Aruba Security User guide

  • Hello! I have analyzed the provided document, which is a Security Command Reference for HPE FlexFabric 5940 and 5930 Switch Series. This document provides detailed information about various security commands, including authentication, authorization, and accounting. It covers AAA commands, local user management, RADIUS, HWTACACS, LDAP configurations, connection recording, 802.1X, MAC authentication and Portal setup. I am ready to assist you with your questions regarding these features.
  • What type of commands are covered in this document?
    What are the document versions covered by this manual?
    What is the purpose of the AAA commands?
    What are the key features of 802.1X commands?
HPE FlexFabric 5940 & 5930 Switch Series
Security Command Reference
P
art number: 5200-4883c
Software
version: Release 2609 and later
Document version: 6W103-20200310
© Copyright 2020 Hewlett Packard Enterprise Development LP
The information contained herein is subject to change without notice. The only warranties for Hewlett Packard
Enterprise products and services are set forth in the express warranty statements accompanying such
products and services. Nothing herein should be construed as constituting an additional warranty. Hewlett
Packard Enterprise shall not be liable for technical or editorial errors or omissions contained herein.
Confidential computer software. Valid license from Hewlett Packard Enterprise required for possession, use, or
copying. Consistent with FAR 12.211 and 12.212, Commercial Computer Software, Computer Software
Documentation, and Technical Data for Commercial Items are licensed to the U.S. Government under vendor’s
standard commercial license.
Links to third-party websites take you outside the Hewlett Packard Enterprise website. Hewlett Packard
Enterprise has no control over and is not responsible for information outside the Hewlett Packard Enterprise
website.
Acknowledgments
Intel®, Itanium®, Pentium®, Intel Inside®, and the Intel Inside logo are trademarks of Intel Corporation in the
United States and other countries.
Microsoft® and Windows® are either registered trademarks or trademarks of Microsoft Corporation in the
United States and/or other countries.
Adobe® and Acrobat® are trademarks of Adobe Systems Incorporated.
Java and Oracle are registered trademarks of Oracle and/or its affiliates.
UNIX® is a registered trademark of The Open Group.
i
Contents
AAA commands ····························································································· 1
General AAA commands···································································································································· 1
aaa nas-id profile ········································································································································ 1
aaa session-limit ········································································································································ 2
accounting command ································································································································· 2
accounting default ······································································································································ 3
accounting dual-stack ································································································································ 4
accounting lan-access ································································································································ 5
accounting login ········································································································································· 7
accounting portal ········································································································································ 8
accounting quota-out·································································································································· 9
accounting start-fail ·································································································································· 10
accounting update-fail ······························································································································ 11
authentication default ······························································································································· 11
authentication lan-access ························································································································· 12
authentication login ·································································································································· 14
authentication portal ································································································································· 15
authentication super ································································································································· 16
authorization command ···························································································································· 17
authorization default ································································································································· 18
authorization lan-access ·························································································································· 20
authorization login ···································································································································· 21
authorization portal ··································································································································· 22
authorization-attribute (ISP domain view) ································································································ 23
display domain ········································································································································· 25
domain ····················································································································································· 28
domain default enable ······························································································································ 29
domain if-unknown ··································································································································· 30
nas-id bind vlan ········································································································································ 30
session-time include-idle-time ·················································································································· 31
state (ISP domain view) ··························································································································· 32
Local user commands ······································································································································ 33
access-limit ·············································································································································· 33
authorization-attribute (local user view/user group view) ········································································· 34
bind-attribute ············································································································································ 36
description ················································································································································ 37
display local-user ····································································································································· 37
display user-group ···································································································································· 40
group ························································································································································ 42
local-user ·················································································································································· 42
local-user auto-delete enable ··················································································································· 44
password ·················································································································································· 44
service-type ·············································································································································· 46
state (local user view) ······························································································································ 47
user-group ················································································································································ 47
validity-datetime ······································································································································· 48
RADIUS commands ········································································································································· 49
aaa device-id ············································································································································ 49
accounting-on enable ······························································································································· 50
accounting-on extended ··························································································································· 51
attribute 15 check-mode ··························································································································· 52
attribute 25 car ········································································································································· 52
attribute 31 mac-format ···························································································································· 53
attribute convert (RADIUS DAS view) ······································································································ 54
attribute convert (RADIUS scheme view) ································································································· 55
attribute reject (RADIUS DAS view) ········································································································· 56
attribute reject (RADIUS scheme view) ···································································································· 57
ii
attribute remanent-volume ······················································································································· 58
attribute translate ····································································································································· 59
client ························································································································································· 59
data-flow-format (RADIUS scheme view) ································································································ 60
display radius scheme ······························································································································ 61
display radius statistics ···························································································································· 65
display stop-accounting-buffer (for RADIUS) ··························································································· 66
key (RADIUS scheme view) ····················································································································· 67
nas-ip (RADIUS scheme view)················································································································· 68
port ··························································································································································· 69
primary accounting (RADIUS scheme view) ···························································································· 70
primary authentication (RADIUS scheme view) ······················································································· 71
radius attribute extended ·························································································································· 73
radius dscp ··············································································································································· 74
radius dynamic-author server ··················································································································· 75
radius nas-ip ············································································································································· 76
radius scheme ·········································································································································· 77
radius session-control client ····················································································································· 78
radius session-control enable ·················································································································· 79
radius-server test-profile ·························································································································· 79
reset radius statistics ································································································································ 80
reset stop-accounting-buffer (for RADIUS) ······························································································ 81
retry ·························································································································································· 82
retry realtime-accounting ·························································································································· 83
retry stop-accounting (RADIUS scheme view) ························································································· 84
secondary accounting (RADIUS scheme view) ······················································································· 85
secondary authentication (RADIUS scheme view) ·················································································· 86
server-load-sharing enable ······················································································································ 88
snmp-agent trap enable radius ················································································································ 89
state primary ············································································································································ 90
state secondary ········································································································································ 91
stop-accounting-buffer enable (RADIUS scheme view) ··········································································· 93
stop-accounting-packet send-force ·········································································································· 93
timer quiet (RADIUS scheme view) ·········································································································· 94
timer realtime-accounting (RADIUS scheme view) ·················································································· 95
timer response-timeout (RADIUS scheme view) ······················································································ 96
user-name-format (RADIUS scheme view) ······························································································ 97
vpn-instance (RADIUS scheme view) ······································································································ 98
HWTACACS commands ·································································································································· 98
data-flow-format (HWTACACS scheme view) ························································································· 98
display hwtacacs scheme ························································································································ 99
display stop-accounting-buffer (for HWTACACS) ·················································································· 104
hwtacacs nas-ip ····································································································································· 105
hwtacacs scheme ··································································································································· 106
key (HWTACACS scheme view) ············································································································ 107
nas-ip (HWTACACS scheme view) ········································································································ 108
primary accounting (HWTACACS scheme view) ··················································································· 109
