Best Practices: Server Security Hardening

Size: px
Start display at page:

Download "Best Practices: Server Security Hardening"

Transcription

1 The following sections explain how to enhance server security by eliminating or controlling individual points of security exposure. Disable Web Root Access, on page 1 Use SMPv3 Instead of SMPv2, on page 2 Authenticate With External AAA, on page 3 Enable OCSP Settings on the Prime Infrastructure Server, on page 5 Set Up Local Password Policies, on page 5 Disable Individual TCP/UDP Ports, on page 6 Check on Server Security Status, on page 7 Configure Prime Infrastructure in FIPS Mode, on page 8 Disable Web Root Access During installation, Prime Infrastructure also creates a web root user account, prompting the installer for the password to be used for this account. The web root account is needed to enable first-time login to the Prime Infrastructure server and its web user interface. We recommend that you never use this account for normal operations. Instead, use it to create user IDs with appropriate privileges for day-to-day operations and network management, and administrative user IDs for managing Prime Infrastructure itself. Once these user accounts are created, disable the default web root account created at install time, and create user accounts using your administrative user IDs thereafter. To disable the Web root accounts: Open a CLI session with the Prime Infrastructure server (seehow to Connect Via CLI ). Do not enter configure terminal mode. Disable the web root account by entering the following command: PIServer/admin# ncs webroot disable Prime Infrastructure disables the web root account. ote Root shell access is disabled in FIPS release by default and it cannot be enabled. 1

2 Use SMPv3 Instead of SMPv2 Use SMPv3 Instead of SMPv2 Prime Infrastructure 3.2 FIPS supports both SHA-1 and SHA-2 Certificates Chain Key Size: 2048 Bit Chain SMPv3 is a higher-security protocol than SMPv2. You can enhance the security of communications between your network devices and the Prime Infrastructure server by configuring the managed devices so that management takes place using SMPv3 instead of SMPv2. You can choose to enable SMPv3 when adding new devices, when importing devices in bulk, or as part of device discovery. See Related Topics for instruction on how to perform each task. Inventory Section To add device using IPSec parameter, certificate from same CA should be applied in Prime Infrastructure and Device. Choose Inventory > Device Management > etwork Devices. After providing SMP and CLI credentials, add IPSec parameter to make Prime Infrastructure to Device Communication an FIPS Compliant. There are 2 different modes: Transport and Tunnel. SMP v2/v3 is supported via FIPS IPSEC Parameter format Ex1: C=in, ST=tn, L=che, O=hcl, OU=cisco, C=FIPS72.cisco.com Ex2: C=in, ST=tn, L=che, O=hcl, OU=cisco, C=FIPS73.cisco.com, E=abc@abc.com Related Topics Use SMPv3 to Add Devices, on page 2 Use SMPv3 to Import Devices, on page 3 Use SMPv3 to Run Discovery, on page 3 Use SMPv3 to Add Devices To specify SMPv3 when adding a new device: Select Inventory > Device Management > etwork Devices Choose Add Device. In the SMP Parameters area, in Version, select v3. Step 4 Complete the other fields as appropriate, then click Add. Related Topics Use SMPv3 to Import Devices, on page 3 Use SMPv3 to Run Discovery, on page 3 Use SMPv3 Instead of SMPv2, on page 2 2

3 Use SMPv3 to Import Devices Use SMPv3 to Import Devices To specify use of SMPv3 when importing devices in bulk: Step 4 Step 5 Select Inventory > Device Management > etwork Devices. Choose Bulk Import. The Bulk Import page appears. Download the device add sample template from the here link on the Bulk Import page. Edit the template file using any CSV-compatible application. For each row representing a device in the CSV import file: a) In the snmp version column, enter 3. b) Enter appropriate values in the snmpv3_user_name, snmpv3_auth_type, snmpv3_auth_password, snmpv3_privacy_type, and snmpv3_privacy_password columns. c) Complete other columns as appropriate for your devices. Select Inventory > Device Management > etwork Devices, then click Bulk Import and import your modified CSV file. Related Topics Use SMPv3 to Add Devices, on page 2 Use SMPv3 to Run Discovery, on page 3 Use SMPv3 Instead of SMPv2, on page 2 Use SMPv3 to Run Discovery To specify SMPv3 as part of device discovery: Step 4 Step 5 Select Inventory > Device Management > Discovery. The Discovery Jobs page appears. Click the Discovery Settings link in the upper right corner of the page. The Discovery Settings page appears. Choose ew to add new SMP v3 credentials. Complete the fields as needed. Click Save to save the SMPv3 settings and use them thereafter. Related Topics Use SMPv3 to Add Devices, on page 2 Use SMPv3 to Import Devices, on page 3 Use SMPv3 Instead of SMPv2, on page 2 Authenticate With External AAA User accounts and password are managed more securely when they are managed centrally, by a dedicated, remote authentication server running a secure authentication protocol such as RADIUS or TACACS+. You can configure Prime Infrastructure to authenticate users using external AAA servers. You will need to access the Administration > Users > Users, Roles & AAA page to set up external authentication via the 3

4 Set Up External AAA Via GUI Prime Infrastructure graphic user interface (GUI). You can also set up external authentication via the command line interface (CLI). See Related Topics for instructions on how to set up AAA using each method. Related Topics Set Up External AAA Via GUI, on page 4 Set Up External AAA Via CLI, on page 4 Set Up External AAA Via GUI To set up remote user authentication via the GUI: Step 4 Step 5 Log in to Prime Infrastructure with a user ID that has administrator privileges. Select Administration > Users > Users, Roles & AAA > TACACS+ or Administration > Users > Users, Roles & AAA > RADIUS. Enter the TACACS+ or RADIUS server IP address and shared secret in the appropriate fields. Select Administration > Users > Users, Roles & AAA > AAA Mode Settings. Set the AAA mode as appropriate. Related Topics Authenticate With External AAA, on page 3 Set Up External AAA Via CLI, on page 4 Set Up External AAA Via CLI To set up remote user authentication via the CLI: Log in to Prime Infrastructure using the command line, as explained in How to Connect Via CLI. Be sure to enter configure terminal mode. At the prompt, enter the following command to setup an external TACACS+ server: PIServer/admin/terminal# aaa authentication tacacs+ server tacacs-ip key plain shared-secret Where: tacacs-ip is the IP address of an active TACACS+ server. shared-secret is the plain-text shared secret for the active TACACS+ server. At the prompt, enter the following command to create a user with administrative authority, who will be authenticated by the above AAA server: PIServer/admin/terminal# username username password remote role admin id Where: username is the name of the user ID. password is the plain-text password for the user. 4

