Security Overview
Getting Started with Access Security
Keeping the switch in a locked wiring closet or other secure space helps to
prevent unauthorized physical access.
As additional precautions, you can do the following:
■
Disable or re-enable the password-clearing function of the Clear button.
■
Configure the Clear button to reboot the switch after clearing any local
usernames and passwords.
■
Modify the operation of the Reset+Clear button combination so that the
switch reboots, but does not restore the switch’s factory default settings.
■
Disable or re-enable password recovery.
■
Disable USB autorun by setting a Manager password, or enable USB
autorun in secure mode so that security credentials are required to use
this feature.
For the commands used to configure the Clear and Reset buttons, refer to
“Front-Panel Security” on page 2-23. For information on using USB Autorun,
refer to the sections on
“Using USB to Transfer Files to and from the Switch”
and “
Using USB Autorun
” in the
Management and Configuration Guide,
Appendix A “File Transfers”
.
Quick Start: Using the Management Interface Wizard
The Management Interface wizard provides a convenient step-by-step method
to prepare the switch for secure network operation. It guides you through the
process of locking down the following switch operations or protocols:
■
setting local passwords
■
restricting SNMP access
■
enabling/disabling Telnet
■
enabling/disabling SSH
■
enabling/disabling remote Web management
■
restricting web access to SSL
■
enabling/disabling USB autorun
■
setting timeouts for SSH/Telnet sessions
The wizard can also be used to view the pre-configured defaults and see the
current settings for switch access security. The wizard can be launched either
via the CLI (see page 1-12) or the Web browser interface (see page 1-13).
N o t e
The wizard’s security settings can also be configured using standard
commands via the CLI, Menu or Web browser interfaces. For full details on
preparing and configuring the switch for SSH and SSL operation, refer to
chapters 7 and 8 respectively.
1-11
Summary of Contents for PROCURVE 2910AL
Page 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Page 2: ......
Page 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Page 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Page 156: ...TACACS Authentication Operating Notes 4 30 ...
Page 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Page 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Page 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Page 592: ...12 Index ...
Page 593: ......