© Copyright Lenovo 2018
Chapter 4: Securing Administration
93
SSH and SCP Encryption of Management Messages
The
following
encryption
and
authentication
methods
are
supported
for
SSH
and
SCP:
Server
Host
Authentication: Client
RSA
authenticates
the
switch
at
the
beginning
of
every
connection
Key
Exchange:
RSA
Encryption:
3DES
‐
CBC,
DES
User
Authentication:
Local
password
authentication,
RADIUS
Generating an RSA Host Key for SSH Access
To
support
the
SSH
server
feature,
an
RSA
host
key
is
required.
The
host
key
is
2048
bits
and
is
used
to
identify
the
NE2552E.
When
the
SSH
server
is
first
enabled
and
applied,
the
switch
automatically
generates
the
RSA
host
key
and
stores
it
in
FLASH
memory.
To
configure
an
RSA
host
key,
first
connect
to
the
NE2552E
through
the
console
port
(commands
are
not
available
via
external
Telnet
connection),
and
enter
the
following
command
to
generate
it
manually.
When
the
switch
reboots,
it
will
retrieve
the
host
key
from
the
FLASH
memory.
Notes:
The
switch
will
perform
only
one
session
of
key/cipher
generation
at
a
time.
Thus,
an
SSH/SCP
client
will
not
be
able
to
log
in
if
the
switch
is
performing
key
generation
at
that
time.
Also,
key
generation
will
fail
if
an
SSH/SCP
client
is
logging
in
at
that
time.
Because
the
switch
software
only
generates
RSA
keys,
if
there
is
already
a
DSA
‐
based
SSH
key
on
the
switch,
this
key
will
remain
on
the
switch
and
not
be
replaced
until
you
run
the
ssh generate-host key
command
to
generate
an
RSA
key.
SSH/SCP Integration with RADIUS Authentication
SSH/SCP
is
integrated
with
RADIUS
authentication.
After
the
RADIUS
server
is
enabled
on
the
switch,
all
subsequent
SSH
authentication
requests
will
be
redirected
to
the
specified
RADIUS
servers
for
authentication.
The
redirection
is
transparent
to
the
SSH
clients.
SSH/SCP Integration with Authentication
SSH/SCP
is
integrated
with
authentication.
After
the
server
is
enabled
on
the
switch,
all
subsequent
SSH
authentication
requests
will
be
redirected
to
the
specified
servers
for
authentication.
The
redirection
is
transparent
to
the
SSH
clients.
NE2552E(config)#
ssh generate-host-key
(Generates
the
host
key)
Summary of Contents for ThinkSystem NE2552E
Page 27: ... Copyright Lenovo 2018 27 Part 1 Getting Started ...
Page 28: ...28 NE2552E Application Guide for ENOS 8 4 ...
Page 70: ...70 NE2552E Application Guide for ENOS 8 4 ...
Page 85: ... Copyright Lenovo 2018 85 Part 2 Securing the Switch ...
Page 86: ...86 NE2552E Application Guide for ENOS 8 4 ...
Page 112: ...112 NE2552E Application Guide for ENOS 8 4 ...
Page 134: ...134 NE2552E Application Guide for ENOS 8 4 ...
Page 154: ...154 NE2552E Application Guide for ENOS 8 4 ...
Page 194: ...194 NE2552E Application Guide for ENOS 8 4 ...
Page 218: ...218 NE2552E Application Guide for ENOS 8 4 ...
Page 234: ...234 NE2552E Application Guide for ENOS 8 4 ...
Page 238: ...238 NE2552E Application Guide for ENOS 8 4 ...
Page 239: ... Copyright Lenovo 2018 239 Part 4 Advanced Switching Features ...
Page 240: ...240 NE2552E Application Guide for ENOS 8 4 ...
Page 242: ...242 NE2552E Application Guide for ENOS 8 4 ...
Page 278: ...278 NE2552E Application Guide for ENOS 8 4 ...
Page 284: ...284 NE2552E Application Guide for ENOS 8 4 ...
Page 314: ...314 NE2552E Application Guide for ENOS 8 4 ...
Page 338: ...338 NE2552E Application Guide for ENOS 8 4 ...
Page 374: ...374 NE2552E Application Guide for ENOS 8 4 ...
Page 388: ...388 NE2552E Application Guide for ENOS 8 4 ...
Page 418: ...418 NE2552E Application Guide for ENOS 8 4 ...
Page 430: ...430 NE2552E Application Guide for ENOS 8 4 ...
Page 432: ...432 NE2552E Application Guide for ENOS 8 4 ...
Page 436: ...436 NE2552E Application Guide for ENOS 8 4 ...
Page 460: ...460 NE2552E Application Guide for ENOS 8 4 ...
Page 461: ... Copyright Lenovo 2018 461 Part 7 Network Management ...
Page 462: ...462 NE2552E Application Guide for ENOS 8 4 ...
Page 476: ...476 NE2552E Application Guide for ENOS 8 4 ...
Page 498: ...498 NE2552E Application Guide for ENOS 8 4 ...
Page 520: ...520 NE2552E Application Guide for ENOS 8 4 ...
Page 534: ...534 NE2552E Application Guide for ENOS 8 4 ...
Page 536: ...536 NE2552E Application Guide for ENOS 8 4 ...
Page 544: ...544 NE2552E Application Guide for ENOS 8 4 ...
Page 549: ... Copyright Lenovo 2018 549 Part 9 Appendices ...
Page 550: ...550 NE2552E Application Guide for ENOS 8 4 ...
Page 566: ...566 NE2552E Application Guide for ENOS 8 4 ...
Page 572: ...572 NE2552E Application Guide for ENOS 8 4 ...
Page 573: ......
Page 574: ...Part Number 01KN246 Printed in USA IP P N 01KN246 ...