5 Enable OCSP Settings on the Prime Infrastructure Server id is the address of the user (optional). Related Topics Authenticate With External AAA, on page 3 Set Up External AAA Via GUI, on page 4 Enable OCSP Settings on the Prime Infrastructure Server Online Certificate Status Protocol (OCSP) enables certificate-based authentication for web clients using OCSP responders. Typically, the OCSP responder s URL is read from the certificate s Authority Information Access (AIA). As a failover mechanism, you can configure the same URL on the Prime Infrastructure server as well To set up a custom URL of an OCSP responder, follow the steps below. Log in to the Prime Infrastructure server using the command line, as explained in How to Connect Via CLI. Do not enter configure terminal mode. At the prompt, enter the following command to enable client certificate authentication: PIServer/admin# ocsp responder custom enable At the prompt, enter the following command to set the custom OCSP responder URL: PIServer/admin# ocsp responder set url Responder#URL Where: Responder# is the number of the OCSP responder you want to define (e.g., 1 or 2). URL is the URL of the OCSP responder, as taken from the client CA certificate. ote that there should be no space between the Responder# and URL values. Step 4 To delete an existing custom OCSP responder defined on the Prime Infrastructure server, use the following command: PIServer/admin# ocsp responder clear url Responder# If you do not already know the number of the OCSP responder you want to delete, use the show security-status command to view the OCSP responders currently configured on the server. For details, see Check on Server Security Status, on page 7. Set Up Local Password Policies If you are authenticating users locally, using Prime Infrastructure s own internal authentication, you can enhance your system s security by enforcing rules for strong password selection. ote that these policies affect only the passwords for local Prime Infrastructure user IDs. If you are authenticating Prime Infrastructure users via a centralized or remote AAA server, you can enforce similar protections using the functions of the AAA server. 5

6 Disable Individual TCP/UDP Ports To enforce local password policies: Log in to Prime Infrastructure with a user ID that has administrator privileges. Select Administration > Users > Users, Roles & AAA > Local Password Policy. Select the check boxes next to the password policies you want to enforce, including: The minimum number of characters passwords must contain. o use of the username or cisco as a password (or common permutations of these). o use of public in root passwords. o more than three consecutive repetitions of any password character. Passwords must contain at least one character from three of the following character classes: upper case, lower case, digit, and special character. Whether the password must contain only ASCII characters. Minimum elapsed number of days before a password can be reused. Password expiration period. Advance warnings for password expirations. If you enable any of the following password policies, you can also specify: The minimum password length, in number of characters. The minimum elapsed time between password re-uses. The password expiry period. The number of days in advance to start warning users about future password expiration. Step 4 Click Save. Disable Individual TCP/UDP Ports The following table lists the TCP and UDP ports Prime Infrastructure uses, the names of the services communicating over these ports, and the product s purpose in using them. The Safe column indicates whether you can disable a port and service without affecting Prime Infrastructure s functionality. Table 1: Prime Infrastructure TCP/UDP Ports Port Service ame Purpose Safe? 21/tcp FTP File transfer between devices and server Y 22/tcp SSHD Used by SCP, SFTP, and SSH connections to and from the system 69/udp TFTP File transfer between devices and the server Y 6

7 Check on Server Security Status Port Service ame Purpose Safe? 80/tcp HTTP Provisioning of exus devices Y 162/udp SMP-TRAP To receive SMP Traps 443/tcp HTTPS Primary Web Interface to the product 514/udp SYSLOG To receive Syslog messages 1522/tcp Oracle Oracle/JDBC Database connections: These include both internal server connections and for connections with the High Availability peer server. 8082/tcp HTTPS Health Monitoring ote You must check the Login Disclaimer Acknowledgment check box, to log in to the Health Monitor web page. 8087/tcp HTTPS Software updates on HA Secondary Systems ote You must check the Login Disclaimer Acknowledgment check box, to log in to the Software Update web page. 9991/udp ETFLOW To receive etflow streams (enabled if Assurance license installed) 9992/tcp PI Tomcat Process Lync Monitoring in Assurance 61617/tcp JMS (over TCP) For interaction with remote Plug&Play Gateway server Check on Server Security Status Prime Infrastructure administrators can connect to the server via CLI and use the show security-status command to display the server s currently open TCP/UDP ports, the status of other services the system is using, and other security-related configuration information. For example: Log in to Prime Infrastructure using the command line, as explained in Connecting Via CLI. Do not enter configure terminal mode. Enter the following command at the prompt: test-vm-237/admin# show security-status Depending on your settings, you will see output like the following: Open TCP Ports : Open UDP Ports : FIPS Mode : enabled on FIPS SSH Client Ciphers : disabled TFTP Service : disabled FTP Service : disabled 7

8 Configure Prime Infrastructure in FIPS Mode JMS port (61617) : disabled Root Access : disabled TLS versions : TLSv1.2 TLS ciphers : tls-ecdhe,tls-dhe,tls-static ote : Shows currently configured values. Changes made after last system start if any, will be effective after next restart test-vm-237/admin# Configure Prime Infrastructure in FIPS Mode Federal Information Processing Standards (FIPS) are U.S. government computer-security standards. The FIPS-140 series of standards specifies requirements for cryptography modules. For a more complete description, see Prime Infrastructure s FIPS mode is intended for customers who have requirements to use products which are compliant with the FIPS-140 standards referenced above. Installing Prime Infrastructure in FIPS mode disables use of certain capabilities in order to comply with the cryptographic security requirements of FIPS-140. For more information, see Prime Infrastructure FIPS Mode Details, on page 9 Please note: If you install Prime Infrastructure in FIPS mode, internal libraries are automatically setup for operating in FIPS compliant mode, hence you can not switch to non-fips mode or vice versa after the installation. You have to do a fresh installation of the product with appropriate version (FIPS or non-fips) to switch to FIPS mode from non-fips mode or vice versa. For the steps to install Prime Infrastructure in FIPS mode, see the sectioninstalling the Server in the Cisco Prime Infrastructure Quick Start Guide. FIPS Cryptographic Security Details Prime Infrastructure integrates the following FIPS approved cryptographic modules: 1. CiscoSSL FIPS Object Module (FOM) Version 6.0, FIPS Certificate # Red Hat Enterprise Linux Libreswan Cryptographic Module, FIPS Certificate #2721 In the Prime Infrastructure implementation: 1. Each of the integrated cryptographic modules mentioned above are initialized in a manner that is compliant with their individual security policies. 2. All cryptographic algorithms used for TLS, SSH and SPV3 are offloaded to CiscoSSL FIPS Object Module Version 6.0, FIPS Certificate # All cryptographic algorithms used for IPSec secure connection uses the Red Hat Enterprise Linux Libreswan Cryptographic Module, FIPS Certificate #

9 Prime Infrastructure FIPS Mode Details Prime Infrastructure FIPS Mode Details When you install Prime Infrastructure in FIPS mode, the following insecure services will be disabled by default. You should avoid enabling them in order to ensure FIPS/CC compliant operations. TFTP service (used for internal operations like image transfer to/from managed devices) FTP service (used for internal operations like image transfer to/from managed devices) SMP server Any managed device or any other applications or services interacting with Prime Infrastructure should confirm to the following protocol, ciphers, key and certificate requirement in order to ensure proper operations. Incoming Connections to Services All secure services will be running in FIPS/Common Criteria (CC) compliance mode. These service will use only FIPS compliant keys and ciphers listed below. All cryptographic operations used in these services are offloaded to CiscoSSL FIPS Object Module, version 6.0, FIPS Certificate #2505. SSH Service (CLI login for administrators) RSA, ECDSA AES256-CBC, AES128-CBC, AES256-GCM, AES128-GCM SHA2-512, SHA2-256, SHA1 ecdh-sha2-nistp521, ecdh-sha2-nistp384, ecdh-sha2-nistp256, diffie-hellman-group14-sha1 Secure Copy (SCP) and SFTP Services ( Used for file transfer for internal operations such as image transfer between the managed devices.) RSA, ECDSA AES256-CBC, AES128-CBC, AES256-GCM, AES128-GCM SHA2-512, SHA2-256, SHA1 ecdh-sha2-nistp521, ecdh-sha2-nistp384, ecdh-sha2-nistp256, diffie-hellman-group14-sha1 HTTPS Service (Web UI, BI) TLSv1.2 enabled by default, TLSv1.1 can be enabled TLS_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_256_CBC_SHA256, TLS_DHE_RSA_WITH_AES_128_CBC_SHA, TLS_DHE_RSA_WITH_AES_128_CBC_SHA256,TLS_DHE_RSA_WITH_AES_256_CBC_SHA,TLS_DHE_RSA_WITH_AES_256_CBC_SHA256, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 9

