Configuring Secure Shell (SSH)
Configuring the Switch for SSH Operation
C a u t i o n
To allow SSH access
only
to clients having the correct public key, you
must
configure the secondary (password) method for
login public-key
to
none
.
Otherwise a client without the correct public key can still gain entry by
submitting a correct local login password.
Syntax:
aaa authentication ssh enable < local | tacacs | radius > < local | none >
Configures a password method for the primary and second
ary enable (Manager) access. If you do not specify an
optional secondary method, it defaults to
none
.
For example, assume that you have a client public-key file named
Client-
Keys.pub
(on a TFTP server at 10.33.18.117) ready for downloading to the
switch. For SSH access to the switch you want to allow only clients having a
private key that matches a public key found in
Client-Keys.pub.
For Manager-
level (enable) access for successful SSH clients you want to use for
primary password authentication and
local
for secondary password authenti
cation, with a Manager username of "1eader" and a password of "m0ns00n".
To set up this operation you would configure the switch in a manner similar
to the following:
ProCurve(config)# password manager user-name leader
New password for Manager: ********
Please retype new password for Manager: ********
ProCurve(config)# aaa authentication ssh login public-key none
ProCurve(config)# aaa authentication ssh enable tacacs local
ProCurve(config)# coy tftp pub-key-file 10.33.18.117
ProCurve(config)# write memory
Configures Manager user-
name and password.
Configures the
switch to allow
SSH access only
for a client whose
public key
matches one of the
keys in the public
key file.
Configures the primary and
secondary password methods for
Manager (enable) access. (Becomes
available after SSH access is granted
Copies a public key file
named "Client-Keys.pub"
into the switch.
Figure 7-11. Configuring for SSH Access Requiring a
Client Public-Key Match and Manager Passwords
7-20
Содержание J8697A
Страница 1: ...6200yl Access Security Guide 5400zl 3500yl ProCurve Switches K 11 XX www procurve com ...
Страница 2: ......
Страница 22: ...Product Documentation Feature Index xx ...
Страница 55: ...Configuring Username and Password Security Front Panel Security 2 21 ...
Страница 56: ...Configuring Username and Password Security Front Panel Security 2 22 ...
Страница 58: ...Virus Throttling Contents Operating Notes 3 30 Connection Rate Log and Trap Messages 3 31 3 2 ...
Страница 88: ...Virus Throttling Connection Rate Log and Trap Messages This page is intentionally unused 3 32 ...
Страница 118: ...Web and MAC Authentication Client Status This page intentionally unused 4 30 ...
Страница 230: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup This page is intentionally unused 8 22 ...
Страница 356: ...Configuring and Monitoring Port Security Operating Notes for Port Security 11 44 ...
Страница 370: ...Using Authorized IP Managers Operating Notes This page is intentionally unused 12 14 ...
Страница 388: ...10 Index ...
Страница 389: ......