primary authentication (HWTACACS scheme view) ·············································································· 110
primary authorization ······························································································································ 112
reset hwtacacs statistics ························································································································ 113
reset stop-accounting-buffer (for HWTACACS) ····················································································· 114
retry stop-accounting (HWTACACS scheme view) ················································································ 114
secondary accounting (HWTACACS scheme view) ·············································································· 115
secondary authentication (HWTACACS scheme view) ········································································· 116
secondary authorization ························································································································· 118
stop-accounting-buffer enable (HWTACACS scheme view) ·································································· 120
timer quiet (HWTACACS scheme view) ································································································· 120
timer realtime-accounting (HWTACACS scheme view) ········································································· 121
timer response-timeout (HWTACACS scheme view) ············································································· 122
user-name-format (HWTACACS scheme view) ····················································································· 122
vpn-instance (HWTACACS scheme view) ····························································································· 123
LDAP commands ··········································································································································· 124
iii
attribute-map ·········································································································································· 124
authentication-server ······························································································································ 125
authorization-server ······························································································································· 126
display ldap scheme ······························································································································· 126
ip ···························································································································································· 128
ipv6 ························································································································································· 129
ldap attribute-map ·································································································································· 130
ldap scheme ··········································································································································· 130
ldap server ············································································································································· 131
login-dn ·················································································································································· 132
login-password ······································································································································· 132
map ························································································································································ 133
protocol-version ······································································································································ 134
search-base-dn ······································································································································ 135
search-scope ·········································································································································· 135
server-timeout ········································································································································ 136
user-parameters ····································································································································· 137
Connection recording policy commands ········································································································ 138
aaa connection-recording policy ············································································································ 138
accounting hwtacacs-scheme ················································································································ 138
display aaa connection-recording policy ································································································ 139
802.1X commands ····················································································· 141
display dot1x ·········································································································································· 141
display dot1x connection ························································································································ 145
display dot1x mac-address ···················································································································· 147
dot1x ······················································································································································ 149
dot1x access-user log enable ················································································································ 150
dot1x after-mac-auth max-attempt ········································································································· 150
dot1x authentication-method ·················································································································· 151
dot1x auth-fail vlan ································································································································· 152
dot1x auth-fail vsi ··································································································································· 153
dot1x critical eapol ································································································································· 154
dot1x critical vlan ···································································································································· 155
dot1x critical vsi ······································································································································ 155
dot1x critical-voice-vlan ·························································································································· 156
dot1x domain-delimiter ··························································································································· 157
dot1x ead-assistant enable ···················································································································· 158
dot1x ead-assistant free-ip ····················································································································· 159
dot1x ead-assistant url ··························································································································· 159
dot1x eapol untag··································································································································· 160
dot1x guest-vlan ····································································································································· 161
dot1x guest-vlan-delay ··························································································································· 162
dot1x guest-vsi ······································································································································· 163
dot1x guest-vsi-delay ····························································································································· 164
dot1x handshake ···································································································································· 165
dot1x handshake reply enable ··············································································································· 165
dot1x handshake secure ························································································································ 166
dot1x mac-binding ·································································································································· 167
dot1x mac-binding enable ······················································································································ 168
dot1x mandatory-domain ······················································································································· 168
dot1x max-user ······································································································································ 169
dot1x multicast-trigger ···························································································································· 170
dot1x port-control ··································································································································· 171
dot1x port-method ·································································································································· 171
dot1x quiet-period ·································································································································· 172
dot1x re-authenticate ····························································································································· 173
dot1x re-authenticate manual················································································································· 173
dot1x re-authenticate server-unreachable keep-online ·········································································· 174
dot1x retry ·············································································································································· 174
dot1x timer ············································································································································· 175
dot1x timer reauth-period ······················································································································· 177
iv
dot1x unicast-trigger ······························································································································· 178
dot1x user-ip freeze ······························································································································· 179
reset dot1x guest-vlan ···························································································································· 179
reset dot1x guest-vsi ······························································································································ 180
reset dot1x statistics ······························································································································· 180
MAC authentication commands ································································· 181
display mac-authentication ····················································································································· 181
display mac-authentication connection ·································································································· 184
display mac-authentication mac-address ······························································································· 186
mac-authentication ································································································································· 188
mac-authentication access-user log enable ··························································································· 189
mac-authentication carry user-ip ············································································································ 189
mac-authentication critical vlan ·············································································································· 190
mac-authentication critical vsi ················································································································ 191
mac-authentication critical-voice-vlan ···································································································· 192
mac-authentication domain ···················································································································· 193
mac-authentication guest-vlan ··············································································································· 194
mac-authentication guest-vsi ················································································································· 195
mac-authentication guest-vlan auth-period ···························································································· 196
mac-authentication guest-vsi auth-period ······························································································ 196
mac-authentication host-mode ··············································································································· 197
mac-authentication max-user ················································································································· 198
mac-authentication offline-detect enable ······························································································· 198
mac-authentication parallel-with-dot1x··································································································· 199
mac-authentication re-authenticate ········································································································ 200
mac-authentication re-authenticate server-unreachable keep-online ···················································· 201
mac-authentication timer (system view) ································································································· 202
mac-authentication timer (interface view) ······························································································ 203
mac-authentication user-name-format ··································································································· 204
reset mac-authentication critical vlan ····································································································· 205
reset mac-authentication critical vsi ······································································································· 206
reset mac-authentication critical-voice-vlan ··························································································· 206
reset mac-authentication guest-vlan ······································································································ 207
reset mac-authentication guest-vsi ········································································································ 207
reset mac-authentication statistics ········································································································· 208
Portal commands ······················································································· 209
default-logon-page ································································································································· 209
display portal ·········································································································································· 209
display portal packet statistics················································································································ 212
display portal rule ··································································································································· 214
display portal server ······························································································································· 219
display portal user ·································································································································· 220
display portal web-server ······················································································································· 225
display web-redirect rule ························································································································ 227
if-match ·················································································································································· 228
ip ···························································································································································· 230