10 Outgoing Client Connections: By default, insecure protocols are not used for the out going client connections in order to guarantee FIPS compliant operations. We recommend you to configure and use secure protocols. All secure clients will operate in FIPS/CC compliant mode and only the following FIPS/CC compliant ciphers/keys will be used. All cryptographic operations are offloaded to CiscoSSL FIPS Object Module, version 6.0, FIPS Certificate #2505 Telnet client (for communicating to network device) ot recommended to use. SSH Client (for communicating to network devices) AES128-CBC, AES256-CBC, AES256-GCM, AES128-GCM SHA2-256, SHA2-512, SHA1 diffie-hellman-group14-sha1, diffie-hellman-group14-sha256, diffie-hellman-group15-sha512, diffie-hellman-group16-sha512, diffie-hellman-group17-sha512, diffie-hellman-group18-sha512 ote Do not user Telnet client for communication. You can enable additional non-compliant ciphers (such as AES128-CTR, AES192-CTR, 3des-cbc, HMAC-SHA1-96, diffie-hellman-group-exchange-sha1, diffie-hellman-group-exchange-sha256 and diffie-hellman-group1-sha1) using the following CLI command, but this does not guarantee FIPS/CC compliant operations. ncs run sshclient-nonfips-ciphers [enable disable] HTTPS Client (for communicating to network devices and other applications like ISE, Cisco Services, Audit server) TLSv1.2, TLSv1.1 TLS_RSA_WITH_AES_128_CBC_SHA, TLS_RSA_WITH_AES_256_CBC_SHA256, TLS_DHE_RSA_WITH_AES_128_CBC_SHA, TLS_DHE_RSA_WITH_AES_128_CBC_SHA256,TLS_DHE_RSA_WITH_AES_256_CBC_SHA,TLS_DHE_RSA_WITH_AES_256_CBC_SHA256, TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA, TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256, TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 Certificate presented by the HTTPS server will be validated. Make sure that: The certificate path terminates with a trusted CA certificate. Certificates have the Server Authentication purpose in the extendedkeyusage field. You install proper certificate, because default keys are generated as per FIPS/CC requirements. A trusted CA reviews and updates the certificate. We recommend to use SMPv3 with AES/SHA or IPSec tunnel for securing SMP trap for FIPS complaint operations. Using SMPv2 or SMPv3 with DES/MD5 are not FIPS compliant. 10

11 Using IPSec Certificate-Based Authentication With FIPS Mode SMPv2 SMPv3 AES-256, AES-198, AES-128 SHA1 Refer Cisco Products Support page for all device related documentaion. Using IPSec Certificate-Based Authentication With FIPS Mode For enhanced security, Prime Infrastructure supports IPSec certificate-based authentication only. This authentication takes place during the IKE/ISAKMP tunnel-establishment negotiation between Prime Infrastructure and the devices it manages. The certificates installed on each device and on Prime Infrastructure should be signed by a common Certificate Authority (CA). To set up certificate-based authentication between Prime Infrastructure and the devices it manages, you must perform the following tasks: 1. Generate a Certificate Signing Request (CSR) and send it to a Certificate Authority (CA) for verification. 2. Import the returned CA certificate to the Prime Infrastructure server (both primary and secondary, if using High Availability features). 3. Import the same CA certificate to the devices Prime Infrastructure will manage. Instructions on how to perform each of these actions are given in the Related Topics. ote Only certificate-based authentication is supported for IPSec in Prime Infrastructure. In Prime Infrastrucutre Wired devices - Only SMP, Syslog and Traps are communicated through Tunnel.In Prime Infrastrucutre Wireless devices - Only SMP is communicated through Tunnel. The following cryptographic operations in IPSec communications are performed by Red Hat Enterprise Linux LibreswanCryptographic Module, FIPS Certificate #2721. IKEv1/IKEv2 We recommend to use IKEv1 for both Wired Device and WLCs. RSA AES-128-CBC, AES-192-CBC, AES-256-CBC, AES-128-GCM, AES-256-GCM SHA2-256, SHA2-384, SHA2-512, SHA1 Generate the Certificate Related Topics Generate the Certificate, on page 11 Importing the Certificate to Prime Infrastructure, on page 12 To generate a CSR, get it signed by a Certificate Authority (CA), and ready it for import: 11

12 Importing the Certificate to Prime Infrastructure Step 4 Step 5 Log in to Prime Infrastructure using the command line, as explained in How to Connect Via CLI. Do not enter configure terminal mode. At the prompt, enter the following command to generate the CSR: ncs key genkey -newdn -csr test.csr repository defaultrepo This will generate the CSR file test.csr in the Prime Infrastructure server s default repository. Copy test.csr to a file storage resource to which you have all access rights. For example: copy disk:/defaultrepo/test.csr sftp://your.ftp.server. Submit the test.csr file to the third-party Certificate Authority for verification and signing. Depending on the CA, you may need to the file, or paste its contents into a web form. You will receive the server and CA certificates from the CA. For example: C.cer - The server certificate. C is replaced with the common name of the CA (e.g., MyCompany CA ). CA.cer - The CA certificate from the signing authority. You may receive more than one of these files, with various names. Step 6 Copy all the certificate files from your file resource back to the default repository. For example: copy sftp://your.ftp.server/c.cer disk:defaultrepo copy sftp://your.ftp.server/ca.cer disk:defaultrepo You are now ready to import the certificates into the Prime Infrastructure server, as explained in Importing the Certificate to Prime Infrastructure, on page 12. Importing the Certificate to Prime Infrastructure Once you have received and prepared the signed CA certificate (as explained in Generate the Certificate, on page 11 ), you must import it to the Prime Infrastructure server. If you are using Prime Infrastructure s High Availability (HA) features, you will need to import it into both the primary and secondary servers. Step 4 If you have not already done so, log in to Prime Infrastructure using the command line, as explained in How to Connect Via CLI. Do not enter configure terminal mode. At the prompt, enter the following command to import the CA certificate file: ncs key importcacert CA-Alias CA.cer repository defaultrepo If you have more than one CA certificate file: Repeat this step for each CA cert file. Finally, import the C.cer file into the server: ncs key importsignedcert C.cer repository defaultrepo Restart the Prime Infrastructure server to apply the changes: ncs stop 12

