© Copyright Lenovo 2017
Chapter 25: Using IPsec with IPv6
423
3.
Export
the
CSR
file
to
an
external
server:
Generating an IKEv2 Digital Certificate
To
create
an
IKEv2
digital
certificate
for
authentication:
1.
Create
an
HTTPS
certificate
defining
the
information
you
want
to
be
used
in
the
various
fields.
2.
Save
the
HTTPS
certificate.
The
certificate
is
valid
only
until
the
switch
is
rebooted.
To
save
the
certificate
so
that
it
is
retained
beyond
reboot
or
power
cycles,
use
the
following
command:
3.
Enable
IKEv2
RSA
‐
signature
authentication:
CN 4093>
show https host-csr pem-format
-----BEGIN CERTIFICATE REQUEST-----
MIICtDCCAZwCAQAwbzELMAkGA1UEBhMCVVMxEzARBgNVBAgMCkNhbGlmb3JuaWEx
ETAPBgNVBAcMCFNhbiBKb3NlMQwwCgYDVQQKDANBQkMxFDASBgNVBAsMC0VuZ2lu
ZWVyaW5nMRQwEgYDVQQDDAt3d3cuYWJjLmNvbTCCASIwDQYJKoZIhvcNAQEBBQAD
ggEPADCCAQoCggEBAMEnVJBSnIYxmYKpWga7E5j9JSK9JU57Md7NofJ2
FvQ8hfPO8b4bzLQzKbNBxGc59BJjZJ5w8eGKRDCjlIf1uIAgg3Gs8ZK1FozOUJZN
xbtYBx6QrTBYmXdHStQ7CQ9sfWhnEnusnvc8bxNlukyuEcFsAUdz93r1sEfN3cDe
/bO43l7GmvhTEdmfFvAfgi9b9RDqUjla2kwhjvHCTeveQN1/MYQZvbJo
V4qq+pgQOt9ZJOMDrGQ0GdxXVwGePCOvCRLESsq5rQb3zPSVvWnTsq0G
VQN9dI9lANZGZJi6BRNIRdBen/dH0KRcCAwEAAaAAMA0GCSqGSIb3DQEB
BQUAA4IBAQCSLDOrOnl7kaZri2Oj9Skde3MehaklddfZnCkT1ALL3ZXY
xWwYnvF5jAgnHhxRJbPOzwHNDWMtZiiNOTHyzHVptsyRBv70Kb8odJmuyKWDqunJ
Ho1hHe63a6io3kGrmq1bdM0ZXXUaiK1p/lNLOrsYk45D01Az
YHhcdRQtFUbQxqbirpi0jLsi82X7JCNQ2XCP6dhphkWKI6wsCvV/gH/X
wqMkNF8m1COd2yzSXxqpG/Xf0TRF9SAyN5vKiPvh6RkXXeNV
neyr2J5JENyGORPynuV5GUHa
-----END CERTIFICATE REQUEST-----
CN 4093(config)#
copy cert-request tftp
Port type ["DATA"/"MGT"/"EXTM"]:
<port
type>
Address or name of remote host:
<hostname
or
IPv4
address>
Destination file name:
<path
and
filename
on
the
remote
server>
Certificate request successfully tftp'd to...
CN 4093(config)#
access https generate-certificate
Country Name (2 letter code) []:
<country
code>
State or Province Name (full name) []:
<state>
Locality Name (eg, city) []:
<city>
Organization Name (eg, company) []:
<company>
Organizational Unit Name (eg, section) []:
<org.
unit>
Common Name (eg, YOUR name) []:
<name>
Email (eg, email address) []:
address>
Confirm generat‘eywing certificate? [y/n]:
y
Generating certificate. Please wait (approx 30 seconds)
restarting SSL agent
CN 4093(config)#
access https save-certificate
CN 4093(config)#
access https enable
Содержание Flex System Fabric CN4093
Страница 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Страница 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Страница 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Страница 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Страница 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Страница 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Страница 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Страница 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Страница 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Страница 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Страница 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Страница 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Страница 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Страница 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Страница 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Страница 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Страница 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Страница 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Страница 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Страница 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Страница 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Страница 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Страница 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Страница 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Страница 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Страница 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Страница 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Страница 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Страница 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Страница 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Страница 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Страница 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Страница 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Страница 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Страница 633: ......
Страница 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...