ipv6 ························································································································································· 231
port ························································································································································· 232
portal { bas-ip | bas-ipv6 } ······················································································································ 233
portal { ipv4-max-user | ipv6-max-user } ································································································ 234
portal apply web-server ·························································································································· 234
portal authorization strict-checking········································································································· 235
portal delete-user ··································································································································· 236
portal device-id ······································································································································· 237
portal domain ········································································································································· 237
portal enable ·········································································································································· 238
portal fail-permit server ·························································································································· 239
portal free-all except destination ············································································································ 240
portal free-rule ········································································································································ 241
portal free-rule destination ····················································································································· 242
v
portal free-rule source ···························································································································· 243
portal ipv6 free-all except destination····································································································· 244
portal ipv6 layer3 source ························································································································ 245
portal ipv6 user-detect ···························································································································· 246
portal layer3 source ································································································································ 247
portal local-web-server ··························································································································· 248
portal log enable ····································································································································· 249
portal max-user ······································································································································ 250
portal nas-id-profile ································································································································ 251
portal nas-port-id format ························································································································· 252
portal pre-auth domain ··························································································································· 254
portal pre-auth ip-pool ···························································································································· 255
portal refresh enable ······························································································································ 256
portal roaming enable ···························································································································· 257
portal server ··········································································································································· 258
portal user-detect ··································································································································· 258
portal user-dhcp-only ····························································································································· 260
portal web-proxy port ····························································································································· 261
portal web-server ··································································································································· 261
reset portal packet statistics ··················································································································· 262
server-detect (portal authentication server view) ··················································································· 263
server-detect (portal Web server view) ·································································································· 264
server-type ············································································································································· 265
tcp-port ··················································································································································· 265
url ··························································································································································· 266
url-parameter ·········································································································································· 267
user-sync ················································································································································ 269
vpn-instance ··········································································································································· 270
web-redirect url ······································································································································ 270
Web authentication commands ·································································· 272
display web-auth ···································································································································· 272
display web-auth free-ip ························································································································· 273
display web-auth server ························································································································· 273
display web-auth user ···························································································································· 274
ip ···························································································································································· 275
redirect-wait-time ···································································································································· 276
url ··························································································································································· 277
url-parameter ·········································································································································· 278
web-auth auth-fail vlan ··························································································································· 279
web-auth domain ···································································································································· 280
web-auth enable ····································································································································· 280
web-auth free-ip ····································································································································· 281
web-auth max-user ································································································································ 282
web-auth offline-detect ··························································································································· 282
web-auth proxy port ······························································································································· 283
web-auth server ····································································································································· 284
Port security commands ············································································ 286
display port-security ······························································································································· 286
display port-security mac-address block ································································································ 289
display port-security mac-address security ···························································································· 290
port-security access-user log enable ····································································································· 291
port-security authentication open ··········································································································· 292
port-security authentication open global ································································································ 292
port-security authorization ignore ··········································································································· 293
port-security authorization-fail offline ····································································································· 294
port-security enable ································································································································ 295
port-security escape critical-vsi ·············································································································· 296
port-security global escape critical-vsi ··································································································· 297
port-security intrusion-mode ··················································································································· 299
port-security mac-address aging-type inactivity ····················································································· 299
vi
port-security mac-address dynamic ······································································································· 300
port-security mac-address security ········································································································ 301
port-security mac-limit ···························································································································· 303
port-security mac-move permit··············································································································· 304
port-security max-mac-count ·················································································································· 304
port-security nas-id-profile ······················································································································ 306
port-security ntk-mode ··························································································································· 306
port-security oui ······································································································································ 307
port-security port-mode ·························································································································· 308
port-security timer autolearn aging········································································································· 310
port-security timer disableport ················································································································ 312
snmp-agent trap enable port-security ···································································································· 312
User profile commands ·············································································· 314
display user-profile ································································································································· 314
user-profile ············································································································································· 315
Password control commands ····································································· 316
display password-control ························································································································ 316
display password-control blacklist ·········································································································· 317
password-control { aging | composition | history | length } enable ························································· 318
password-control aging ·························································································································· 320
password-control alert-before-expire ····································································································· 321
password-control complexity ·················································································································· 321
password-control composition ················································································································ 322
password-control enable ························································································································ 324
password-control expired-user-login ······································································································ 325
password-control history ························································································································ 325
password-control length ························································································································· 326
password-control login idle-time ············································································································· 328
password-control login-attempt ·············································································································· 328
password-control super aging ················································································································ 331
password-control super composition ······································································································ 331
password-control super length ··············································································································· 332
password-control update-interval ··········································································································· 333
reset password-control blacklist ············································································································· 334
reset password-control history-record ···································································································· 334
Keychain commands ················································································· 336
accept-lifetime utc ·································································································································· 336
accept-tolerance ····································································································································· 337
authentication-algorithm ························································································································· 337
default-send-key ····································································································································· 338
display keychain ····································································································································· 339
key ·························································································································································· 340
keychain ················································································································································· 341
key-string ················································································································································ 341
send-lifetime utc ····································································································································· 342
tcp-algorithm-id ······································································································································ 343
tcp-kind ··················································································································································· 344
