Nokia IP265 Security Guide - Page 11

Nokia - features

Page 11 highlights

Service Routing commands Network Security and Access commands Traffic management commands Description Input Configure, manage, and view the routing protocols through the CLI: configure, manage, and view BGB BGP, OSPF, RIP, IGRP, IGMP, PIM, route aggregation, BOOTP, DVMRP, static routes,, ICMP router discovery, IP broadcast helper, Network Time Protocol, and dial on demand routing; configure a variety of miscellaneous options that affect routing; configure trace routing settings; view summary information about routes on the system; view general information that the IPSO routing daemon records; view information about multicast forwarding cache Commands and configuration data Configure, manage, and view the security and access features through the CLI: configure and view network access; add firmware licenses to the platform; configure Authentication, Authorization, and Accounting (AAA); enable and disable and configure SSH services; add and delete new system users; create and delete groups, and add and remove members; enable and disable a VPN accelerator card; display VPN accelerator status or statistics Commands and configuration data Configure, manage, and view traffic management functionality through the CLI: configure an access list to control the traffic from one or more interfaces; create or delete existing aggregation classes and modify the mean rate or burst size; configure depth of queues, assign logical names to some of the queues, and set up a queue specifier; add, delete, or show ATM QoS descriptors; add, delete, or show association of ATM QoS descriptors with ATM VCs; show available or reserved bandwidth on an ATM interface; enable and disable DSCP to VLAN mapping Commands and configuration data Output Status of commands and configuration data Status of commands and configuration data Status of commands and configuration data Critical Security Parameter (CSP) Access None Admin, monitor, user passwords; shared secret for RADIUS; shared secret for TACPLUS; SSH host keys; SSHv1 server key; SSH authorized keys; Read/write access for all CSPs None © Copyright 2005, 2006, 2007 Nokia Page 11 of 43 This document may be freely reproduced and distributed whole and intact including this Copyright Notice.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43

Service
Description
Input
Output
Critical Security
Parameter
(CSP) Access
Routing
commands
Configure, manage, and view the
routing protocols through the CLI:
configure, manage, and view BGB
BGP, OSPF, RIP, IGRP, IGMP, PIM,
route aggregation, BOOTP, DVMRP,
static routes,, ICMP router discovery,
IP broadcast helper, Network Time
Protocol, and dial on demand routing;
configure a variety of miscellaneous
options that affect routing; configure
trace routing settings; view summary
information about routes on the
system; view general information that
the IPSO routing daemon records;
view information about multicast
forwarding cache
Commands
and
configuration
data
Status of
commands
and
configuration
data
None
Network Security
and Access
commands
Configure, manage, and view the
security and access features through
the CLI: configure and view network
access; add firmware licenses to the
platform; configure Authentication,
Authorization, and Accounting (AAA);
enable and disable and configure
SSH services; add and delete new
system users; create and delete
groups, and add and remove
members; enable and disable a VPN
accelerator card; display VPN
accelerator status or statistics
Commands
and
configuration
data
Status of
commands
and
configuration
data
Admin, monitor, user
passwords; shared
secret for RADIUS;
shared secret for
TACPLUS; SSH host
keys; SSHv1 server
key; SSH authorized
keys; Read/write
access for all CSPs
Traffic
management
commands
Configure, manage, and view traffic
management functionality through
the CLI: configure an access list to
control the traffic from one or more
interfaces; create or delete existing
aggregation classes and modify the
mean rate or burst size; configure
depth of queues, assign logical
names to some of the queues, and
set up a queue specifier; add, delete,
or show ATM QoS descriptors; add,
delete, or show association of ATM
QoS descriptors with ATM VCs;
show available or reserved
bandwidth on an ATM interface;
enable and disable DSCP to VLAN
mapping
Commands
and
configuration
data
Status of
commands
and
configuration
data
None
© Copyright 2005, 2006, 2007
Nokia
Page 11 of 43
This document may be freely reproduced and distributed whole and intact including this Copyright Notice.