New and Changed Information

This chapter contains the following sections:

New and Changed Information

The following table provides an overview of the significant changes to the organization and features in this guide up to this current release. The table does not provide an exhaustive list of all changes made to the guide or of the new features up to this release.

Table 1. New Features and Changed Behavior in Cisco APIC for Cisco APIC Release 3.2(4)

Feature or Change

Description

Where Documented

EIGRP Authentication

Support for EIGRP keychain authentication

Chapter: Protocol Authentication

Table 2. New Features and Changed Behavior in Cisco APIC for Cisco APIC Release 3.2(1)

Feature or Change

Description

Where Documented

802.1x enhancements

Support for IP Phones

Chapter: 802.1x

Per Leaf Aggregate for DPP

Support for Shared Policer Mode

Chapter: Data Plane Policing

SAML Enhancements

Support for Encrypted SAML Assertions

Chapter: TACACS+, RADIUS, LDAP, RSA, and SAML

Table 3. New Features and Changed Behavior in Cisco APIC for Cisco APIC

Feature or Change

Description

Where Documented

Document Reorganization

The topics in this section were collected from the Custom Certificate for ACI Cisco HTTPS Access Knowledge Base article.

Chapter: HTTPS Access

Table 4. New Features and Changed Behavior in Cisco APIC for Cisco APIC Release 3.1(1i)

Feature or Change

Description

Where Documented

CoPP per Interface per Protocol

Support for configuring CoPP on a per interface per protocol basis.

Chapter: Control Plane Traffic

CoPP Prefilter

A CoPP prefilter profile is used on spine and leaf switches to filter access to authentication services based on specified sources and TCP ports to protect against DDoS attacks.

Chapter: Control Plane Traffic

FIPs SHA1 Key Support

When FIPs is enabled, SHA1 key is supported for NTP authentication

Chapter: Fabric Security

LDAP Group Map

Enables LDAP configuration in the APIC GUI as an alternative to configuring a Cisco AVPair.

Chapter: TACACs+, RADIUS, LDAP, RSA, and SAML

RSA Secure ID

Provides token based password authentication

Chapter: TACACs+, RADIUS, LDAP, RSA, and SAML

Server Monitoring

Provides a method to determine whether a remote AAA server is alive or not.

Chapter: TACACs+, RADIUS, LDAP, RSA, and SAML

Basic GUI topics removed

Basic GUI procedures are no longer supported

The following topics have been removed:

  • Configuring Port Security Using the Basic GUI

  • Configuring Data Plane Policing for Layer 2 Using the Basic GUI

Table 5. New Features and Changed Behavior in Cisco APIC for Cisco APIC Release 3.0(1x)

Feature or Change

Description

Where Documented

First Hop Security

Enables better IPv4 and IPv6 link security and management over the layer 2 links.

Chapter: First Hop Security

SAML Management/2 Factor Authentication

SAML is an XML-based open standard data format that uses security tokens containing assertions that pass information between an SAML identity provider and a SAML service provider.

Chapter: TACACs+, RADIUS, LDAP, RSA, and SAML

Local User Authentication using OTP

OTP is a one-time password that is valid for only one session. Once OTP is enabled, APIC generates a random human readable 16 binary octets that are base32 OTP Key.

Chapter: Access, Authentication, and Accounting

Password Strength

Allows configuration of user password parameters for security management.

Chapter: Access, Authentication, and Accounting

SSH Private Key File

Allows password authentication for outside access.

Chapter: Access, Authentication, and Accounting

Data Plane Policing at the EPG level

Support for configuring the data Plane Policing at the Endpoing Group (EPG) level.

Chapter: Data Plane Policing

802.1x Support

Support for configuring 802.1x

Chapter: 802.1x

Table 6. New Features and Changed Behavior in Cisco APIC for Cisco APIC Release 3.0(x)

Feature or Change

Description

Where Documented

EPG level Data Plane Policing

Support for configuring the Data Plane Policing at the Endpoint Group (EPG) level.

Chapter: Data Plane Policing

Table 7. New Features and Changed Behavior in Cisco APIC for Cisco APIC Release 2.3(x)

Feature or Change

Description

Where Documented

Document Reorganization

The topics in this guide were collected from Cisco APIC Basic Configuration Guide, Release 2.x, Cisco ACI and Port Security, and the following Knowledge Base articles:

  • Cisco ACI and COOP Authentication

  • Cisco ACI AAA RBAC Rules and Privileges

  • Cisco APIC Signature-Based Transactions

  • Cisco APIC and Federal Information Processing Standards (FIPS)

  • Configuring TACACS+, RADIUS, and LDAP for Cisco APIC Access

Cisco APIC Security Configuration Guide (this guide)

Control Plane Policing

Protects the control plane and Configuring Security separates it from the data plane, which ensures network stability, reachability, and packet delivery.

Chapter: Control Plane Traffic

Table 8. New Features and Changed Behavior in Cisco APIC for Cisco APIC Release 2.2(x)

Feature or Change

Description

Where Documented

Support for changing remote user role

Allows the remote user to request a role-change

Chapter: Access, Authentication, and Accounting

Support on all platforms (except N9K-C93180YC-EX) for:

Support on all platforms (except N9K-C93180YC-EX) for:

Chapter: Data Plane Policing

Table 9. New Features and Changed Behavior in Cisco APIC for Cisco APIC Release 2.1(x)

Feature or Change

Description

Where Documented

FIPS

Support for FIPS is enabled.

Chapter: Fabric Security

Table 10. New Features and Changed Behavior in Cisco APIC for Cisco APIC Release 2.0(x)

Feature or Change

Description

Where Documented

  • Port Security

  • Maximum endpoint value support expanded

  • Port Security support

  • The maximum number of secure MAC addresses for the interface range is 0-12000 addresses.

Chapter: Port Security

COOP

COOP authentication supported

Chapter: Protocol Authentication

Support for Ethertype, protocol, L4 port, and TCP flag filters is available.

Support for Ethertype, protocol, L4 port, and TCP flag filters is available.

Chapter: Access, Authentication, and Accounting

Table 11. New Features and Changed Behavior in Cisco APIC for Cisco APIC Release 1.3(x)

Feature or Change

Description

Where Documented

AAA RBAC Roles and Privileges

This guide was released to provide a description of AAA RBAC roles and privileges.

Chapter: Access, Authentication, and Accounting

Support for egress policers on the N9K-C93180YC-EX.

Support for egress policers on the N9K-C93180YC-EX.

Chapter: Data Plane Policing

Table 12. New Features and Changed Behavior in Cisco APIC for Cisco APIC Release 1.2(x)

Feature or Change

Description

Where Documented

Data Plane Policing

Support for Data Plane Policing

Chapter: Data Plane Policing

Table 13. New Features and Changed Behavior in Cisco APIC for Cisco APIC Release 1.1(x)

Feature or Change

Description

Where Documented

TACACS+, RADIUS, and LDAP

Support for TACACS+, RADIUS, and LDAP

Chapter: TACACs+, RADIUS, LDAP, RSA, and SAML

Table 14. New Features and Changed Behavior in Cisco APIC for Cisco APIC Release 1.0(x)

Feature or Change

Description

Where Documented

Signature-Based Transactions

The APIC controllers in a Cisco ACI fabric offer different methods to authenticate users.

Chapter: Access, Authentication, and Accounting

Custom Certificate for Cisco ACI HTTPS Access

Configure a custom certificate for HTTPS access when using Cisco ACI

Chapter: HTTPS Access