Public key management commands ·························································· 345
display public-key local public ················································································································ 345
display public-key peer ··························································································································· 348
peer-public-key end ································································································································ 350
public-key local create ···························································································································· 351
public-key local destroy ·························································································································· 354
public-key local export dsa ····················································································································· 355
public-key local export ecdsa ················································································································· 357
public-key local export rsa ······················································································································ 359
public-key peer ······································································································································· 360
public-key peer import sshkey················································································································ 361
vii
PKI commands ·························································································· 363
attribute ·················································································································································· 363
ca identifier ············································································································································· 364
certificate request entity ························································································································· 365
certificate request from ··························································································································· 366
certificate request mode ························································································································· 366
certificate request polling ······················································································································· 367
certificate request url ······························································································································ 368
common-name ······································································································································· 369
country ··················································································································································· 370
crl check ················································································································································· 370
crl url ······················································································································································ 371
display pki certificate access-control-policy ··························································································· 372
display pki certificate attribute-group ······································································································ 373
display pki certificate domain ················································································································· 374
display pki certificate request-status ······································································································ 379
display pki crl domain ····························································································································· 380
fqdn ························································································································································ 382
ip ···························································································································································· 383
ldap-server ············································································································································· 383
locality ···················································································································································· 384
organization ············································································································································ 385
organization-unit ····································································································································· 385
pki abort-certificate-request ···················································································································· 386
pki certificate access-control-policy ········································································································ 387
pki certificate attribute-group ·················································································································· 387
pki delete-certificate ······························································································································· 388
pki domain ·············································································································································· 390
pki entity ················································································································································· 390
pki export ················································································································································ 391
pki import ················································································································································ 398
pki request-certificate ····························································································································· 402
pki retrieve-certificate ····························································································································· 403
pki retrieve-crl ········································································································································· 405
pki storage ·············································································································································· 406
pki validate-certificate ····························································································································· 407
public-key dsa ········································································································································ 409
public-key ecdsa ···································································································································· 410
public-key rsa ········································································································································· 411
root-certificate fingerprint ······················································································································· 412
rule ························································································································································· 414
source ···················································································································································· 415
state ······················································································································································· 416
usage ····················································································································································· 416
IPsec commands ······················································································· 418
ah authentication-algorithm ···················································································································· 418
description ·············································································································································· 419
display ipsec { ipv6-policy | policy } ········································································································ 419
display ipsec { ipv6-policy-template | policy-template } ·········································································· 424
display ipsec profile ································································································································ 426
display ipsec sa ······································································································································ 427
display ipsec statistics ···························································································································· 431
display ipsec transform-set ···················································································································· 433
display ipsec tunnel ································································································································ 434
encapsulation-mode ······························································································································· 437
esn enable ·············································································································································· 438
esp authentication-algorithm ·················································································································· 438
esp encryption-algorithm ························································································································ 439
ike-profile ················································································································································ 441
ikev2-profile ············································································································································ 442
viii
ipsec { ipv6-policy | policy } ···················································································································· 443
ipsec { ipv6-policy | policy } isakmp template ························································································· 444
ipsec { ipv6-policy | policy } local-address ······························································································ 445
ipsec { ipv6-policy-template | policy-template } ······················································································ 446
ipsec anti-replay check ··························································································································· 447
ipsec anti-replay window ························································································································ 447
ipsec apply ············································································································································· 448
ipsec decrypt-check enable ···················································································································· 449
ipsec df-bit ·············································································································································· 449
ipsec fragmentation ································································································································ 450
ipsec global-df-bit ··································································································································· 451
ipsec limit max-tunnel ····························································································································· 452
ipsec logging packet enable ··················································································································· 452
ipsec profile ············································································································································ 453
ipsec redundancy enable ······················································································································· 454
ipsec sa global-duration ························································································································· 454
ipsec sa idle-time ··································································································································· 455
ipsec transform-set ································································································································· 456
local-address ·········································································································································· 457
pfs ·························································································································································· 457
protocol ·················································································································································· 458
qos pre-classify ······································································································································ 459
redundancy replay-interval ····················································································································· 459
remote-address ······································································································································ 460
reset ipsec sa ········································································································································· 462
reset ipsec statistics ······························································································································· 463
reverse-route dynamic ··························································································································· 463
reverse-route preference ························································································································ 464
reverse-route tag ···································································································································· 465
sa duration ············································································································································· 466
sa hex-key authentication ······················································································································ 467
sa hex-key encryption ···························································································································· 468
sa idle-time ············································································································································· 469
sa spi ······················································································································································ 470
sa string-key ··········································································································································· 471
security acl ············································································································································· 472
snmp-agent trap enable ipsec ················································································································ 474
tfc enable ················································································································································ 475
transform-set ·········································································································································· 475
IKE commands ·························································································· 477
authentication-algorithm ························································································································· 477
authentication-method ···························································································································· 478
certificate domain ··································································································································· 478
description ·············································································································································· 480
dh ··························································································································································· 480
display ike proposal ································································································································ 481
display ike sa ·········································································································································· 482
