15.1 Introduction to Management Service
In network, safety of the switch itself is the most important, also focused on by administrator.
iSpirit 3026 switch provide not only user’s name and password, but also provide management
service to ensure that safety of switch.
iSpirit 3026 switch provide TELNET, WEB, and SNMP service to realize remote management for
switch, e.g. close or start and connect the service to ACL resource bank to ensure safe
management.
Switch management besides serial-port has other visit control methods as TELNET, WEB, and
SNMP, which can control switch in remote, avoid any time and area limitations, so it is well
welcomed administrator. But the safety problem should not be ignored, especially where it
needs high safety performance. Besides central operator's lab personnel, other users do not
permitted to operate the switch, or only specific users can be admitted to operate the switch
when it is much important to control management services.
Based on different demands, administrator can close TELNET, WEB, or/and SNMP services,
administrator or users cannot through these closed service visit the switch. For example switch
close TELNET service, so all users cannot through TELNET to enter into the switch.
The device can obtain good safety if management service of switch has been closed. Which is
mainly based on communication principle between supplicant end and service end and identify
users’ management information. For above three kinds of entries to identify that whether the
administrator has started with relative services, if not the user cannot with this kind of service to
enter into the switch.
If the administrator needs TELNET, WEB or/and SNMP services, which must be started, when
the user with user’s name and password can manage switch in any switch end with these
services. When the switch is in unsafe status, user’s name and password will be embezzled by
attacker who can damage the device by entering into the switch.
iSpirit 3026 switch through management service and ACL realize the safety of management
service. The switch uses of standard IP regulation in ACL resource bank to control the visit, only
the service from legal IP address is admitted but not that from illegal IP address.