New and Changed Information

This chapter includes the new and changed features for the Cisco Nexus 9000 Series NX-OS Security Configuration Guide, Release 10.4(x).

New and Changed Information

Table 1. New and Changed Features

Feature

Description

Changed in Release

Where Documented

Class E in NX-OS Fabric

Added support for Security Group ACL with ESG on Class E IP addresses.

10.4(3)F

Guidelines and Limitations for IP ACLs

MACsec

Added support for MACsec on Cisco Nexus 9364C-H1 switches.

10.4(3)F

Guidelines and Limitations for MACsec

Security ACL

Added support for Security ACL on the Cisco Nexus 9364C-H1 switches.

10.4(3)F

Guidelines and Limitations for IP ACLs

ACL/CoPP

Added support for ACL and CoPP on the Cisco Nexus 9364C-H1 switches.

10.4(3)F

Guidelines and Limitations for IP ACLs

Guidelines and Limitations for CoPP

Support flexible TCAM templates/enhancement

Added support for flexible TCAM configuration on the Cisco Nexus 9364C-H1 switches.

10.4(3)F

Guidelines and Limitations for IP ACLs

TLS v1.3

Added Transport Layer Security protocol version 1.3 support for Cisco Nexus applications.

10.4(3)F

TLS Protocol Support

Guidelines and Limitations for RadSec

Guidelines and Limitations for LDAP

802.1X Guidelines and Limitations

QKD (Quantum Key Distribution) integration with SKIP on MACsec

Added support for QKD on Cisco Nexus 9000 Series Switches.

10.4(3)F

QKD integration with SKIP on MACsec

X.509 certificate based SSH Authorization using TACACS

Added support for SSH-based authorization of x509v3-certificates using TACACS+ server.

10.4(3)F

Guidelines and Limitations for AAA

Configuring AAA SSH-Cert-Authorization on TACACS Servers

About TACACS+

Guidelines and Limitations for TACACS+

Configuring X.509 Certificate-Based SSH Authorization Using TACACS Server

Default route

Added support for configuring default route for ACL QoS.

10.4(2)F

Guidelines and Limitations for IP ACLs

Configuration Examples for IP ACLs

Support flexible TCAM templates/enhancement

Added support for flexible TCAM configuration on the Cisco Nexus 93400LD-H1 switches.

10.4(2)F

Guidelines and Limitations for IP ACLs

Security ACL

Added support for Security ACL on the Cisco Nexus 93400LD-H1 switches.

10.4(2)F

Guidelines and Limitations for IP ACLs

MACsec

Added support for MACsec on Cisco Nexus 93400LD-H1, and 93108TC-FX3 switches.

10.4(2)F

Guidelines and Limitations for MACsec

ACL/CoPP

Added support for ACL and CoPP ACL on Cisco Nexus 93400LD-H1, and 93108TC-FX3 switches.

10.4(2)F

Guidelines and Limitations for CoPP

Guidelines and Limitations for IP ACLs

CR multiline support

Added configuration replace feature support for LDAP.

10.4(2)F

Guidelines and Limitations for LDAP

BGP support for TCP Authentication Option (TCP-AO)

Added support for TCP authentication option on Cisco Nexus 9000 platform switches.

10.4(2)F

Configuring TCP Authentication Option

MACsec rate counter support on FX3 platforms

Added support for MACsec rate counter for "show macsec secy statistics command" and rate related OIDs in CISCO-SECY-EXT-MIB on Cisco Nexus 9300-FX3 switches.

10.4(2)F

Guidelines and Limitations for MACsec

MACsec support on N9K-X98900CD-A

Added support for MACsec on Cisco Nexus X98900CD-A​ line cards.

10.4(2)F

Guidelines and Limitations for MACsec

Flexible configuration of SSH to customize Ciphers, MACs, and Keytypes

Added CLI options to configure SSH Algorithm.

10.4(2)F

Customizing SSH Cryptographic Algorithms

Certification based authentication for MACsec

Added EAP-TLS support to 802.1X Port-based Authentication for uplink ports where MACsec is required.

10.4(1)F

Prerequisites for 802.1X

802.1X Guidelines and Limitations

Configuring EAP-TLS

Verifying the 802.1X Configuration

Configuring MACsec EAP

Support to redirect/deny 'all' packets using ePBR policy

Added new ACE all keyword to prioritize the IP/IPv6/MAC ACL rule over SUP rule.

10.4(1)F

Guidelines and Limitations for IP ACLs

Applying an IP ACL Rule Prioritization over SUP Rule

Guidelines and Limitations for MAC ACLs

Applying a MAC ACL Rule Prioritization over SUP Rule

Radius over DTLS Support

Radius over DTLS protocol support is added. This protocol is for transporting RADIUS datagrams over a secure channel.

10.4(1)F

About RADIUS with DTLS

Configuring RADIUS with DTLS

AAA

Added support for AAA on Cisco Nexus 9804 switches, and Cisco Nexus X98900CD-A and X9836DM-A line cards.

10.4(1)F

Guidelines and Limitations for AAA

RADIUS

Added support for RADIUS on Cisco Nexus 9804 switches, and Cisco Nexus X98900CD-A and X9836DM-A line cards.

10.4(1)F

Guidelines and Limitations for RADIUS

TACACS+

Added support for TACACS+ on Cisco Nexus 9804 switches, and Cisco Nexus X98900CD-A and X9836DM-A line cards.

10.4(1)F

Guidelines and Limitations for TACACS+

LDAP

Added support for LDAP on Cisco Nexus 9804 switches, and Cisco Nexus X98900CD-A and X9836DM-A line cards.

10.4(1)F

Guidelines and Limitations for LDAP

MACsec

Added support for MACsec on Cisco Nexus 9348GC-FX3, 9348GC-FX3PH and 9332D-H2R switches

10.4(1)F

Guidelines and Limitations for MACsec

Security ACL

Added support for Security ACL on the Cisco Nexus 9332D-H2R switches.

10.4(1)F

Guidelines and Limitations for IP ACLs

ACL/CoPP

Added support for ACL and CoPP on the Cisco Nexus 9332D-H2R switches.

10.4(1)F

Guidelines and Limitations for IP ACLs

Guidelines and Limitations for CoPP

Support flexible TCAM templates/enhancement

Added support for flexible TCAM configuration on the Cisco Nexus 9332D-H2R switches.

10.4(1)F

Guidelines and Limitations for IP ACLs

ACL Consistency Checker

Added support for ACL Consistency Checker on Cisco Nexus 9804 switches, and Cisco Nexus X98900CD-A and X9836DM-A line cards.

10.4(1)F

Guidelines and Limitations for IP ACLs

ACL - Sup, CoPP

Added support for CoPP ACL on Cisco Nexus 9804 switches, and Cisco Nexus X98900CD-A and X9836DM-A line cards.

10.4(1)F

Guidelines and Limitations for CoPP

RACL with statistics

Added support for RACL (Ingress-IPv4/IPv6 and Egress-IPv4/IPv6) with statistics on Cisco Nexus 9804 switches, and Cisco Nexus X98900CD-A and X9836DM-A line cards.

10.4(1)F

Guidelines and Limitations for IP ACLs

DHCP relay

Added support for DHCP relay on Cisco Nexus 9804 switches, and Cisco Nexus X98900CD-A and X9836DM-A line cards.

10.4(1)F

Guidelines and Limitations for DHCP

CoPP Limit

Added CoPP Limit configuration for PTP interface on Cisco Nexus 9348GC-FX3

10.4(1)F

Changing CoPP Policy limit