13 Generate CSR Certificate for Wired Devices ncs start Generate CSR Certificate for Wired Devices Generate CSR. The following example shows how to generate CSR using Open SSL: bash-4.1# openssl genrsa -des3 -out ngwc.pem 2048 Enter pass phrase for ngwc.pem: <<Password>> Verifying - Enter pass phrase for ngwc.pem: <<Password>> bash-4.1# bash-4.1# openssl req -new -key ngwc.pem -out cert.csr Enter pass phrase for ngwc.pem: <<Password>> Country ame (2 letter code) [XX]:US State or Province ame (full name) []:SJ Locality ame (eg, city) [Default City]:SJ Organization ame (eg, company) [Default Company Ltd]: cisco Organizational Unit ame (eg, section) []:cisco Common ame (eg, your name or your server's hostname) []:polaris-edison.cisco.com Address []: <<Mail id - OPTIOAL>> Please enter the following 'extra' attributes to be sent with your certificate request A challenge password []: <OPTIOAL> An optional company name []: <OPTIOAL> [root@babandi01-ova GWC]# We have generated CSR and PEM (key) files. Provide CSR file to CA to get the ROOT CA certificate and Signed Device certificate. Import CA Certificate in Wired Devices Login to wired device. To import ROOT CA certificate, Key file and Signed Device certificate. Copy and paste the below sample code block in the device CLI: conf t crypto pki trustpoint <CA Server ame> enrollment terminal PEM crl optional exit crypto pki import SSL-CA pem exportable terminal password <Password> ** <Password> - Provide the password used while generating Private key before CSR Generation. ** Open the ROOT CA certificate received from CA, copy entire contents and paste the same here including BEGI and ED. Type quit and press enter once pasted. ** Open Private key file generated from openssl, copy entire contents and paste the same here including BGI and ED. Type quit and press enter once pasted. ** Open etwork Device Certificate received from CA, copy entire contents and paste the same here including BGI and ED. Type quit and press enter once pasted. ote: Certificate import will be successful if certificates are valid one. Validate the CA certificate. 13

14 Configure IPSEC in Wired Device To validate whether the certificate is imported successfully, enter show crypto pki certificates command. The parameter is used to manage the network device in Prime Infrastructure application and considered as IPSEC parameter. Certificate Status: Available Certificate Serial umber (hex): <<SERIAL-o>> Certificate Usage: General Purpose Issuer: cn=<<c-ame>> o=<<issued-orgaizatio>> c=<<issued COUTRY>> Subject: ame: <<FQD AME>> e=<< ID PROVIDED WHILE GEERATIG CSR>> cn=<<fqd AME>> ou=<<orgaisatio UIT provided while generating CSR>> o=<<issued-orgaizatio>> l=<<city provided while generating CSR>> st=<<state provided while generating CSR>> c=<<coutry provided while generating CSR>> CRL Distribution Points: <<Distributor CRL>> Validity Date: start date: 16:10:33 UTC Oct end date: 16:20:33 UTC Oct Associated Trustpoints: SSL-CA Configure IPSEC in Wired Device The following example shows how to configure devices properly for IPSec communication: conf t crypto ikev2 proposal <PROPOSAL-AME> encryption aes-cbc-256 integrity sha1 sha256 group 14 crypto ikev2 policy <POLICY-AME> match address local <<ETWORK DEVICE IP>> proposal <PROPOSAL-AME> 14

15 Configure IPSec between Prime Infrastructure and Wireless LA controllers crypto ikev2 authorization policy <POLICY-AME> crypto isakmp policy 1 encr aes 256 hash sha authentication rsa-sig Certiifcate group 14 lifetime exit --> This key word assures the authentication happened using SSL CA crypto isakmp identity dn ---> This key word only makes the communication happened using IPSEC parameters. This is simply called as Subject D. crypto pki certificate map CERTMAP 10 subject-name co c = in crypto isakmp profile <PROFILE-AME> ca trust-point SSL-CA match certificate CERTMAP crypto ipsec transform-set aes256-sha1 esp-aes 256 esp-sha-hmac mode tunnel Mode. This can be Tunnel or Transport exit ip access-list extended <<ACCESS-LIST-AME>> permit udp host <<ETWORK-DEVICE-IP>> host <<APPLICATIO-SERVER-IP>> crypto map <MAP-AME> 1 ipsec-isakmp set peer <<APPLICATIO-SERVER-IP>> set transform-set aes256-sha1 set isakmp-profile <PROFILE-AME> match address <<ACCESS-LIST-AME>> exit interface <Managment-interface> crypto map <MAP-AME> ---> This Command binds the crypto map to the interface exit exit ote The default lifetime configuration value of IKE/IPSEC on Prime Infrastructure is 28800/3600. IKE/IPSEC lifetime value should be same for both the device and Prime Infrastructure. Configure IPSec between Prime Infrastructure and Wireless LA controllers To configure IPSec between Prime Infrastructure and wireless LA controllers, you must generate CSR certificates for Cisco Wireless LA Controllers (WLCs), import certificates to WLCs, and configuring IPSec for WLCs. For more details, see Generate CSR for Third-Party Certificates and Download Chained Certificates to the WLC. Remember that the certificates installed on each device and on Prime Infrastructure should be signed by a common Certificate Authority (CA). Manage Devices in Prime Infrastructure Follow the below steps to add devices in Prime Infrastructure: 15

16 How to Use High Availability With FIPS Mode Before you begin Refer "Configure IPSec between Prime Infrastructure and Wireless LA controllers" to generate the CSR and install the signed certificate. You should also enable the FIPS pre-requisites in WLC. Ensure that the SSL certificates are signed by common Certificate Authority(CA) and imported in Prime Infrastrucutre server. Step 4 Choose Inventory > Device Management > etwork Devices Click the Add icon above the etwork Devices table, then choose Add Device. Enter the General, SMP and Telnet/SSH parameters. Click IPsec tab. a) Select Enable IPSec Communication check box. b) Select Transport from the Mode dropdownlist. c) Enter the following in the Certificate Subject D field. The subject name available in the device under Certificate after issuing show crypto pki certificate" command, for wired devices. The subject name available in the device under IPSec Device Certificate details" after issuing show certificate ipsec certificate" command, for wireless LA devices. d) Leave the Others filed empty for wired devices, and enter "forceencaps= yes or no" (depending on the network) for wireless LA. Step 5 Click Add. Device will be added successfully. How to Use High Availability With FIPS Mode For details on running Prime Infrastructure in FIPS mode with high availability functionality, see How to Set Up HA in FIPS Mode. ote The Database synchronization happens through IPSec tunnel during HA operations. Using Backup and Restore With FIPS Mode Backup and restore of a Prime Infrastructure server installed in FIPS mode works the same way as with servers not installed in FIPS mode. ote, however, that you cannot restore data backed up from a server not installed in FIPS mode to a server installed in FIPS mode. Similarly, data backed up from a server installed in FIPS mode cannot be restored to a server not installed in FIPS mode. Using Operations Center With FIPS Mode Use of Operations Center is not supported with any Prime Infrastructure server installed in FIPS mode. 16

Best Practices: Server Security Hardening

Best Practices: Server Security Hardening The following sections explain how to enhance server security by eliminating or controlling individual points of security exposure. Disable Insecure Services, on page 1 Disable Root Access, on page 1 Use

More information

Contents. Configuring SSH 1

Contents. Configuring SSH 1 Contents Configuring SSH 1 Overview 1 How SSH works 1 SSH authentication methods 2 SSH support for Suite B 3 FIPS compliance 3 Configuring the device as an SSH server 4 SSH server configuration task list

More information

Security Certifications Compliance

Security Certifications Compliance , page 1 Enable FIPS Mode, page 2 Enable Common Criteria Mode, page 3 Generate the SSH Host Key, page 3 Configure IPSec Secure Channel, page 4 Configure Static CRL for a Trustpoint, page 9 About the Certificate