display ike statistics ································································································································ 485
dpd ························································································································································· 486
encryption-algorithm ······························································································································· 487
exchange-mode ····································································································································· 488
ike dpd ···················································································································································· 489
ike identity ·············································································································································· 489
ike invalid-spi-recovery enable ··············································································································· 490
ike keepalive interval ······························································································································ 491
ike keepalive timeout ······························································································································ 492
ike keychain ··········································································································································· 493
ike limit ··················································································································································· 493
ike nat-keepalive ···································································································································· 494
ike profile ················································································································································ 495
ike proposal ············································································································································ 495
ix
ike signature-identity from-certificate ····································································································· 496
inside-vpn ··············································································································································· 497
keychain ················································································································································· 498
local-identity ··········································································································································· 498
match local address (IKE keychain view)······························································································· 499
match local address (IKE profile view) ··································································································· 500
match remote ········································································································································· 501
pre-shared-key ······································································································································· 503
priority (IKE keychain view) ···················································································································· 504
priority (IKE profile view) ························································································································ 505
proposal ················································································································································· 505
reset ike sa ············································································································································· 506
reset ike statistics ··································································································································· 507
sa duration ············································································································································· 507
snmp-agent trap enable ike ···················································································································· 508
IKEv2 commands······················································································· 510
address ·················································································································································· 510
authentication-method ···························································································································· 510
certificate domain ··································································································································· 512
config-exchange ····································································································································· 513
dh ··························································································································································· 513
display ikev2 policy ································································································································ 514
display ikev2 profile ································································································································ 515
display ikev2 proposal ···························································································································· 517
display ikev2 sa ······································································································································ 518
display ikev2 statistics ···························································································································· 522
dpd ························································································································································· 523
encryption ··············································································································································· 524
hostname ··············································································································································· 525
identity ···················································································································································· 526
identity local ··········································································································································· 527
ikev2 cookie-challenge ··························································································································· 527
ikev2 dpd ················································································································································ 528
ikev2 keychain ········································································································································ 529
ikev2 nat-keepalive ································································································································ 530
ikev2 policy ············································································································································· 530
ikev2 profile ············································································································································ 531
ikev2 proposal ········································································································································ 532
inside-vrf ················································································································································· 533
integrity ··················································································································································· 534
keychain ················································································································································· 535
match local (IKEv2 profile view) ············································································································· 536
match local address (IKEv2 policy view) ································································································ 537
match remote ········································································································································· 537
match vrf (IKEv2 policy view) ················································································································· 539
match vrf (IKEv2 profile view) ················································································································ 540
nat-keepalive ·········································································································································· 540
peer ························································································································································ 541
pre-shared-key ······································································································································· 542
prf ··························································································································································· 543
priority (IKEv2 policy view) ····················································································································· 544
priority (IKEv2 profile view) ···················································································································· 545
proposal ················································································································································· 545
reset ikev2 sa ········································································································································· 546
reset ikev2 statistics ······························································································································· 547
sa duration ············································································································································· 548
SSH commands ························································································· 549
SSH server commands ·································································································································· 549
display ssh server ·································································································································· 549
display ssh user-information ·················································································································· 550
x
free ssh ·················································································································································· 551
scp server enable ··································································································································· 552
sftp server enable ··································································································································· 553
sftp server idle-timeout ··························································································································· 553
ssh server acl ········································································································································· 554
ssh server acl-deny-log enable ·············································································································· 555
ssh server authentication-retries ············································································································ 555
ssh server authentication-timeout ·········································································································· 556
ssh server compatible-ssh1x enable ······································································································ 557
ssh server dscp ······································································································································ 558
ssh server enable ··································································································································· 558
ssh server ipv6 acl ································································································································· 559
ssh server ipv6 dscp ······························································································································ 559
ssh server key-re-exchange enable ······································································································· 560
ssh server pki-domain ···························································································································· 561
ssh server port ······································································································································· 561
ssh server rekey-interval ························································································································ 562
ssh user ·················································································································································· 563
SSH client commands ···································································································································· 565
bye ························································································································································· 565
cd ··························································································································································· 566
cdup ······················································································································································· 566
delete ····················································································································································· 567
delete ssh client server-public-key ········································································································· 567
dir ··························································································································································· 568
display scp client source ························································································································ 569
display sftp client source ························································································································ 569
display ssh client server-public-key ········································································································ 570
display ssh client source ························································································································ 571
exit ·························································································································································· 571
get ·························································································································································· 572
help ························································································································································ 572
ls ····························································································································································· 573
mkdir ······················································································································································ 574
put ·························································································································································· 574
pwd ························································································································································· 575
quit ························································································································································· 575
remove ··················································································································································· 575
rename ··················································································································································· 576
rmdir ······················································································································································· 576
scp ·························································································································································· 577
scp client ipv6 source ····························································································································· 580
