
2.4 Configuration Examples
This section provides an HTTPS configuration example.
2.4.1 Example for Configuring the Router as an HTTPS Server
This section describes how to configure an HTTPS server to allow the administrator of an
enterprise to remotely log in to a gateway.
Networking Environment
As shown in
, the administrator of enterprise A works in a different city than the R&D
department. The administrator needs to securely log in to the gateway of the R&D department
to manage the gateway.
To meet the preceding requirement, configure the HTTPS server function on the Router (the
gateway) so that:
l
The administrator establishes an HTTPS connection with the Router (the gateway) from a
host named Admin and manages the Router on web pages.
l
The administrator uses the SSL protocol's security mechanisms to authenticate the
Router, improving remote access security.
NOTE
To implement certificate authentication, you also need to configure a Certificate Authority (CA) server. The CA
server configuration is not mentioned here.
Figure 2-2
Networking diagram of HTTPS server configuration
Admin
1.1.1.1/24
CA
R&D department
Router
PC
Internet
Eth1/0/0
2.1.1.1/24
3.1.1.1/24
Enterprise A
Configuration Roadmap
The configuration roadmap is as follows:
1.
Configure a public key infrastructure (PKI) entity and a PKI domain.
2.
Configure a server SSL policy.
3.
Configure the Router as an HTTPS server.
Data Preparation
To complete the configuration, you need the following data:
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
2 HTTPS Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
38