More information

Configure Site Network Settings

Configure Site Network Settings About Global Network Settings, page 1 About Device Credentials, page 2 Configure Global Device Credentials, page 4 Configure IP Address Pools, page 9 Configure Global Network Servers, page 9 Configure

More information

Configuring the Cisco APIC-EM Settings

Configuring the Cisco APIC-EM Settings Logging into the Cisco APIC-EM, page 1 Quick Tour of the APIC-EM Graphical User Interface (GUI), page 2 Configuring the Prime Infrastructure Settings, page 3 Discovery Credentials, page 4 Security, page

More information

FIPS Mode Setup

FIPS Mode Setup This chapter provides information about FIPS 140-2 mode setup. FIPS 140-2 Setup, page 1 FIPS Mode Restrictions, page 9 FIPS 140-2 Setup Caution FIPS mode is only supported on releases that have been through

More information

FIPS Management. FIPS Management Overview. Configuration Changes in FIPS Mode

FIPS Management. FIPS Management Overview. Configuration Changes in FIPS Mode This chapter contains the following sections: Overview, on page 1 Configuration Changes in FIPS Mode, on page 1 Switching the Appliance to FIPS Mode, on page 2 Encrypting Sensitive Data in FIPS Mode, on

More information

About FIPS, NGE, and AnyConnect

About FIPS, NGE, and AnyConnect About FIPS, NGE, and AnyConnect, on page 1 Configure FIPS for the AnyConnect Core VPN Client, on page 4 Configure FIPS for the Network Access Manager, on page 5 About FIPS, NGE, and AnyConnect AnyConnect

More information

UCS Manager Communication Services

UCS Manager Communication Services Communication Protocols, page 1 Communication Services, page 1 Non-Secure Communication Services, page 3 Secure Communication Services, page 5 Network-Related Communication Services, page 12 Communication

More information

Let's Encrypt - Free SSL certificates for the masses. Pete Helgren Bible Study Fellowship International San Antonio, TX

Let's Encrypt - Free SSL certificates for the masses. Pete Helgren Bible Study Fellowship International San Antonio, TX Let's Encrypt - Free SSL certificates for the masses Pete Helgren Bible Study Fellowship International San Antonio, TX Agenda Overview of data security Encoding and Encryption SSL and TLS Certficate options

More information

MWA Deployment Guide. VPN Termination from Smartphone to Cisco ISR G2 Router

MWA Deployment Guide. VPN Termination from Smartphone to Cisco ISR G2 Router MWA Deployment Guide Mobile Workforce Architecture: VPN Deployment Guide for Microsoft Windows Mobile and Android Devices with Cisco Integrated Services Router Generation 2 This deployment guide explains

More information

Configuring SSL. SSL Overview CHAPTER

Configuring SSL. SSL Overview CHAPTER 7 CHAPTER This topic describes the steps required to configure your ACE appliance as a virtual Secure Sockets Layer (SSL) server for SSL initiation or termination. The topics included in this section are:

More information

Managing Certificates

Managing Certificates Loading an Externally Generated SSL Certificate, page 1 Downloading Device Certificates, page 4 Uploading Device Certificates, page 6 Downloading CA Certificates, page 8 Uploading CA Certificates, page

More information

FlexVPN Between a Router and an ASA with Next Generation Encryption Configuration Example

FlexVPN Between a Router and an ASA with Next Generation Encryption Configuration Example FlexVPN Between a Router and an ASA with Next Generation Encryption Configuration Example Document ID: 116008 Contributed by Graham Bartlett, Cisco TAC Engineer. Mar 26, 2013 Contents Introduction Prerequisites

More information

Configure System Settings

Configure System Settings About System Settings, on page 1 View the Overview in System 360, on page 1 View the Services in System 360, on page 3 About DNA Center and Cisco ISE Integration, on page 4 Configure Authentication and

More information

BIG-IP System: SSL Administration. Version

BIG-IP System: SSL Administration. Version BIG-IP System: SSL Administration Version 13.0.0 Table of Contents Table of Contents About SSL Administration on the BIG-IP System...7 About SSL administration on the BIG-IP system... 7 Device Certificate

More information

Managing User Accounts

Managing User Accounts Configuring Guest User Accounts, page 1 Configuring Administrator Usernames and Passwords, page 4 Changing the Default Values for SNMP v3 Users, page 6 Generating a Certificate Signing Request, page 7

More information

Managing Certificates

Managing Certificates CHAPTER 12 The Cisco Identity Services Engine (Cisco ISE) relies on public key infrastructure (PKI) to provide secure communication for the following: Client and server authentication for Transport Layer

More information

Configuring SSL CHAPTER

Configuring SSL CHAPTER 7 CHAPTER This chapter describes the steps required to configure your ACE appliance as a virtual Secure Sockets Layer (SSL) server for SSL initiation or termination. The topics included in this section

More information

MSE System and Appliance Hardening Guidelines

MSE System and Appliance Hardening Guidelines MSE System and Appliance Hardening Guidelines This appendix describes the hardening of MSE, which requires some services and processes to be exposed to function properly. This is referred to as MSE Appliance

More information

Configuring Certificate Authorities and Digital Certificates

Configuring Certificate Authorities and Digital Certificates CHAPTER 43 Configuring Certificate Authorities and Digital Certificates Public Key Infrastructure (PKI) support provides the means for the Cisco MDS 9000 Family switches to obtain and use digital certificates

More information

Configuring SSH with x509 authentication on IOS devices

Configuring SSH with x509 authentication on IOS devices Configuring SSH with x509 authentication on IOS devices Contents Introduction Prerequisites Requirements Components Used Configure Network Diagram Deployment considerations Configurations (Optional) Integration

More information

Use Plug and Play to Deploy New Devices

Use Plug and Play to Deploy New Devices About Plug and Play, page 1 Prerequisites for Using Plug and Play, page 2 Plug and Play Workflow, page 2 Use the Plug and Play Dashboard to Monitor New Device Deployments, page 4 Create Plug and Play Profiles

More information

Configuring SSL. SSL Overview CHAPTER

Configuring SSL. SSL Overview CHAPTER CHAPTER 8 Date: 4/23/09 This topic describes the steps required to configure your ACE (both the ACE module and the ACE appliance) as a virtual Secure Sockets Layer (SSL) server for SSL initiation or termination.

More information

Send documentation comments to

Send documentation comments to CHAPTER 6 Configuring Certificate Authorities and Digital Certificates This chapter includes the following topics: Information About Certificate Authorities and Digital Certificates, page 6-1 Default Settings,

More information

This command is removed effective with Cisco IOS Release 12.4(6)T. no eap {username name password password}

This command is removed effective with Cisco IOS Release 12.4(6)T. no eap {username name password password} eap eap Note This command is removed effective with Cisco IOS 12.4(6)T. To specify Extensible Authentication Protocol- (EAP-) specific parameters, use the eap command in identity profile configuration

More information

Brocade Fabric OS FIPS Cryptographic Module 8.2 User Guide

Brocade Fabric OS FIPS Cryptographic Module 8.2 User Guide USER GUIDE Brocade Fabric OS FIPS Cryptographic Module 8.2 User Guide Supporting Fabric OS 8.2.0 FOS-820-FIPS-Crypto-UG100 20 September 2018 Copyright 2018 Brocade Communications Systems LLC. All Rights

More information

Encrypted Phone Configuration File Setup

Encrypted Phone Configuration File Setup This chapter provides information about encrypted phone configuration files setup. After you configure security-related settings, the phone configuration file contains sensitive information, such as digest

More information

Setting Up a Cisco Unified Communications Manager SIP Trunk Integration, page 1

Setting Up a Cisco Unified Communications Manager SIP Trunk Integration, page 1 Up a Cisco Unified Communications Manager SIP Trunk Integration This chapter provides instructions for setting up a Cisco Unified Communications Manager SIP trunk integration with Cisco Unity Connection.