scp client source ···································································································································· 581
scp ipv6 ·················································································································································· 581
scp ipv6 suite-b ······································································································································ 585
scp suite-b ·············································································································································· 586
sftp ························································································································································· 588
sftp client ipv6 source ····························································································································· 590
sftp client source ···································································································································· 591
sftp ipv6 ·················································································································································· 592
sftp ipv6 suite-b ······································································································································ 595
sftp suite-b ·············································································································································· 596
ssh client ipv6 source ····························································································································· 598
ssh client source ···································································································································· 598
ssh2 ························································································································································ 599
ssh2 ipv6 ················································································································································ 602
ssh2 ipv6 suite-b ···································································································································· 605
ssh2 suite-b ············································································································································ 607
SSH2 commands ··········································································································································· 609
display ssh2 algorithm ···························································································································· 609
ssh2 algorithm cipher ····························································································································· 609
ssh2 algorithm key-exchange ················································································································ 610
xi
ssh2 algorithm mac ································································································································ 611
ssh2 algorithm public-key ······················································································································· 612
SSL commands ························································································· 614
ciphersuite ·············································································································································· 614
client-verify ············································································································································· 616
display crypto version ····························································································································· 617
display ssl client-policy ··························································································································· 618
display ssl server-policy ························································································································· 618
pki-domain (SSL client policy view) ········································································································ 619
pki-domain (SSL server policy view) ······································································································ 620
prefer-cipher ··········································································································································· 621
server-verify enable ································································································································ 623
session ··················································································································································· 623
ssl client-policy ······································································································································· 624
ssl renegotiation disable ························································································································· 625
ssl server-policy ····································································································································· 625
ssl version disable ·································································································································· 626
version ···················································································································································· 627
Attack detection and prevention commands ·············································· 629
ack-flood action ······································································································································ 629
ack-flood detect ······································································································································ 629
ack-flood detect non-specific ·················································································································· 630
ack-flood threshold ································································································································· 631
attack-defense local apply policy ··········································································································· 632
attack-defense login reauthentication-delay··························································································· 633
attack-defense policy ····························································································································· 633
attack-defense signature log non-aggregate·························································································· 634
attack-defense tcp fragment enable ······································································································· 635
display attack-defense flood statistics ip ································································································ 635
display attack-defense flood statistics ipv6 ···························································································· 637
display attack-defense policy ················································································································· 638
display attack-defense policy ip ············································································································· 642
display attack-defense policy ipv6 ·········································································································· 644
display attack-defense scan attacker ip ································································································· 646
display attack-defense scan attacker ipv6 ····························································································· 647
display attack-defense scan victim ip ····································································································· 648
display attack-defense scan victim ipv6 ································································································· 649
display attack-defense statistics local ···································································································· 650
dns-flood action ······································································································································ 654
dns-flood detect ······································································································································ 654
dns-flood detect non-specific ················································································································· 656
dns-flood port ········································································································································· 656
dns-flood threshold ································································································································· 657
exempt acl ·············································································································································· 658
fin-flood action ········································································································································ 659
fin-flood detect ········································································································································ 660
fin-flood detect non-specific ··················································································································· 661
fin-flood threshold ··································································································································· 661
http-flood action ······································································································································ 662
http-flood detect ····································································································································· 663
http-flood detect non-specific ················································································································· 664
http-flood port ········································································································································· 665
http-flood threshold ································································································································ 665
icmp-flood action ···································································································································· 666
icmp-flood detect ip ································································································································ 667
icmp-flood detect non-specific················································································································ 668
icmp-flood threshold ······························································································································· 668
icmpv6-flood action ································································································································ 669
icmpv6-flood detect ipv6 ························································································································ 670
icmpv6-flood detect non-specific ············································································································ 671
xii
icmpv6-flood threshold ··························································································································· 672
reset attack-defense policy flood ············································································································ 673
reset attack-defense statistics local ······································································································· 673
rst-flood action ········································································································································ 674
rst-flood detect ······································································································································· 674
rst-flood detect non-specific ··················································································································· 675
rst-flood threshold ·································································································································· 676
scan detect ············································································································································· 677
signature { large-icmp | large-icmpv6 } max-length ················································································ 678
signature detect ······································································································································ 678
signature level action ····························································································································· 681
signature level detect ····························································································································· 682
syn-ack-flood action ······························································································································· 683
syn-ack-flood detect ······························································································································· 684
syn-ack-flood detect non-specific ··········································································································· 685
syn-ack-flood threshold ·························································································································· 686
syn-flood action ······································································································································ 686
syn-flood detect ······································································································································ 687
syn-flood detect non-specific ·················································································································· 688
syn-flood threshold ································································································································· 689
udp-flood action ······································································································································ 690
udp-flood detect ····································································································································· 690
udp-flood detect non-specific ················································································································· 691
udp-flood threshold ································································································································ 692
TCP attack prevention commands ····························································· 694
tcp anti-naptha enable···························································································································· 694
tcp check-state interval ·························································································································· 694
tcp state ·················································································································································· 695
IP source guard commands ······································································· 697
display ip source binding ························································································································ 697
display ipv6 source binding ···················································································································· 698
display ipv6 source binding pd ··············································································································· 700
ip source binding (interface view) ··········································································································· 701
ip source binding (system view) ············································································································· 702
ip verify source ······································································································································· 703
ipv6 source binding (interface view) ······································································································· 704
ipv6 source binding (system view) ········································································································· 705
ipv6 verify source ··································································································································· 706
ARP attack protection commands ······························································ 707
Unresolvable IP attack protection commands ································································································ 707
arp resolving-route enable ····················································································································· 707
