System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

About this content

Provides comprehensive instructions for securing Cisco IOS XR routers through trustworthy systems, AAA, certificates and key management, SSH, FIPS cryptography, secure logging, port authentication, device ownership, access protection, automated certificate provisioning, and management-plane security.


Whats changed in this book

Specific changes or updates tied to individual releases are clearly called out within the relevant sections. For a list of features introduced in a specific release, refer to the Release Notes.

The table lists the release numbers for which this document has been updated since its initial publication.

Table 1. Changes to this document
Date Summary

September 2026

First published for Release 26.3.1.

YANG Data Models for System Security Features

Lists the YANG data models available for implementing and managing System Security features on Cisco devices.

Trustworthy Systems

Short description: Outlines core concepts, hardware and software components, operational processes, security mechanisms, and verification procedures that establish trustworthy systems, highlighting key technologies including roots of trust, secure boot, TPM, ECC P256, and essential security terms.

Maintaining Trust

Outlines comprehensive measures for maintaining trust in secure systems, including steady-state trust models, SELinux, secure installation, SSD encryption, runtime defenses, boot integrity, secure communications, and integrity verification mechanisms.

AAA Access Model and Local User Administration

Outlines AAA access configuration, user identity management, administrative models, and local user setup, guiding administrators through requirements, group structures, database integration, method lists, and step-by-step procedures for secure AAA implementation on network devices.

AAA Password Security and Authorization Policies

Outlines AAA password security, FIPS compliance measures, method lists, task-based authorization, command accounting, and configuration patterns to enhance access control and policy enforcement in network environments.

RADIUS Server Configuration and Secure Transport

Outlines RADIUS server functionality, secure transport methods with DTLS and TLS, router integration, dead-server detection, server group configuration, and per-VRF AAA techniques to enhance authentication, authorization, and security for network infrastructures.

TACACS+ Services for AAA

Outlines TACACS+ integration for AAA, including DSCP marking, server and server group configuration, per-VRF deployment, operational statistics, and securing TACACS+ with TLS protection to enhance access control, authorization, authentication, and accounting in network environments.

CA Interoperability and Certificate Enrollment

Explains CA interoperability concepts and certificate enrollment processes, covering configuration requirements, enrollment methods, and operational workflows for managing digital certificates across integrated systems.

CA Trust Pools and PKI Certificate Lifecycle

Outlines the principles, configuration, and management of CA trust pools and the PKI certificate lifecycle, emphasizing trust models, certificate operations, and key management to ensure secure authentication and communication within a network environment.

Crosswork Trust Insights and Public-Key Systems

Outlines the use of Crosswork Trust Insights and the implementation of public-key systems, summarizing best practices, configuration steps, and verification processes to enhance secure network operations.

Keychain Management

Details keychain management principles, implementation practices, operational processes, and configuration examples to guide secure authentication, key lifetime administration, and compliance with system requirements within network environments.

MACsec using EAP-TLS Authentication

Outlines MACsec EAP-TLS authentication principles, device roles, prerequisites, local authentication models, configuration workflows, and verification procedures for integrating EAP-TLS with MACsec encryption in network environments.

uRPF Source Address Validation

Outlines uRPF source address validation methods, detailing validation modes, operational behaviors, configuration tasks, compliance requirements, VRF-specific guidelines, and procedures for verifying uRPF operations across network interfaces.

Type 6 Password Encryption

Outlines Type 6 password encryption concepts, operational workflow, and implementation requirements, guiding users through key activation after iPXE boot, encryption processes, maintenance best practices, and secure BGP session configuration with appropriate key management.

Management Plane Protection

Outlines management plane protection features, requirements, restrictions, interface types, configuration workflows, and verification examples to guide secure and efficient management plane operation in network environments.

Secure Shell Fundamentals and Configuration

Explains core SSH functions and CiscoSSH behavior, and provides server, client, NETCONF, host-key, multiplexing, cipher, and HMAC configuration guidance.

Certificate and Public-Key Authentication for SSH

Explains certificate and public-key trust models and provides requirements, configuration, verification, and key-management guidance for SSH clients and servers on Cisco IOS XR routers.

SSH Access and Connection Management

Explains authentication controls, multifactor access, port forwarding, packet marking, and timeout settings that secure and manage SSH connections on the routers.

FIPS Mode and Cryptographic Services

Provides FIPS mode requirements and procedures for compliant cryptographic keys, key chains, certificates, OSPFv3, SNMPv3, and SSH services on Cisco IOS XR routers.

Implementing Secure Logging

Explains how to send system log messages securely over Transport Layer Security (TLS), configure TLS security templates, and apply RFC 5289-compliant cryptographic controls on Cisco 8000 Series Routers.

802.1X and MAC-Based Port Authentication

Describes how Cisco 8000 Series Routers control network access with 802.1X, MAC Authentication Bypass, fallback authentication, and RADIUS Change of Authorization.

Device Ownership and Authorized Operations

Provides the security concepts and operational references for establishing device ownership, obtaining ownership vouchers, provisioning third-party key packages, and authorizing privileged router operations.

Implementing Lawful Intercept

Describes the prerequisites, installation tasks, configuration tasks, operational behavior, and limitations for implementing lawful intercept.

EST Protocol for Automated Certificate Provisioning

Describes the EST protocol, its certificate provisioning capabilities, configuration requirements, authentication options, and configuration procedure.