System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases
System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases
Provides comprehensive instructions for securing Cisco IOS XR routers through trustworthy systems, AAA, certificates and key management, SSH, FIPS cryptography, secure logging, port authentication, device ownership, access protection, automated certificate provisioning, and management-plane security.
Specific changes or updates tied to individual releases are clearly called out within the relevant sections. For a list of features introduced in a specific release, refer to the Release Notes.
The table lists the release numbers for which this document has been updated since its initial publication.
| Date | Summary |
|---|---|
|
September 2026 |
First published for Release 26.3.1. |
Lists the YANG data models available for implementing and managing System Security features on Cisco devices.
Short description: Outlines core concepts, hardware and software components, operational processes, security mechanisms, and verification procedures that establish trustworthy systems, highlighting key technologies including roots of trust, secure boot, TPM, ECC P256, and essential security terms.
Outlines comprehensive measures for maintaining trust in secure systems, including steady-state trust models, SELinux, secure installation, SSD encryption, runtime defenses, boot integrity, secure communications, and integrity verification mechanisms.
Outlines AAA access configuration, user identity management, administrative models, and local user setup, guiding administrators through requirements, group structures, database integration, method lists, and step-by-step procedures for secure AAA implementation on network devices.
Outlines AAA password security, FIPS compliance measures, method lists, task-based authorization, command accounting, and configuration patterns to enhance access control and policy enforcement in network environments.
Outlines RADIUS server functionality, secure transport methods with DTLS and TLS, router integration, dead-server detection, server group configuration, and per-VRF AAA techniques to enhance authentication, authorization, and security for network infrastructures.
Outlines TACACS+ integration for AAA, including DSCP marking, server and server group configuration, per-VRF deployment, operational statistics, and securing TACACS+ with TLS protection to enhance access control, authorization, authentication, and accounting in network environments.
Explains CA interoperability concepts and certificate enrollment processes, covering configuration requirements, enrollment methods, and operational workflows for managing digital certificates across integrated systems.
Outlines the principles, configuration, and management of CA trust pools and the PKI certificate lifecycle, emphasizing trust models, certificate operations, and key management to ensure secure authentication and communication within a network environment.
Outlines the use of Crosswork Trust Insights and the implementation of public-key systems, summarizing best practices, configuration steps, and verification processes to enhance secure network operations.
Details keychain management principles, implementation practices, operational processes, and configuration examples to guide secure authentication, key lifetime administration, and compliance with system requirements within network environments.
Outlines MACsec EAP-TLS authentication principles, device roles, prerequisites, local authentication models, configuration workflows, and verification procedures for integrating EAP-TLS with MACsec encryption in network environments.
Outlines uRPF source address validation methods, detailing validation modes, operational behaviors, configuration tasks, compliance requirements, VRF-specific guidelines, and procedures for verifying uRPF operations across network interfaces.
Outlines Type 6 password encryption concepts, operational workflow, and implementation requirements, guiding users through key activation after iPXE boot, encryption processes, maintenance best practices, and secure BGP session configuration with appropriate key management.
Outlines management plane protection features, requirements, restrictions, interface types, configuration workflows, and verification examples to guide secure and efficient management plane operation in network environments.
Explains core SSH functions and CiscoSSH behavior, and provides server, client, NETCONF, host-key, multiplexing, cipher, and HMAC configuration guidance.
Explains certificate and public-key trust models and provides requirements, configuration, verification, and key-management guidance for SSH clients and servers on Cisco IOS XR routers.
Explains authentication controls, multifactor access, port forwarding, packet marking, and timeout settings that secure and manage SSH connections on the routers.
Provides FIPS mode requirements and procedures for compliant cryptographic keys, key chains, certificates, OSPFv3, SNMPv3, and SSH services on Cisco IOS XR routers.
Explains how to send system log messages securely over Transport Layer Security (TLS), configure TLS security templates, and apply RFC 5289-compliant cryptographic controls on Cisco 8000 Series Routers.
Describes how Cisco 8000 Series Routers control network access with 802.1X, MAC Authentication Bypass, fallback authentication, and RADIUS Change of Authorization.
Provides the security concepts and operational references for establishing device ownership, obtaining ownership vouchers, provisioning third-party key packages, and authorizing privileged router operations.
Describes the prerequisites, installation tasks, configuration tasks, operational behavior, and limitations for implementing lawful intercept.
Describes the EST protocol, its certificate provisioning capabilities, configuration requirements, authentication options, and configuration procedure.