arp resolving-route probe-count ············································································································· 707
arp resolving-route probe-interval ·········································································································· 708
arp source-suppression enable ·············································································································· 708
arp source-suppression limit ·················································································································· 709
display arp source-suppression ············································································································· 710
ARP packet rate limit commands ··················································································································· 710
arp rate-limit ··········································································································································· 710
arp rate-limit log enable ·························································································································· 711
arp rate-limit log interval ························································································································· 711
snmp-agent trap enable arp ··················································································································· 712
Source MAC-based ARP attack detection commands ·················································································· 713
arp source-mac ······································································································································ 713
arp source-mac aging-time ···················································································································· 714
arp source-mac exclude-mac ················································································································· 714
arp source-mac threshold ······················································································································ 715
display arp source-mac ·························································································································· 715
ARP packet source MAC consistency check commands··············································································· 716
arp valid-check enable ··························································································································· 716
xiii
ARP active acknowledgement commands ····································································································· 717
arp active-ack enable ····························································································································· 717
Authorized ARP commands ··························································································································· 717
arp authorized enable ···························································································································· 717
ARP attack detection commands ··················································································································· 718
arp detection enable······························································································································· 718
arp detection log enable ························································································································· 719
arp detection port-match-ignore ············································································································· 719
arp detection rule ··································································································································· 720
arp detection trust ·································································································································· 721
arp detection validate ····························································································································· 721
arp restricted-forwarding enable ············································································································ 722
display arp detection ······························································································································ 723
display arp detection statistics attack-source ························································································· 723
display arp detection statistics packet-drop ··························································································· 724
reset arp detection statistics attack-source ···························································································· 725
reset arp detection statistics packet-drop ······························································································· 725
ARP scanning and fixed ARP commands ······································································································ 726
arp fixup ················································································································································· 726
arp scan ················································································································································· 727
ARP gateway protection commands ·············································································································· 728
arp filter source ······································································································································ 728
ARP filtering commands································································································································· 729
arp filter binding ······································································································································ 729
ARP packet sender IP address checking commands ···················································································· 729
arp sender-ip-range ································································································································ 729
ND attack defense commands ··································································· 731
Source MAC consistency check commands ·································································································· 731
ipv6 nd check log enable························································································································ 731
ipv6 nd mac-check enable ····················································································································· 731
ND attack detection commands ····················································································································· 732
display ipv6 nd detection statistics ········································································································· 732
ipv6 nd detection enable ························································································································ 733
ipv6 nd detection trust ···························································································································· 733
reset ipv6 nd detection statistics ············································································································ 734
RA guard commands ····································································································································· 734
display ipv6 nd raguard policy ················································································································ 734
display ipv6 nd raguard statistics ··········································································································· 735
if-match acl ············································································································································· 736
if-match autoconfig managed-address-flag ···························································································· 737
if-match autoconfig other-flag ················································································································· 737
if-match hop-limit ···································································································································· 738
if-match prefix ········································································································································· 739
if-match router-preference ······················································································································ 740
ipv6 nd raguard apply policy ·················································································································· 740
ipv6 nd raguard log enable····················································································································· 741
ipv6 nd raguard policy ···························································································································· 742
ipv6 nd raguard role ······························································································································· 742
reset ipv6 nd raguard statistics ·············································································································· 743
uRPF commands ······················································································· 744
display ip urpf ········································································································································· 744
ip urpf ····················································································································································· 744
MFF commands ························································································· 746
display mac-forced-forwarding interface ································································································ 746
display mac-forced-forwarding vlan ······································································································· 746
mac-forced-forwarding ··························································································································· 747
mac-forced-forwarding gateway probe ··································································································· 748
mac-forced-forwarding network-port ······································································································ 748
mac-forced-forwarding server ················································································································ 749
xiv
Crypto engine commands ·········································································· 751
display crypto-engine ····························································································································· 751
display crypto-engine statistics ·············································································································· 751
reset crypto-engine statistics ·················································································································· 753
FIPS commands ························································································ 754
display fips status ··································································································································· 754
fips mode enable ···································································································································· 754
fips self-test ············································································································································ 756
MACsec commands ··················································································· 758
confidentiality-offset ······························································································································· 758
display macsec ······································································································································· 759
display mka policy ·································································································································· 761
display mka session ······························································································································· 762
display mka statistics ····························································································································· 765
macsec cipher-suite ······························································································································· 766
macsec confidentiality-offset ·················································································································· 767
macsec desire ········································································································································ 768
macsec mka-session log enable ············································································································ 768
macsec replay-protection enable ··········································································································· 769
macsec replay-protection window-size ·································································································· 770
macsec validation mode ························································································································· 771
mka apply policy ····································································································································· 771
mka enable ············································································································································· 772
mka policy ·············································································································································· 773
mka priority ············································································································································· 774
mka psk ·················································································································································· 775
replay-protection enable ························································································································· 776
replay-protection window-size ················································································································ 777
reset mka session ·································································································································· 778
reset mka statistics ································································································································· 778
validation mode ······································································································································ 779
Document conventions and icons ······························································ 780
Conventions ··················································································································································· 780
Network topology icons ·································································································································· 781
Support and other resources ····································································· 782
Accessing Hewlett Packard Enterprise Support····························································································· 782
Accessing updates ········································································································································· 782
Websites ················································································································································ 783
Customer self repair ······························································································································· 783
Remote support ······································································································································ 783
Documentation feedback ······················································································································· 783
Index ·········································································································· 785
1
AAA commands
The device supports the FIPS mode that complies with NIST FIPS 140-2 requirements. Support for
features, commands, and parameters might differ in FIPS mode and non-FIPS mode. For more
information about FIPS mode, see Security Configuration Guide.
General AAA commands
aaa nas-id profile
Use aaa nas-id profile to create a NAS-ID profile and enter its view, or enter the view of an existing
NAS-ID profile.
Use undo aaa nas-id profile to delete a NAS-ID profile.
