Security Conventions
l
Password setting
–
When configuring a password, the cipher text is recommended. To ensure device
security, change the password periodically.
–
When you configure a password in plain text that starts and ends with %@%@ (the
password can be decrypted by the device), the password is displayed in the same manner
as the configured one in the configuration file. Do not use this setting.
–
When you configure a password in cipher text, different features cannot use the same
cipher-text password. For example, the cipher-text password set for the AAA feature
cannot be used for other features.
l
Encryption algorithm
Currently, the device uses the following encryption algorithms: 3DES, AES, RSA, SHA1,
SHA2, and MD5. 3DES, RSA and AES are reversible, while SHA1, SHA2, and MD5 are
irreversible. The encryption algorithms DES/3DES/RSA (RSA-1024 or lower)/MD5 (in
digital signature scenarios and password encryption)/SHA1 (in digital signature scenarios)
have a low security, which may bring security risks. If protocols allowed, using more secure
encryption algorithms, such as AES/RSA (RSA-2048 or higher)/SHA2/HMAC-SHA2, is
recommended. The encryption algorithm depends on actual networking. The irreversible
encryption algorithm must be used for the administrator password, SHA2 is recommended.
l
Personal data
Some personal data may be obtained or used during operation or fault location of your
purchased products, services, features, so you have an obligation to make privacy policies
and take measures according to the applicable law of the country to protect personal data.
l
The terms mirrored port, port mirroring, traffic mirroring, and mirroing in this manual are
mentioned only to describe the product's function of communication error or failure
detection, and do not involve collection or processing of any personal information or
communication data of users.
Change History
Changes between document issues are cumulative. Therefore, the latest document version
contains all updates made to previous versions.
Changes in Issue 01 (2014-11-30)
Initial commercial release.
Huawei AR530&AR550 Series Industrial Switch Routers
Configuration Guide - Ethernet Switching
About This Document
Issue 01 (2014-11-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
iv