System Security Configuration Guide for Cisco ASR 9000 Series Routers, IOS XR Release 7.3.X
Total Page:16
File Type:pdf, Size:1020Kb
System Security Configuration Guide for Cisco ASR 9000 Series Routers, IOS XR Release 7.3.x First Published: 2021-02-01 Americas Headquarters Cisco Systems, Inc. 170 West Tasman Drive San Jose, CA 95134-1706 USA http://www.cisco.com Tel: 408 526-4000 800 553-NETS (6387) Fax: 408 527-0883 THE SPECIFICATIONS AND INFORMATION REGARDING THE PRODUCTS IN THIS MANUAL ARE SUBJECT TO CHANGE WITHOUT NOTICE. ALL STATEMENTS, INFORMATION, AND RECOMMENDATIONS IN THIS MANUAL ARE BELIEVED TO BE ACCURATE BUT ARE PRESENTED WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED. USERS MUST TAKE FULL RESPONSIBILITY FOR THEIR APPLICATION OF ANY PRODUCTS. THE SOFTWARE LICENSE AND LIMITED WARRANTY FOR THE ACCOMPANYING PRODUCT ARE SET FORTH IN THE INFORMATION PACKET THAT SHIPPED WITH THE PRODUCT AND ARE INCORPORATED HEREIN BY THIS REFERENCE. IF YOU ARE UNABLE TO LOCATE THE SOFTWARE LICENSE OR LIMITED WARRANTY, CONTACT YOUR CISCO REPRESENTATIVE FOR A COPY. The Cisco implementation of TCP header compression is an adaptation of a program developed by the University of California, Berkeley (UCB) as part of UCB's public domain version of the UNIX operating system. All rights reserved. Copyright © 1981, Regents of the University of California. NOTWITHSTANDING ANY OTHER WARRANTY HEREIN, ALL DOCUMENT FILES AND SOFTWARE OF THESE SUPPLIERS ARE PROVIDED “AS IS" WITH ALL FAULTS. CISCO AND THE ABOVE-NAMED SUPPLIERS DISCLAIM ALL WARRANTIES, EXPRESSED OR IMPLIED, INCLUDING, WITHOUT LIMITATION, THOSE OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT OR ARISING FROM A COURSE OF DEALING, USAGE, OR TRADE PRACTICE. IN NO EVENT SHALL CISCO OR ITS SUPPLIERS BE LIABLE FOR ANY INDIRECT, SPECIAL, CONSEQUENTIAL, OR INCIDENTAL DAMAGES, INCLUDING, WITHOUT LIMITATION, LOST PROFITS OR LOSS OR DAMAGE TO DATA ARISING OUT OF THE USE OR INABILITY TO USE THIS MANUAL, EVEN IF CISCO OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental. All printed copies and duplicate soft copies of this document are considered uncontrolled. See the current online version for the latest version. Cisco has more than 200 offices worldwide. Addresses and phone numbers are listed on the Cisco website at www.cisco.com/go/offices. Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: https://www.cisco.com/c/en/us/about/legal/trademarks.html. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1721R) © 2021 Cisco Systems, Inc. All rights reserved. CONTENTS PREFACE Preface xiii Changes to This Document xiii Communications, Services, and Additional Information xiii CHAPTER 1 New and Changed Feature Information 1 System Security Features Added or Modified in IOS XR Release 7.3.x 1 CHAPTER 2 Configuring AAA Services 3 Information About Configuring AAA Services 4 User, User Groups, and Task Groups 4 User Categories 4 User Groups 5 Task Groups 6 Cisco IOS XR Software Administrative Model 7 Administrative Access 7 AAA Database 8 Remote AAA Configuration 8 AAA Configuration 9 Authentication 10 Password Types 12 Type 8 and Type 9 Passwords 12 Type 10 Password 13 AAA Password Security for FIPS Compliance 13 AAA Password Security Policies 14 Minimum Password Length for First User Creation 16 Task-Based Authorization 16 System Security Configuration Guide for Cisco ASR 9000 Series Routers, IOS XR Release 7.3.x iii Contents Task IDs 17 General Usage Guidelines for Task IDs 17 Task IDs for TACACS+ and RADIUS Authenticated Users 18 Task Maps 18 Privilege Level Mapping 20 XML Schema for AAA Services 21 About RADIUS 21 Network Security Situations in Which RADIUS is Unsuitable 22 RADIUS Operation 22 Differentiated Services Code Point (DSCP) Marking support for TACACS packets 23 How to Configure AAA Services 23 Prerequisites for Configuring AAA Services 23 Restrictions for Configuring AAA Services 24 Configuring Task Groups 24 Task Group Configuration 24 Configuring User Groups 26 Configure First User on Cisco Routers 27 Configuring Users 28 Password Masking For Type 7 Password Authentication 30 Configure Type 8 and Type 9 Passwords 31 Configure Type 10 Password 32 Backward Compatibility for Password Types 34 Configure AAA Password Policy 34 Configuring Router to RADIUS Server Communication 36 Configuring RADIUS Dead-Server Detection 39 Configuring Per VRF AAA 41 New Vendor-Specific Attributes (VSAs) 41 Configuring a TACACS+ Server 44 Configuring RADIUS Server Groups 46 Configuring TACACS+ Server Groups 