52
CN4093 Application Guide for N/OS 8.4
Boot Strict Mode
The
implementations
specified
in
this
section
are
compliant
with
National
Institute
of
Standards
and
Technology
(NIST)
Special
Publication
(SP)
800
‐
131A.
The
CN4093
10
Gb
Converged
Scalable
Switch
can
operate
in
two
boot
modes:
Compatibility
mode
(default):
This
is
the
default
switch
boot
mode.
This
mode
may
use
algorithms
and
key
lengths
that
may
not
be
allowed/acceptable
by
NIST
SP
800
‐
131A
specification.
This
mode
is
useful
in
maintaining
compatibility
with
previous
releases
and
in
environments
that
have
lesser
data
security
requirements.
Strict
mode:
Encryption
algorithms,
protocols,
and
key
lengths
in
strict
mode
are
compliant
with
NIST
SP
800
‐
131A
specification.
When
in
boot
strict
mode,
the
switch
uses
Secure
Sockets
Layer
(SSL)/Transport
Layer
Security
(TLS)
1.2
protocols
to
ensure
confidentiality
of
the
data
to
and
from
the
switch.
By
default,
HTTP,
Telnet,
and
SNMPv1
and
SNMPv2
are
disabled
on
the
CN4093.
Before
enabling
strict
mode,
ensure
the
following:
The
software
version
on
all
connected
switches
is
Enterprise
NOS
8.4.
NIST
Strict
compliance
is
enabled
on
the
Chassis
Management
Module.
The
supported
protocol
versions
and
cryptographic
cipher
suites
between
clients
and
servers
are
compatible.
For
example:
if
using
SSH
to
connect
to
the
switch,
ensure
that
the
SSH
client
supports
SSHv2
and
a
strong
cipher
suite
that
is
compliant
with
the
NIST
standard.
Compliant
Web
server
certificate
is
installed
on
the
switch,
if
using
BBI.
A
new
self
‐
signed
certificate
is
generated
for
the
switch
(
CN 4093(config)#
access https generate-certificate
).
The
new
certificate
is
generated
using
2048
‐
bit
RSA
key
and
SHA
‐
256
digest.
Protocols
that
are
not
NIST
SP
800
‐
131A
compliant
must
be
disabled
or
not
used.
Only
SSHv2
or
higher
is
used.
The
current
configuration,
if
any,
must
be
saved
in
a
location
external
to
the
switch.
When
the
switch
reboots,
both
the
startup
and
running
configuration
are
lost.
Содержание Flex System Fabric CN4093
Страница 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Страница 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Страница 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Страница 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Страница 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Страница 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Страница 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Страница 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Страница 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Страница 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Страница 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Страница 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Страница 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Страница 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Страница 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Страница 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Страница 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Страница 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Страница 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Страница 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Страница 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Страница 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Страница 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Страница 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Страница 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Страница 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Страница 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Страница 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Страница 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Страница 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Страница 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Страница 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Страница 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Страница 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Страница 633: ......
Страница 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...