More information

Configuring Internet Key Exchange Version 2

Configuring Internet Key Exchange Version 2 This module contains information about and instructions for configuring basic and advanced Internet Key Exchange Version 2 (IKEv2). The tasks and configuration examples for IKEv2 in this module are divided

More information

Configuring Internet Key Exchange Version 2 and FlexVPN Site-to-Site

Configuring Internet Key Exchange Version 2 and FlexVPN Site-to-Site Configuring Internet Key Exchange Version 2 and FlexVPN Site-to-Site This module contains information about and instructions for configuring basic and advanced Internet Key Exchange Version 2 (IKEv2)and

More information

Install the ExtraHop session key forwarder on a Windows server

Install the ExtraHop session key forwarder on a Windows server Install the ExtraHop session key forwarder on a Windows server Published: 2018-12-17 Perfect Forward Secrecy (PFS) is a property of secure communication protocols that enables short-term, completely private

More information

Management Access. Configure Management Remote Access. Configure ASA Access for ASDM, Telnet, or SSH

Management Access. Configure Management Remote Access. Configure ASA Access for ASDM, Telnet, or SSH This chapter describes how to access the Cisco ASA for system management through Telnet, SSH, and HTTPS (using ASDM), how to authenticate and authorize users, and how to create login banners. Configure

More information

Securing VMware NSX-T J U N E 2018

Securing VMware NSX-T J U N E 2018 Securing VMware NSX-T J U N E 2018 Securing VMware NSX Table of Contents Executive Summary...2 NSX-T Traffic [Control, Management, and Data]...3 NSX Manager:...7 NSX Controllers:...9 NSX Edge:...10 NSX-T

More information

How to Enable Client Certificate Authentication on Avi

How to Enable Client Certificate Authentication on Avi Page 1 of 11 How to Enable Client Certificate Authentication on Avi Vantage view online Overview This article explains how to enable client certificate authentication on an Avi Vantage. When client certificate

More information

Cisco Cloud Services Router 1000V

Cisco Cloud Services Router 1000V Cisco Cloud Services Router 1000V Common Criteria Configuration Guide Version 0.4 5 Janurary 2018 Americas Headquarters: Cisco Systems, Inc., 170 West Tasman Drive, San Jose, CA 95134-1706 USA 2017 Cisco

More information

Compatibility Matrix for Cisco Unified Communications Manager and the IM and Presence Service, Release 11.5(1)SU5

Compatibility Matrix for Cisco Unified Communications Manager and the IM and Presence Service, Release 11.5(1)SU5 Compatibility Matrix for Cisco Unified Communications Manager and the IM and Presence Service, Release 11.5(1)SU5 Compatibility Matrix for Cisco Unified Communications Manager and the IM and Presence Service

More information

Datapath. Encryption

Datapath. Encryption Datapath The following refers to the IKE/IPsec datapath implementation of overlay tunnels between Silver Peak devices. VXOA Release 7.3 (Regular "IPsec" mode with IKE) 8.0 (Regular "IPsec" mode with IKE)

More information

Digital Certificates. About Digital Certificates

Digital Certificates. About Digital Certificates This chapter describes how to configure digital certificates. About, on page 1 Guidelines for, on page 9 Configure, on page 12 How to Set Up Specific Certificate Types, on page 12 Set a Certificate Expiration

More information

Configuring SSL Security

Configuring SSL Security CHAPTER9 This chapter describes how to configure SSL on the Cisco 4700 Series Application Control Engine (ACE) appliance. This chapter contains the following sections: Overview Configuring SSL Termination

More information

Cisco Digital Network Architecture Center Administrator Guide, Release 1.1

Cisco Digital Network Architecture Center Administrator Guide, Release 1.1 Cisco Digital Network Architecture Center Administrator Guide, Release 1.1 First Published: 2018-01-26 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com

More information

BIG-IP System: SSL Administration. Version

BIG-IP System: SSL Administration. Version BIG-IP System: SSL Administration Version 13.1.0 Table of Contents Table of Contents About SSL Administration on the BIG-IP System...7 About SSL administration on the BIG-IP system... 7 Device Certificate

More information

Configuring Security for VPNs with IPsec

Configuring Security for VPNs with IPsec This module describes how to configure basic IPsec VPNs. IPsec is a framework of open standards developed by the IETF. It provides security for the transmission of sensitive information over unprotected

More information

SSH Algorithms for Common Criteria Certification

SSH Algorithms for Common Criteria Certification The feature provides the list and order of the algorithms that are allowed for Common Criteria Certification. This module describes how to configure the encryption, Message Authentication Code (MAC), and

More information

Configure RADIUS DTLS on Identity Services Engine

Configure RADIUS DTLS on Identity Services Engine Configure RADIUS DTLS on Identity Services Engine Contents Introduction Prerequisites Requirements Components Used Configure Configurations 1. Add network device on ISE and enable DTLS protocol. 2. Configure

More information

Using SSL to Secure Client/Server Connections

Using SSL to Secure Client/Server Connections Using SSL to Secure Client/Server Connections Using SSL to Secure Client/Server Connections, page 1 Using SSL to Secure Client/Server Connections Introduction This chapter contains information on creating

More information

Datapath. Encryption

Datapath. Encryption Datapath The following refers to the IKE/IPsec datapath implementation of overlay tunnels between Silver Peak devices. VXOA Release 7.3 (Regular "IPsec" mode with IKE) 8.0 (Regular "IPsec" mode with IKE)

More information

Cisco Digital Network Architecture Center Administrator Guide, Release 1.1

Cisco Digital Network Architecture Center Administrator Guide, Release 1.1 Cisco Digital Network Architecture Center Administrator Guide, Release 1.1 First Published: 2018-01-26 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com

More information

Implementing Internet Key Exchange Security Protocol

Implementing Internet Key Exchange Security Protocol Implementing Internet Key Exchange Security Protocol Internet Key Exchange (IKE) is a key management protocol standard that is used in conjunction with the IP Security (IPSec) standard. IPSec is a feature

More information

Configuring Secure Socket Layer HTTP

Configuring Secure Socket Layer HTTP This feature provides Secure Socket Layer (SSL) version 3.0 support for the HTTP 1.1 server and HTTP 1.1 client within Cisco IOS software. SSL provides server authentication, encryption, and message integrity

More information

Platform Settings for Classic Devices

Platform Settings for Classic Devices The following topics explain Firepower platform settings and how to configure them on Classic devices: Introduction to Firepower Platform Settings, page 1 Configuring Firepower Platform Settings, page

More information

Configure Cisco DNA Center System Settings

Configure Cisco DNA Center System Settings About DNA Center and Cisco ISE Integration, page 1 Configure Authentication and Policy Servers, page 2 Device Controllability, page 3 Configure Device Controllability, page 4 Configure an IP Address Manager,

More information

Operational User Guidance and Preparative

Operational User Guidance and Preparative Operational User Guidance and Preparative Procedures Pulse Secure, LLC Document Version 0.4 March 2018 Document Version 1.6.4 Pulse Secure, LLC Page 1 of 86 Pulse Secure, LLC 2700 Zanker Road, Suite 200

More information

Configuring Secure Socket Layer HTTP

Configuring Secure Socket Layer HTTP This feature provides Secure Socket Layer (SSL) version 3.0 support for the HTTP 1.1 server and HTTP 1.1 client within Cisco IOS software. SSL provides server authentication, encryption, and message integrity

More information

SSL Accelerated Services. Feature Description

SSL Accelerated Services. Feature Description Feature Description UPDATED: 28 March 2018 Copyright Notices Copyright 2002-2018 KEMP Technologies, Inc. All rights reserved. KEMP Technologies and the KEMP Technologies logo are registered trademarks

More information

Read the following information carefully, before you begin an upgrade.