Syntax
aaa nas-id profile profile-name
undo aaa nas-id profile profile-name
Default
No NAS-ID profiles exist.
Views
System view
Predefined user roles
network-admin
Parameters
profile-name: Specifies the NAS-ID profile name, a case-insensitive string of 1 to 31 characters.
Usage guidelines
Configure a NAS-ID profile to maintain NAS-ID and VLAN bindings on the device.
By default, the device sends its device name in the NAS-Identifier attribute of all RADIUS requests.
A NAS-ID profile enables you to send different NAS-Identifier attribute strings in RADIUS requests
from different VLANs. The strings can be organization names, service names, or any user
categorization criteria, depending on the administrative requirements.
For example, map the NAS-ID companyA to all VLANs of company A. The device will send
companyA in the NAS-Identifier attribute for the RADIUS server to identify requests from any
Company A users.
Examples
# Create a NAS-ID profile named aaa and enter its view.
<Sysname> system-view
[Sysname] aaa nas-id profile aaa
[Sysname-nas-id-prof-aaa]
Related commands
nas-id bind vlan
port-security nas-id-profile
2
portal nas-id-profile
aaa session-limit
Use aaa session-limit to set the maximum number of concurrent users that can log on to the device
through the specified method.
Use undo aaa session-limit to restore the default maximum number of concurrent users for the
specified login method.
Syntax
In non-FIPS mode:
aaa session-limit { ftp | http | https | ssh | telnet } max-sessions
undo aaa session-limit { ftp | http | https | ssh | telnet }
In FIPS mode:
aaa session-limit { https | ssh } max-sessions
undo aaa session-limit { https | ssh }
Default
The maximum number of concurrent users is 32 for each user type.
Views
System view
Predefined user roles
network-admin
Parameters
ftp: FTP users.
http: HTTP users.
https: HTTPS users.
ssh: SSH users.
telnet: Telnet users.
max-sessions: Specifies the maximum number of concurrent login users. The value range is 1 to 32
for FTP, SSH, and Telnet services, and is 1 to 64 for HTTP and HTTPS services.
Usage guidelines
After the maximum number of concurrent login users for a user type exceeds the upper limit, the
system denies the subsequent users of this type.
Examples
# Set the maximum number of concurrent FTP users to 4.
<Sysname> system-view
[Sysname] aaa session-limit ftp 4
accounting command
Use accounting command to specify the command line accounting method.
Use undo accounting command to restore the default.
3
Syntax
accounting command hwtacacs-scheme hwtacacs-scheme-name
undo accounting command
Default
The default accounting methods of the ISP domain are used for command line accounting.
Views
ISP domain view
Predefined user roles
network-admin
Parameters
hwtacacs-scheme hwtacacs-scheme-name: Specifies an HWTACACS scheme by its name, a
case-insensitive string of 1 to 32 characters.
Usage guidelines
The command line accounting feature works with the accounting server to record valid commands
that have been successfully executed on the device.
•
When the command line authorization feature is disabled, the accounting server records all
valid commands that have been successfully executed.
•
When the command line authorization feature is enabled, the accounting server records only
authorized commands that have been successfully executed.
Command line accounting can use only a remote HWTACACS server.
Examples
# In ISP domain test, perform command line accounting based on HWTACACS scheme hwtac.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] accounting command hwtacacs-scheme hwtac
Related commands
accounting default
command accounting (Fundamentals Command Reference)
hwtacacs scheme
accounting default
Use accounting default to specify default accounting methods for an ISP domain.
Use undo accounting default to restore the default.
Syntax
In non-FIPS mode:
accounting default { hwtacacs-scheme hwtacacs-scheme-name [ radius-scheme
radius-scheme-name ] [ local ] [ none ] | local [ none ] | none | radius-scheme
radius-scheme-name [ hwtacacs-scheme hwtacacs-scheme-name ] [ local ] [ none ] }
undo accounting default
In FIPS mode:
4
accounting default { hwtacacs-scheme hwtacacs-scheme-name [ radius-scheme
radius-scheme-name ] [ local ] | local | radius-scheme radius-scheme-name [ hwtacacs-scheme
hwtacacs-scheme-name ] [ local ] }
undo accounting default
Default
The default accounting method of an ISP domain is local.
Views
ISP domain view
Predefined user roles
network-admin
Parameters
hwtacacs-scheme hwtacacs-scheme-name: Specifies an HWTACACS scheme by its name, a
case-insensitive string of 1 to 32 characters.
local: Performs local accounting.
none: Does not perform accounting.
radius-scheme radius-scheme-name: Specifies a RADIUS scheme by its name, a case-insensitive
string of 1 to 32 characters.
Usage guidelines
The default accounting method is used for all users that support this method and do not have an
accounting method configured.
Local accounting is only used for monitoring and controlling the number of local user connections. It
does not provide the statistics function that the accounting feature generally provides.
You can specify one primary default accounting method and multiple backup default accounting
methods.
When the primary method is invalid, the device attempts to use the backup methods in sequence.
For example, the accounting default radius-scheme radius-scheme-name local none command
specifies the primary default RADIUS accounting method and two backup methods (local accounting
and no accounting). The device performs RADIUS accounting by default and performs local
accounting when the RADIUS server is invalid. The device does not perform accounting when both
of the previous methods are invalid.
Examples
# In ISP domain test, use RADIUS scheme rd as the primary default accounting method and use
local accounting as the backup.
<Sysname> system-view
[Sysname] domain test
[Sysname-isp-test] accounting default radius-scheme rd local
Related commands
hwtacacs scheme
local-user
radius scheme
accounting dual-stack
Use accounting dual-stack to specify the accounting method for dual-stack users.
Use undo accounting dual-stack to restore the default.
/