206
RackSwitch G8000: Application Guide
Generating an IKEv2 Digital Certificate
To create an IKEv2 digital certificate for authentication:
1. Create an HTTPS certificate defining the information you want to be used in the
various fields.
2. Save the HTTPS certificate.
The certificate is valid only until the switch is rebooted. To save the certificate so
that it is retained beyond reboot or power cycles, use the following command:
3. Enable IKEv2 RSA-signature authentication:
Enabling IKEv2 Preshared Key Authentication
To set up IKEv2 preshared key authentication:
1. Enter the local preshared key.
2. If asymmetric authentication is supported, enter the remote key:
where the following parameters are used:
–
preshared key
A string of 1-256 characters
–
IPv6 host
An IPv6-format host, such as “3000::1”
3. Set up the IKEv2 identification type by entering
one
of the following commands:
To disable IKEv2 RSA-signature authentication method and enable preshared key
authentication, enter:
RS G8000(config)#
access https
generate-certificate
Country Name (2 letter code) []:
<country code>
State or Province Name (full name) []:
<state>
Locality Name (eg, city) []:
<city>
Organization Name (eg, company) []:
<company>
Organizational Unit Name (eg, section) []:
<org. unit>
Common Name (eg, YOUR name) []:
<name>
Email (eg, email address) []:
<email address>
Confirm generat‘eywing certificate? [y/n]:
y
Generating certificate. Please wait (approx 30 seconds)
restarting SSL agent
RS G8000(config)#
access https save-certificate
RS G8000(config)#
access https enable
RS G8000(config)#
ikev2 preshare-key local
<preshared key, a string of 1-256 chars>
RS G8000(config)#
ikev2 preshare-key remote
<
preshared key> <IPv6
host
>
RS G8000(config)#
ikev2 identity local address
(
use an IPv6 address)
RS G8000(config)#
ikev2 identity local email
<
email address
>
RS G8000(config)#
ikev2 identity local fqdn
<
domain name
>
RS G8000(config)#
access https disable
Содержание RackSwitch G8000
Страница 1: ...RackSwitch G8000 Application Guide...
Страница 2: ......
Страница 3: ...RackSwitch G8000 Application Guide...
Страница 16: ...16 RackSwitch G8000 Application Guide...
Страница 22: ...20 RackSwitch G8000 Application Guide...
Страница 23: ...Copyright IBM Corp 2011 21 Part 1 Getting Started...
Страница 24: ...22 RackSwitch G8000 Application Guide...
Страница 54: ...52 RackSwitch G8000 Application Guide...
Страница 55: ...Copyright IBM Corp 2011 53 Part 2 Securing the Switch...
Страница 56: ...54 RackSwitch G8000 Application Guide...
Страница 92: ...90 RackSwitch G8000 Application Guide...
Страница 94: ...92 RackSwitch G8000 Application Guide...
Страница 144: ...142 RackSwitch G8000 Application Guide...
Страница 145: ...Copyright IBM Corp 2011 143 Part 4 Advanced Switch ing Features...
Страница 146: ...144 RackSwitch G8000 Application Guide...
Страница 148: ...146 RackSwitch G8000 Application Guide...
Страница 182: ...180 RackSwitch G8000 Application Guide...
Страница 184: ...182 RackSwitch G8000 Application Guide...
Страница 212: ...210 RackSwitch G8000 Application Guide...
Страница 258: ...256 RackSwitch G8000 Application Guide...
Страница 286: ...284 RackSwitch G8000 Application Guide...
Страница 294: ...292 RackSwitch G8000 Application Guide...
Страница 298: ...296 RackSwitch G8000 Application Guide...
Страница 310: ...308 RackSwitch G8000 Application Guide...
Страница 311: ...Copyright IBM Corp 2011 309 Part 7 Network Management...
Страница 312: ...310 RackSwitch G8000 Application Guide...
Страница 320: ...318 RackSwitch G8000 Application Guide...
Страница 332: ...330 RackSwitch G8000 Application Guide...
Страница 334: ...332 RackSwitch G8000 Application Guide...
Страница 345: ...Copyright IBM Corp 2011 343 Part 9 Appendices...
Страница 346: ...344 RackSwitch G8000 Application Guide...
Страница 357: ...Copyright IBM Corp 2011 Appendix C Notices 355 Taiwan Class A compliance statement...
Страница 358: ...356 RackSwitch G8000 Application Guide...