algorithms,

220

configuration,

217

,

238

configuration restrictions,

225

displaying,

237

encapsulation modes,

218

encryption,

220

encryption algorithms,

220

IKE configuration,

247

,

249

,

259

IKE configuration (main mode/pre-shared key

authentication),

259

IKE DPD configuration,

256

IKE global identity information configuration,

254

IKE identity authentication,

248

IKE invalid SPI recovery,

257

IKE keepalive function configuration,

255

IKE keychain configuration,

253

IKE NAT keepalive function configuration,

256

IKE negotiation,

247

IKE negotiation failure (no proposal or keychain

referenced correctly),

262

IKE negotiation failure troubleshooting (no proposal

match),

261

IKE negotiation mode,

219

IKE profile configuration,

250

IKE proposal configuration,

252

IKE SA max number,

257

IKE security mechanism,

248

IKE SNMP notification,

258

IKE troubleshooting,

261

IKE-based tunnel for IPv4 packets configuration,

241

implementation,

220

IPv6. See

IPv6 IPsec

maintaining,

237