Read the following information carefully, before you begin an upgrade. Read the following information carefully, before you begin an upgrade. Review Supported Upgrade Paths, page 1 Review Time Taken for Upgrade, page 1 Review Available Cisco APIC-EM Ports, page 2 Securing

More information

Configuring Secure Socket Layer HTTP

Configuring Secure Socket Layer HTTP Finding Feature Information, page 1 Information about Secure Sockets Layer (SSL) HTTP, page 1 How to Configure Secure HTTP Servers and Clients, page 5 Monitoring Secure HTTP Server and Client Status, page

More information

Dell SonicWALL. NSA 220, NSA 220W and NSA 240. FIPS Non-Proprietary Security Policy

Dell SonicWALL. NSA 220, NSA 220W and NSA 240. FIPS Non-Proprietary Security Policy Dell SonicWALL NSA 220, NSA 220W and NSA 240 FIPS 140-2 Non-Proprietary Security Policy Level 2 Version 3.1 April 28, 2014 1 Copyright Notice Copyright 2014 Dell SonicWALL May be reproduced only in its

More information

LAN-to-LAN IPsec VPNs

LAN-to-LAN IPsec VPNs A LAN-to-LAN VPN connects networks in different geographic locations. You can create LAN-to-LAN IPsec connections with Cisco peers and with third-party peers that comply with all relevant standards. These

More information

Cisco Prime Infrastructure 3.4 Administrator Guide

Cisco Prime Infrastructure 3.4 Administrator Guide First Published: 2017-12-18 Last Modified: 2018-04-04 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387)

More information

VPN Overview. VPN Types

VPN Overview. VPN Types VPN Types A virtual private network (VPN) connection establishes a secure tunnel between endpoints over a public network such as the Internet. This chapter applies to Site-to-site VPNs on Firepower Threat

More information

Internet Key Exchange

Internet Key Exchange CHAPTER16 The help topics in this section describe the (IKE) configuration screens. (IKE) What Do You Want to Do? (IKE) is a standard method for arranging for secure, authenticated communications. IKE

More information

This Security Policy describes how this module complies with the eleven sections of the Standard:

This Security Policy describes how this module complies with the eleven sections of the Standard: Vormetric, Inc Vormetric Data Security Server Module Firmware Version 4.4.1 Hardware Version 1.0 FIPS 140-2 Non-Proprietary Security Policy Level 2 Validation May 24 th, 2012 2011 Vormetric Inc. All rights

More information

Firepower Threat Defense Site-to-site VPNs

Firepower Threat Defense Site-to-site VPNs About, on page 1 Managing, on page 3 Configuring, on page 3 Monitoring Firepower Threat Defense VPNs, on page 11 About Firepower Threat Defense site-to-site VPN supports the following features: Both IPsec

More information

IPSec Network Applications

IPSec Network Applications This chapter describes several methods for implementing IPSec within various network applications. Topics discussed in this chapter include: Implementing IPSec for PDN Access Applications, page 1 Implementing

More information

Configuring SSH and Telnet

Configuring SSH and Telnet 6 CHAPTER This chapter describes how to configure Secure Shell Protocol (SSH) and Telnet on Cisco NX-OS devices. This chapter includes the following sections: Information About SSH and Telnet, page 6-1

More information

Configuring LAN-to-LAN IPsec VPNs

Configuring LAN-to-LAN IPsec VPNs CHAPTER 28 A LAN-to-LAN VPN connects networks in different geographic locations. The ASA 1000V supports LAN-to-LAN VPN connections to Cisco or third-party peers when the two peers have IPv4 inside and

More information

Configuring Management Access

Configuring Management Access 37 CHAPTER This chapter describes how to access the ASA for system management through Telnet, SSH, and HTTPS (using ASDM), how to authenticate and authorize users, how to create login banners, and how

More information

Server software page. Certificate Signing Request (CSR) Generation. Software

Server software page. Certificate Signing Request (CSR) Generation. Software Server software page Certificate Signing Request (CSR) Generation Software Apache (mod_ssl and OpenSSL)... 2 cpanel and WHM... 3 Microsoft Exchange 2007... 8 Microsoft Exchange 2010... 9 F5 BigIP... 13

More information

Public Key Infrastructure Configuration Guide, Cisco IOS XE Release 2

Public Key Infrastructure Configuration Guide, Cisco IOS XE Release 2 Public Key Infrastructure Configuration Guide, Cisco IOS XE Release 2 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000

More information

HP FlexFabric 5700 Switch Series

HP FlexFabric 5700 Switch Series HP FlexFabric 5700 Switch Series Security Command Reference Part number: 5998-6695 Software version: Release 2416 Document version: 6W100-20150130 Legal and notice information Copyright 2015 Hewlett-Packard

More information

Security and Certificates

Security and Certificates Encryption, page 1 Voice and Video Encryption, page 6 Federal Information Processing Standards, page 6 Certificate Validation, page 6 Required Certificates for On-Premises Servers, page 7 Certificate Requirements

More information

Defining IPsec Networks and Customers

Defining IPsec Networks and Customers CHAPTER 4 Defining the IPsec Network Elements In this product, a VPN network is a unique group of targets; a target can be a member of only one network. Thus, a VPN network allows a provider to partition

More information

Manage Certificates. Certificates Overview

Manage Certificates. Certificates Overview Certificates Overview, page 1 Show Certificates, page 3 Download Certificates, page 4 Install Intermediate Certificates, page 4 Delete a Trust Certificate, page 5 Regenerate a Certificate, page 6 Upload

More information

VPN CLIENT PROTECTION PROFILE

VPN CLIENT PROTECTION PROFILE VPN CLIENT PROTECTION PROFILE Target of Evaluation: Aruba Remote Access Point, ArubaOS 6.5.1-FIPS Version 1.4 June, 2017 INTRODUCTION This document serves as a supplement to the official Aruba user guidance

More information

Extended Package for Secure Shell (SSH) Version: National Information Assurance Partnership

Extended Package for Secure Shell (SSH) Version: National Information Assurance Partnership Extended Package for Secure Shell (SSH) Version: 1.1 2016-11-25 National Information Assurance Partnership Revision History Version Date Comment 0.9 2015-08-19 First Draft - Extended Package for Secure

More information

Public Key Enabling Oracle Weblogic Server

Public Key Enabling Oracle Weblogic Server DoD Public Key Enablement (PKE) Reference Guide Public Key Enabling Oracle Weblogic Server Contact: dodpke@mail.mil URL: http://iase.disa.mil/pki-pke URL: http://iase.disa.smil.mil/pki-pke Public Key Enabling