48 Configure Per VRF TACACS+ Server Groups 49 Configuring AAA Method Lists 51 Configuring Authentication Method Lists 51 System Security Configuration Guide for Cisco ASR 9000 Series Routers, IOS XR Release 7.3.x iv Contents Configuring Authorization Method Lists 54 Configuring Accounting Method Lists 57 Generating Interim Accounting Records 60 Applying Method Lists for Applications 61 Enabling AAA Authorization 61 Enabling Accounting Services 63 Configuring Login Parameters 64 Configuration Examples for Configuring AAA Services 65 Configuring AAA Services: Example 65 Command Accounting 67 Model-based AAA 67 Prerequisites for Model Based AAA 67 Initial Operation 68 NACM Configuration Management and Persistence 69 Overview of Configuring NACM 69 NACM Rules 69 Enabling NACM 72 Verify the NACM Configurations 73 Disabling NACM 74 Additional References 74 CHAPTER 3 Implementing Certification Authority Interoperability 77 Prerequisites for Implementing Certification Authority 78 Restrictions for Implementing Certification Authority 78 Information About Implementing Certification Authority 78 Supported Standards for Certification Authority Interoperability 78 Certification Authorities 79 Purpose of CAs 79 IPSec Without CAs 80 IPSec with CAs 80 IPSec with Multiple Trustpoint CAs 80 How IPSec Devices Use CA Certificates 81 CA Registration Authorities 81 System Security Configuration Guide for Cisco ASR 9000 Series Routers, IOS XR Release 7.3.x v Contents How to Implement CA Interoperability 81 Configuring a Router Hostname and IP Domain Name 81 Generating an RSA Key Pair 82 Importing a Public Key to the Router 83 Declaring a Certification Authority and Configuring a Trusted Point 84 Authenticating the CA 85 Requesting Your Own Certificates 86 Configuring Certificate Enrollment Using Cut-and-Paste 87 Configuration Examples for Implementing Certification Authority Interoperability 88 Configuring Certification Authority Interoperability: Example 88 Expiry Notification for PKI Certificate 90 Learn About the PKI Alert Notification 90 Enable PKI Traps 92 Regenerate the Certificate 92 Integrating Cisco IOS XR and Crosswork Trust Insights 93 How to Integrate Cisco IOS XR and Crosswork Trust Insights 94 Generate Key Pair 96 Generate System Trust Point for the Leaf and Root Certificate 98 Generate Root and Leaf Certificates 99 System Certificates Expiry 100 Collect Data Dossier 101 Procedure to Test Key Generation and Data-signing with Different Key Algorithm 104 Verify Authenticity of RPM Packages Using Fingerprint 105 Support for Ed25519 Public-Key Signature System 107 Generate Crypto Key for Ed25519 Signature Algorithm 107 Integrate Cisco IOS XR with Cisco Crosswork Trust Insights using Ed25519 108 Where to Go Next 109 Additional References 109 CHAPTER 4 Implementing Keychain Management 111 Prerequisites for Configuring Keychain Management 111 Restrictions for Implementing Keychain Management 111 Information About Implementing Keychain Management 111 System Security Configuration Guide for Cisco ASR 9000 Series Routers, IOS XR Release 7.3.x vi Contents Lifetime of Key 112 How to Implement Keychain Management 112 Configuring a Keychain 113 Configuring a Tolerance Specification to Accept Keys 114 Configuring a Key Identifier for the Keychain 115 Configuring the Text for the Key String 116 Determining the Valid Keys 117 Configuring the Keys to Generate Authentication Digest for the Outbound Application Traffic 118 Configuring the Cryptographic Algorithm 120 Configuration Examples for Implementing Keychain Management 121 Configuring Keychain Management: Example 121 Additional References 122 CHAPTER 5 Configure MACSec 125 Understanding MACsec Encryption 126 Advantages of Using MACsec Encryption 127 Types of MACsec Implementation 127 MKA Authentication Process 128 MACSec Support on Line Cards and Routers 129 MACSec Limitations for Cisco ASR 9901 Routers 130 MACsec PSK 130 Fallback PSK 130 Configuring and Verifying MACSec Encryption 131 Creating a MACsec Key Chain 134 Prerequisites for Configuring MACSec on Bundle Member Interfaces 137 Creating a User-Defined MACsec Policy 138 MACsec SAK Rekey Interval 140 Applying MACsec Configuration on an Interface 141 MACsec Policy Exceptions 142 How to Create MACsec Policy Exception 142 Verifying MACsec Encryption on IOS XR 143 Verifying MACsec Encryption on ASR 9000 156 Configuring and Verifying MACsec Encryption as a Service 159 System Security Configuration Guide for Cisco ASR 9000 Series Routers, IOS XR Release 7.3.x vii Contents