Using Authorized IP Managers
Operating Notes
Operating Notes
■
Network Security Precautions:
You can enhance your network’s secu
rity by keeping physical access to the switch restricted to authorized
personnel, using the password features built into the switch, using the
additional security features described in this manual, and preventing
unauthorized access to data on your management stations.
■
Modem and Direct Console Access:
Configuring authorized IP manag
ers does not protect against access to the switch through a modem or
direct Console (RS-232) port connection.
■
Duplicate IP Addresses:
If the IP address configured in an authorized
management station is also configured (or “spoofed”) in another station,
the other station can gain management access to the switch even though
a duplicate IP address condition exists.
■
Web Proxy Servers:
If you use the web browser interface to access the
switch from an authorized IP manager station, it is recommended that you
avoid the use of a web proxy server in the path between the station and
the switch. This is because switch access through a web proxy server
requires that you first add the web proxy server to the Authorized Manager
IP list.
This reduces security by opening switch access to anyone who
uses the web proxy server
. The following two options outline how to
eliminate a web proxy server from the path between a station and the
switch:
•
Even if you need proxy server access enabled in order to use
other applications, you can still eliminate proxy service for web
access to the switch. To do so, add the IP address or DNS name
of the switch to the non-proxy, or “Exceptions” list in the web
browser interface you are using on the authorized station.
•
If you don’t need proxy server access at all on the authorized
station, then just disable the proxy server feature in the station’s
web browser interface.
14-13
Содержание PROCURVE 2910AL
Страница 1: ...Access Security Guide ProCurve Switches W 14 03 2910al www procurve com ...
Страница 2: ......
Страница 3: ...HP ProCurve 2910al Switch February 2009 W 14 03 Access Security Guide ...
Страница 84: ...Configuring Username and Password Security Front Panel Security 2 36 ...
Страница 156: ...TACACS Authentication Operating Notes 4 30 ...
Страница 288: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup 8 22 ...
Страница 416: ...Configuring Advanced Threat Protection Using the Instrumentation Monitor 10 28 ...
Страница 516: ...Configuring Port Based and User Based Access Control 802 1X Messages Related to 802 1X Operation 12 76 ...
Страница 527: ...Configuring and Monitoring Port Security Port Security Figure 13 4 Examples of Show Mac Address Outputs 13 11 ...
Страница 572: ...Using Authorized IP Managers Operating Notes 14 14 ...
Страница 592: ...12 Index ...
Страница 593: ......
Страница 594: ... Copyright 2009 Hewlett Packard Development Company L P February 2009 Manual Part Number 5992 5439 ...