Cisco Cisco IOS Software Release 12.2(13)ZH
20
Release Notes for the Cisco 1700 Series Routers for Cisco IOS Release 12.2(13)ZH5
OL-4161-03
New and Changed Information
Direct HTTP Enroll with CA Servers
Some Certificate Authorities (CAs) support enrollment via HTTP. The Cisco IOS software allows a user
to specify a profile for HTTP enrollment related operations. The Cisco IOS software will fill in the
command template within the profile with the PKCS 10 certificate request and up to eight user provided
values. The resulting message will be sent to the HTTP server, and the response will be parsed for a PEM
format certificate.
to specify a profile for HTTP enrollment related operations. The Cisco IOS software will fill in the
command template within the profile with the PKCS 10 certificate request and up to eight user provided
values. The resulting message will be sent to the HTTP server, and the response will be parsed for a PEM
format certificate.
For more details of this feature, refer to the following URL:
DHCP Option 82
The Dynamic Host Configuration Protocol (DHCP) relay agent information option (option 82) enables
a DHCP relay agent to include information about itself when forwarding client-originated DHCP packets
to a DHCP server. The DHCP server can use this information to implement IP address or other
parameter-assignment policies.
a DHCP relay agent to include information about itself when forwarding client-originated DHCP packets
to a DHCP server. The DHCP server can use this information to implement IP address or other
parameter-assignment policies.
DHCP Option 82 Support for Routed Bridge Encapsulation
The DHCP Option 82 Support for Routed Bridge Encapsulation feature provides support for the DHCP
relay agent information option when ATM routed bridge encapsulation (RBE) is used.
relay agent information option when ATM routed bridge encapsulation (RBE) is used.
This feature communicates information to the DHCP server using a sub-option of the DHCP relay agent
information option called agent remote ID. The information sent in the agent remote ID includes an IP
address identifying the relay agent and information about the ATM interface and the PVC over which
the DHCP request came in. The DHCP server can use this information to make IP address assignments
and security policy decisions.
information option called agent remote ID. The information sent in the agent remote ID includes an IP
address identifying the relay agent and information about the ATM interface and the PVC over which
the DHCP request came in. The DHCP server can use this information to make IP address assignments
and security policy decisions.
DHCP Option 82 for Subscriber Identification
This feature enables the DHCP relay agent to include information about itself and the attached client
when forwarding DHCP requests from a DHCP client to a DHCP server. The DHCP server can use this
information to assign IP addresses, perform access control, and set quality of service (QoS) and security
policies (or other parameter-assignment policies) for each subscriber of a service-provider network.
when forwarding DHCP requests from a DHCP client to a DHCP server. The DHCP server can use this
information to assign IP addresses, perform access control, and set quality of service (QoS) and security
policies (or other parameter-assignment policies) for each subscriber of a service-provider network.
By enabling the DCHP option 82 feature on the switch, a subscriber is identified by the switch port
through which it connects to the network (rather than by its MAC address). Multiple hosts on the
subscriber LAN can be connected to the same port on the access switch and are uniquely identified.
through which it connects to the network (rather than by its MAC address). Multiple hosts on the
subscriber LAN can be connected to the same port on the access switch and are uniquely identified.
For more details, refer to the following URLs:
•
DHCP Address Allocation Using Option 82
•
DHCP Option 82 Support for Routed Bridge Encapsulation
•
DHCP Option 82 for Subscriber Identification