AT-S63 Management Software Features Guide
Section IX: Management Security
427
SSL and Enhanced Stacking
Secure Sockets Layer (SSL) is supported in an enhanced stack, but only
when all switches in the stack are using the feature.
When a switch’s web server is operating in HTTP, management packets
are transmitted in plaintext. When it operates in HTTPS, management
packets are encrypted. The web server on the AT-9400 Switch operate in
either mode. Enhanced stacking switches that do not support SSL, such
as the AT-8000 Series switches, use HTTP exclusively.
A web browser management session of the switches in an enhanced stack
cannot alternate between the different security modes during a session.
The management session assumes that the web server mode that the
master switch is using is the same for all the switches in the stack. As an
example, if the master switch is using HTTPS, a web browser
management session assumes that all the other switches in the stack are
also using HTTPS, and it does not allow you to manage any switches
running HTTP.
For those networks that consist of enhanced stacking switches where
some switches support SSL and others do not, there are two approaches
you can take. One is to create different enhanced stacks for the different
switches, with one enhanced stack for those switches that support SSL
and another for those that do not. You create different enhanced stacks by
connecting the switches with different common VLANs.
Another workaround is to create one enhanced stack of all the switches
and designate two master switches, where one master switch uses HTTP
and the other HTTPS. When you need to manage those switches in the
stack supporting SSL, you would start the management session on the
master switch whose server mode is set to HTTPS. And when you want to
manage those switch not supporting SSL, you would start the
management session on the master switch whose web server is set to
HTTP.
Each switch in a stack must have its own key pair and certificate. They
cannot share keys and certificates. When you start a web browser
management session on the master switch of an enhanced stack, the
management session uses that switch’s certificate and key pair. When you
change to another switch in the stack, the management session starts to
use the certificate and key pair on that switch, and so forth.
Содержание AT-S63
Страница 14: ...Figures 14 ...
Страница 18: ...Tables 18 ...
Страница 28: ...28 Section I Basic Operations ...
Страница 58: ...Chapter 1 Overview 58 ...
Страница 76: ...Chapter 2 AT 9400Ts Stacks 76 Section I Basic Operations ...
Страница 96: ...Chapter 5 MAC Address Table 96 Section I Basic Operations ...
Страница 114: ...Chapter 8 Port Mirror 114 Section I Basic Operations ...
Страница 116: ...116 Section II Advanced Operations ...
Страница 146: ...Chapter 12 Access Control Lists 146 Section II Advanced Operations ...
Страница 176: ...Chapter 14 Quality of Service 176 Section II Advanced Operations ...
Страница 196: ...196 Section III Snooping Protocols ...
Страница 204: ...Chapter 18 Multicast Listener Discovery Snooping 204 Section III Snooping Protocols ...
Страница 216: ...Chapter 20 Ethernet Protection Switching Ring Snooping 216 Section III Snooping Protocols ...
Страница 218: ...218 Section IV SNMPv3 ...
Страница 234: ...234 Section V Spanning Tree Protocols ...
Страница 268: ...268 Section VI Virtual LANs ...
Страница 306: ...Chapter 27 Protected Ports VLANs 306 Section VI Virtual LANs ...
Страница 320: ...320 Section VII Internet Protocol Routing ...
Страница 360: ...Chapter 30 BOOTP Relay Agent 360 Section VII Routing ...
Страница 370: ...Chapter 31 Virtual Router Redundancy Protocol 370 Section VII Routing ...
Страница 372: ...372 Section VIII Port Security ...
Страница 402: ...Chapter 33 802 1x Port based Network Access Control 402 Section VIII Port Security ...
Страница 404: ...404 Section IX Management Security ...
Страница 436: ...Chapter 36 PKI Certificates and SSL 436 Section IX Management Security ...
Страница 454: ...Chapter 38 TACACS and RADIUS Protocols 454 Section IX Management Security ...
Страница 462: ...Chapter 39 Management Access Control List 462 Section IX Management Security ...
Страница 504: ...Appendix B SNMPv3 Configuration Examples 504 Security Model Security Level Storage Type SNMPv3 Parameters Continued ...
Страница 532: ...Appendix D MIB Objects 532 ...