More information

VPN Option Guide for Site-to-Site VPNs

VPN Option Guide for Site-to-Site VPNs GB-OS Version 6.2 VPN Option Guide for Site-to-Site VPNs VPNOG2013411-02 Global Technology Associates 3505 Lake Lynda Drive Suite 115 Orlando, FL 32817 Tel: +1.407.380.0220 Fax. +1.407.380.6080 Email:

More information

MAGNUM-SDVN Security Administration Manual

MAGNUM-SDVN Security Administration Manual MAGNUM-SDVN Security Administration Manual Revision 19: November 21, 2017 Contents Overview... 3 Administrative Access... 4 Logging Into Terminal Locally... 4 Logging Out Of Local Terminal... 4 Logging

More information

CCNA Security 1.0 Student Packet Tracer Manual

CCNA Security 1.0 Student Packet Tracer Manual 1.0 Student Packet Tracer Manual This document is exclusive property of Cisco Systems, Inc. Permission is granted to print and copy this document for non-commercial distribution and exclusive use by instructors

More information

BlackBerry Dynamics Security White Paper. Version 1.6

BlackBerry Dynamics Security White Paper. Version 1.6 BlackBerry Dynamics Security White Paper Version 1.6 Page 2 of 36 Overview...4 Components... 4 What's New... 5 Security Features... 6 How Data Is Protected... 6 On-Device Data... 6 In-Transit Data... 7

More information

NCP Secure Enterprise macos Client Release Notes

NCP Secure Enterprise macos Client Release Notes Service Release: 3.10 r40218 Date: July 2018 Prerequisites Apple OS X operating systems: The following Apple macos operating systems are supported with this release: macos High Sierra 10.13 macos Sierra

More information

How to Configure SSL Interception in the Firewall

How to Configure SSL Interception in the Firewall Most applications encrypt outgoing connections with SSL or TLS. SSL Interception decrypts SSL-encrypted HTTPS and SMTPS traffic to allow Application Control features (such as the Virus Scanner, ATP, URL

More information

Cisco Prime Infrastructure 3.3 Administrator Guide

Cisco Prime Infrastructure 3.3 Administrator Guide First Published: 2017-08-03 Last Modified: 2018-01-31 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387)

More information

Configure the Prime Infrastructure Server

Configure the Prime Infrastructure Server View the Prime Infrastructure Server Configuration, page 2 Available System Settings, page 2 Secure the Connectivity of the Prime Infrastructure Server, page 9 MIB to Prime Infrastructure Alert/Event Mapping,

More information

Overview of the IPsec Features

Overview of the IPsec Features CHAPTER 2 This chapter provides an overview of the IPsec features of the VSPA. This chapter includes the following sections: Overview of Basic IPsec and IKE Configuration Concepts, page 2-1 Configuring

More information

Security Policy Document Version 3.3. Tropos Networks

Security Policy Document Version 3.3. Tropos Networks Tropos Control Element Management System Security Policy Document Version 3.3 Tropos Networks October 1 st, 2009 Copyright 2009 Tropos Networks. This document may be freely reproduced whole and intact

More information

Securing VMware NSX MAY 2014

Securing VMware NSX MAY 2014 Securing VMware NSX MAY 2014 Securing VMware NSX Table of Contents Executive Summary... 2 NSX Traffic [Control, Management, and Data]... 3 NSX Manager:... 5 NSX Controllers:... 8 NSX Edge Gateway:... 9

More information

Cisco has more than 200 offices worldwide. Addresses, phone numbers, and fax numbers are listed on the Cisco website at

Cisco has more than 200 offices worldwide. Addresses, phone numbers, and fax numbers are listed on the Cisco website at Document Date: May 16, 2017 THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL

More information

Apple Inc. Apple IOS 11 VPN Client on iphone and ipad Guidance Documentation

Apple Inc. Apple IOS 11 VPN Client on iphone and ipad Guidance Documentation Apple Inc. Apple IOS 11 VPN Client on iphone and ipad Guidance Documentation April 2018 Version 1.2 1 Contents 1 Introduction... 4 1.1 Target of Evaluation... 4 1.2 Cryptographic Support... 5 1.3 Glossary...

More information

Security for VPNs with IPsec Configuration Guide, Cisco IOS XE Release 3S

Security for VPNs with IPsec Configuration Guide, Cisco IOS XE Release 3S Security for VPNs with IPsec Configuration Guide, Cisco IOS XE Release 3S Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000

More information

What do you want for Christmas?

What do you want for Christmas? What do you want for Christmas? ISE 2.0 new feature examples TACACS, Certificate Provisioning, Posture encryption Eugene Korneychuk, Michał Garcarz AAA TAC Engineers Agenda ISE - new features in 2.0 AnyConnect

More information

Cisco Passguide Exam Questions & Answers

Cisco Passguide Exam Questions & Answers Cisco Passguide 642-648 Exam Questions & Answers Number: 642-648 Passing Score: 800 Time Limit: 120 min File Version: 61.8 http://www.gratisexam.com/ Cisco 642-648 Exam Questions & Answers Exam Name: Deploying

More information

Configure the Prime Infrastructure Server

Configure the Prime Infrastructure Server View the Prime Infrastructure Server Configuration, on page 1 Available System Settings, on page 2 Secure the Connectivity of the Prime Infrastructure Server, on page 7 MIB to Prime Infrastructure Alert/Event

More information

Manage Your Device Inventory

Manage Your Device Inventory About Device Inventory, page 1 Device Inventory and Cisco ISE Authentication, page 7 Device Inventory Tasks, page 7 Add a Device Manually, page 8 Filter Devices, page 12 Change Devices Layout View, page

More information

In the event of re-installation, the client software will be installed as a test version (max 10 days) until the required license key is entered.

In the event of re-installation, the client software will be installed as a test version (max 10 days) until the required license key is entered. NCP Android Secure Managed Client can be commissioned for use in one of two environments: NCP Secure Enterprise Management as an NCP Secure Enterprise Android VPN Client or NCP Volume License Server as

More information

Cisco Systems 5760 Wireless LAN Controller

Cisco Systems 5760 Wireless LAN Controller Cisco Systems 5760 Wireless LAN Controller FIPS 140-2 Non Proprietary Security Policy Level 1 Validation Version 1.2 April 10, 2015 1 Table of Contents 1 INTRODUCTION... 3 1.1 PURPOSE... 3 1.2 MODEL...

More information

CCNA Security PT Practice SBA

CCNA Security PT Practice SBA A few things to keep in mind while completing this activity: 1. Do not use the browser Back button or close or reload any Exam windows during the exam. 2. Do not close Packet Tracer when you are done.

More information

The Xirrus Wi Fi Array XS4, XS8 Security Policy Document Version 1.0. Xirrus, Inc.

The Xirrus Wi Fi Array XS4, XS8 Security Policy Document Version 1.0. Xirrus, Inc. The Xirrus Wi Fi Array XS4, XS8 Security Policy Document Version 1.0 Xirrus, Inc. March 8, 2011 Copyright Xirrus, Inc. 2011. May be reproduced only in its original entirety [without revision]. Page 1 TABLE

More information

Configure the IM and Presence Service to Integrate with the Microsoft Exchange Server

Configure the IM and Presence Service to Integrate with the Microsoft Exchange Server Configure the IM and Presence Service to Integrate with the Microsoft Exchange Server Configure a Presence Gateway for Microsoft Exchange Integration, page 1 SAN and Wildcard Certificate Support, page

More information