Contents
10
RADIUS Accounting........................................................................................................................................397
General Steps .................................................................................................................................................398
Guidelines .......................................................................................................................................................399
Section IX: Management Security .........................................................................403
Chapter 34: Web Server
..............................................................................................................................405
Supported Platforms .......................................................................................................................................406
Overview .........................................................................................................................................................407
Supported Protocols .................................................................................................................................407
Configuring the Web Server for HTTP ............................................................................................................408
Configuring the Web Server for HTTPS..........................................................................................................409
General Steps for a Self-signed Certificate ..............................................................................................409
General Steps for a Public or Private CA Certificate ................................................................................409
Chapter 35: Encryption Keys
......................................................................................................................411
Supported Platforms .......................................................................................................................................412
Overview .........................................................................................................................................................413
Encryption Key Length....................................................................................................................................414
Encryption Key Guidelines..............................................................................................................................415
Technical Overview.........................................................................................................................................416
Data Encryption ........................................................................................................................................416
Data Authentication ..................................................................................................................................418
Key Exchange Algorithms ........................................................................................................................419
Chapter 36: PKI Certificates and SSL
........................................................................................................421
Supported Platforms .......................................................................................................................................422
Overview .........................................................................................................................................................423
Types of Certificates .......................................................................................................................................423
Distinguished Names ......................................................................................................................................425
SSL and Enhanced Stacking ..........................................................................................................................427
Guidelines .......................................................................................................................................................428
Technical Overview.........................................................................................................................................429
SSL Encryption.........................................................................................................................................429
User Verification .......................................................................................................................................430
Authentication...........................................................................................................................................430
Public Key Infrastructure ..........................................................................................................................431
Public Keys...............................................................................................................................................431
Message Encryption .................................................................................................................................431
Digital Signatures .....................................................................................................................................431
Certificates................................................................................................................................................432
Elements of a Public Key Infrastructure ...................................................................................................433
Certificate Validation.................................................................................................................................434
Certificate Revocation Lists (CRLs)..........................................................................................................434
PKI Implementation ..................................................................................................................................435
Chapter 37: Secure Shell (SSH)
..................................................................................................................437
Supported Platforms .......................................................................................................................................438
Overview .........................................................................................................................................................439
Support for SSH..............................................................................................................................................440
SSH Server .....................................................................................................................................................441
SSH Clients.....................................................................................................................................................442
SSH and Enhanced Stacking..........................................................................................................................443
SSH Configuration Guidelines ........................................................................................................................445
General Steps to Configuring SSH .................................................................................................................446
Содержание AT-S63
Страница 14: ...Figures 14 ...
Страница 18: ...Tables 18 ...
Страница 28: ...28 Section I Basic Operations ...
Страница 58: ...Chapter 1 Overview 58 ...
Страница 76: ...Chapter 2 AT 9400Ts Stacks 76 Section I Basic Operations ...
Страница 96: ...Chapter 5 MAC Address Table 96 Section I Basic Operations ...
Страница 114: ...Chapter 8 Port Mirror 114 Section I Basic Operations ...
Страница 116: ...116 Section II Advanced Operations ...
Страница 146: ...Chapter 12 Access Control Lists 146 Section II Advanced Operations ...
Страница 176: ...Chapter 14 Quality of Service 176 Section II Advanced Operations ...
Страница 196: ...196 Section III Snooping Protocols ...
Страница 204: ...Chapter 18 Multicast Listener Discovery Snooping 204 Section III Snooping Protocols ...
Страница 216: ...Chapter 20 Ethernet Protection Switching Ring Snooping 216 Section III Snooping Protocols ...
Страница 218: ...218 Section IV SNMPv3 ...
Страница 234: ...234 Section V Spanning Tree Protocols ...
Страница 268: ...268 Section VI Virtual LANs ...
Страница 306: ...Chapter 27 Protected Ports VLANs 306 Section VI Virtual LANs ...
Страница 320: ...320 Section VII Internet Protocol Routing ...
Страница 360: ...Chapter 30 BOOTP Relay Agent 360 Section VII Routing ...
Страница 370: ...Chapter 31 Virtual Router Redundancy Protocol 370 Section VII Routing ...
Страница 372: ...372 Section VIII Port Security ...
Страница 402: ...Chapter 33 802 1x Port based Network Access Control 402 Section VIII Port Security ...
Страница 404: ...404 Section IX Management Security ...
Страница 436: ...Chapter 36 PKI Certificates and SSL 436 Section IX Management Security ...
Страница 454: ...Chapter 38 TACACS and RADIUS Protocols 454 Section IX Management Security ...
Страница 462: ...Chapter 39 Management Access Control List 462 Section IX Management Security ...
Страница 504: ...Appendix B SNMPv3 Configuration Examples 504 Security Model Security Level Storage Type SNMPv3 Parameters Continued ...
Страница 532: ...Appendix D MIB Objects 532 ...