User’s
Manual
65
Configuring Switch Using the Web or CLI
Web
Click Security – SSH, Settings
. Enable SSH and adjust the authentication parameters as required, then
click Apply. Note that you must first generate the host key pair on the SSH Host-Key Settings page before
you can enable the SSH server.
CLI
This example enables SSH, sets the authentication parameters, and displays the current configuration. It
shows that the administrator has made a connection through SHH, and then disables this connection.
Console(config)#
ip ssh server
Console(config)#
ip ssh timeout 100
Console(config)#
ip ssh authentication-retries 5
Console(config)#
ip ssh server-key size 512
Console(config)#
end
Console#
show ip ssh
SSH Enabled - version 2.0
Negotiation timeout: 120 secs; Authentication retries: 3
Server key size: 768 bits
Console#
show ssh
Information of secure shell
Session Username Version Encrypt method Negotiation state
------- -------- ------- -------------- -----------------
0 admin 2.0 cipher-3des session-started
Console#
disconnect 0
Console#
6. 5 Configuring Port Security
Port security is a feature that allows you to configure a switch port with one or more device MAC addresses
that are authorized to access the network through that port.
When port security is enabled on a port, the switch stops learning new MAC addresses on the specified port.
Only incoming traffic with source addresses already stored in the dynamic or static address table will be
accepted as authorized to access the network through that port. If a device with an unauthorized MAC
address attempts to use the switch port, the intrusion will be detected and the switch can automatically take
action by disabling the port and sending a trap message.
To use port security, first allow the switch to dynamically learn the <source MAC address, VLAN> pair for
frames received on a port for an initial training period, and then enable port security to stop address
learning. Be sure you enable the learning function long enough to ensure that all valid VLAN members have
been registered on the selected port. Note that you can also restrict the maximum number of addresses that
can be learned by a port.
Содержание IntraCore 36000 Series
Страница 1: ...IntraCore 36000 Series Managed Gigabit Ethernet Switches User s Manual ...
Страница 384: ...384 Asanté IntraCore 36000 Series ...
Страница 385: ...User s Manual 385 ...