
C
HAPTER
14
| Security Measures
Configuring the Secure Shell
– 301 –
To use the SSH server, complete these steps:
1.
Generate a Host Key Pair
– On the SSH Host Key Settings page, create
a host public/private key pair.
2.
Provide Host Public Key to Clients
– Many SSH client programs
automatically import the host public key during the initial connection
setup with the switch. Otherwise, you need to manually create a known
hosts file on the management station and place the host public key in
it. An entry for a public key in the known hosts file would appear similar
to the following example:
10.1.0.54 1024 35
15684995401867669259333946775054617325313674890836547254
15020245593199868544358361651999923329781766065830956
10825913212890233 76546801726272571413428762941301196195566782
59566410486957427888146206519417467729848654686157177393901647
79355942303577413098022737087794545240839717526463580581767167
09574804776117
3.
Import Client’s Public Key to the Switch
– See
, or use the
tftp public-key
command
(
) to copy a file containing the public key for all the SSH
client’s granted management access to the switch. (Note that these
clients must be configured locally on the switch via the User Accounts
.) The clients are subsequently
authenticated using these keys. The current firmware only accepts
public key files based on standard UNIX format as shown in the
following example for an RSA Version 1 key:
1024 35
13410816856098939210409449201554253476316419218729589211431738
80055536161631051775940838686311092912322268285192543746031009
37187721199696317813662774141689851320491172048303392543241016
37997592371449011938006090253948408482717819437228840253311595
2134861022902978982721353267131629432532818915045306393916643
4.
Set the Optional Parameters
– On the SSH Settings page, configure the
optional parameters, including the authentication timeout, the number
of retries, and the server key size.
5.
Enable SSH Service
– On the SSH Settings page, enable the SSH server
on the switch.
6.
Authentication – One of the following authentication methods is
employed:
Password Authentication (for SSH v1.5 or V2 Clients)
a.
The client sends its password to the server.
b.
The switch compares the client's password to those stored in
memory.
c.
If a match is found, the connection is allowed.
Summary of Contents for ES3510MA-DC
Page 1: ...Management Guide www edge core com 8 Port Layer 2 Fast Ethernet Switch...
Page 2: ......
Page 4: ......
Page 6: ...ABOUT THIS GUIDE 6...
Page 44: ...FIGURES 44...
Page 50: ...TABLES 50...
Page 52: ...SECTION I Getting Started 52...
Page 62: ...CHAPTER 1 Introduction System Defaults 62...
Page 80: ...CHAPTER 2 Initial Switch Configuration Managing System Files 80...
Page 82: ...SECTION II Web Configuration 82...
Page 98: ...CHAPTER 3 Using the Web Interface Navigating the Web Browser Interface 98...
Page 126: ...CHAPTER 4 Basic Management Tasks Resetting the System 126...
Page 164: ...CHAPTER 5 Interface Configuration VLAN Trunking 164 Figure 57 Configuring VLAN Trunking...
Page 202: ...CHAPTER 7 Address Table Settings Configuring MAC Address Mirroring 202...
Page 452: ...CHAPTER 17 IP Services Displaying the DNS Cache 452...
Page 498: ...CHAPTER 19 Using the Command Line Interface CLI Command Groups 498...
Page 588: ...CHAPTER 22 SNMP Commands 588...
Page 596: ...CHAPTER 23 Remote Monitoring Commands 596...
Page 650: ...CHAPTER 24 Authentication Commands Management IP Filter 650...
Page 738: ...CHAPTER 27 Interface Commands 738...
Page 760: ...CHAPTER 29 Port Mirroring Commands RSPAN Mirroring Commands 760...
Page 782: ...CHAPTER 32 Address Table Commands 782...
Page 810: ...CHAPTER 33 Spanning Tree Commands 810...
Page 862: ...CHAPTER 35 VLAN Commands Configuring Voice VLANs 862...
Page 876: ...CHAPTER 36 Class of Service Commands Priority Commands Layer 3 and 4 876...
Page 932: ...CHAPTER 38 Multicast Filtering Commands Multicast VLAN Registration 932...
Page 956: ...CHAPTER 39 LLDP Commands 956...
Page 1020: ...CHAPTER 42 Domain Name Service Commands 1020...
Page 1026: ...CHAPTER 43 DHCP Commands DHCP Client 1026...
Page 1058: ...CHAPTER 44 IP Interface Commands IPv6 Interface 1058...
Page 1060: ...SECTION IV Appendices 1060...
Page 1066: ...APPENDIX A Software Specifications Management Information Bases 1066...
Page 1088: ...COMMAND LIST 1088...
Page 1097: ......