8-16
Configuring Secure Shell (SSH)
Configuring the Switch for SSH Operation
N o t e
When an SSH client connects to the switch for the first time, it is possible for
a “man-in-the-middle” attack; that is, for an unauthorized device to pose
undetected as the switch, and learn the usernames and passwords controlling
access to the switch. This possibility can be removed by directly connecting
the management station to the switch’s serial port, using a
show
command to
display the switch’s public key, and copying the key from the display into a
file. This requires a knowledge of where the client stores public keys, plus the
knowledge of what key editing and file format might be required by the client
application. However, if the first contact attempt between a client and the
switch does not pose a security problem, this is unnecessary.
To enable SSH on the switch.
1.
Generate a public/private key pair if you have not already done so. (Refer
to “2. Generating the Switch’s Public and Private Key Pair” on page 8-9.)
2.
Execute the
ip ssh
command.
To disable SSH on the switch, do either of the following:
■
Execute
no ip ssh
.
■
Zeroize the switch’s existing key pair. (page 8-10).
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......