Security Overview
Getting Started with Access Security
Keeping the switch in a locked wiring closet or other secure space helps to
prevent unauthorized physical access.
As additional precautions, you can do the following:
■
Disable or re-enable the password-clearing function of the Clear button.
■
Configure the Clear button to reboot the switch after clearing any local
usernames and passwords.
■
Modify the operation of the Reset+Clear button combination so that the
switch reboots, but does not restore the switch’s factory default settings.
■
Disable or re-enable password recovery.
■
Disable USB autorun by setting a Manager password, or enable USB
autorun in secure mode so that security credentials are required to use
this feature.
For the commands used to configure the Clear and Reset buttons, refer to
“Front-Panel Security” on page 2-23. For information on using USB Autorun,
refer to the sections on
“Using USB to Transfer Files to and from the Switch”
and “
Using USB Autorun
” in the
Management and Configuration Guide,
Appendix A “File Transfers”
.
Quick Start: Using the Management Interface Wizard
The Management Interface wizard provides a convenient step-by-step method
to prepare the switch for secure network operation. It guides you through the
process of locking down the following switch operations or protocols:
■
setting local passwords
■
restricting SNMP access
■
enabling/disabling Telnet
■
enabling/disabling SSH
■
enabling/disabling remote Web management
■
restricting web access to SSL
■
enabling/disabling USB autorun
■
setting timeouts for SSH/Telnet sessions
The wizard can also be used to view the pre-configured defaults and see the
current settings for switch access security. The wizard can be launched either
via the CLI (see page 1-12) or the Web browser interface (see page 1-13).
N o t e
The wizard’s security settings can also be configured using standard
commands via the CLI, Menu or Web browser interfaces. For full details on
preparing and configuring the switch for SSH and SSL operation, refer to
chapters 7 and 8 respectively.
1-11
Содержание PROCURVE 2910AL
Страница 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Страница 2: ......
Страница 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Страница 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Страница 156: ...TACACS Authentication Operating Notes 4 30 ...
Страница 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Страница 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Страница 516: ...Configuring Port Based and User Based Access Control 802 1X Messages Related to 802 1X Operation 12 76 ...
Страница 527: ...Configuring and Monitoring Port Security Port Security Figure 13 4 Examples of Show Mac Address Outputs 13 11 ...
Страница 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Страница 592: ...12 Index ...
Страница 593: ......
Страница 594: ... Copyright 2009 Hewlett Packard Development Company L P February 2009 Manual Part Number 5992 5439 ...