© Copyright Lenovo 2017
Chapter 4: Securing Administration
93
SSH and SCP Encryption of Management Messages
The
following
encryption
and
authentication
methods
are
supported
for
SSH
and
SCP:
Server
Host
Authentication: Client
RSA
authenticates
the
switch
at
the
beginning
of
every
connection
Key
Exchange:
RSA
Encryption:
3DES
‐
CBC,
DES
User
Authentication:
Local
password
authentication,
RADIUS
Generating RSA Host Key for SSH Access
To
support
the
SSH
server
feature,
an
RSA
host
key
is
required.
The
host
key
is
2048
bits
and
is
used
to
identify
the
CN4093.
When
the
SSH
server
is
first
enabled
and
applied,
the
switch
automatically
generates
the
RSA
host
key
and
stores
it
in
FLASH
memory.
To
configure
RSA
host
key,
first
connect
to
the
CN4093
through
the
console
port
(commands
are
not
available
via
external
Telnet
connection),
and
enter
the
following
command
to
generate
it
manually.
When
the
switch
reboots,
it
will
retrieve
the
host
key
from
the
FLASH
memory.
Note:
The
switch
will
perform
only
one
session
of
key/cipher
generation
at
a
time.
Thus,
an
SSH/SCP
client
will
not
be
able
to
log
in
if
the
switch
is
performing
key
generation
at
that
time.
Also,
key
generation
will
fail
if
an
SSH/SCP
client
is
logging
in
at
that
time.
SSH/SCP Integration with RADIUS Authentication
SSH/SCP
is
integrated
with
RADIUS
authentication.
After
the
RADIUS
server
is
enabled
on
the
switch,
all
subsequent
SSH
authentication
requests
will
be
redirected
to
the
specified
RADIUS
servers
for
authentication.
The
redirection
is
transparent
to
the
SSH
clients.
SSH/SCP Integration with Authentication
SSH/SCP
is
integrated
with
authentication.
After
the
server
is
enabled
on
the
switch,
all
subsequent
SSH
authentication
requests
will
be
redirected
to
the
specified
servers
for
authentication.
The
redirection
is
transparent
to
the
SSH
clients.
CN 4093(config)#
ssh generate-host-key
(Generates
the
host
key)
Содержание Flex System Fabric CN4093
Страница 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Страница 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Страница 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Страница 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Страница 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Страница 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Страница 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Страница 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Страница 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Страница 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Страница 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Страница 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Страница 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Страница 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Страница 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Страница 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Страница 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Страница 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Страница 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Страница 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Страница 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Страница 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Страница 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Страница 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Страница 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Страница 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Страница 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Страница 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Страница 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Страница 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Страница 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Страница 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Страница 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Страница 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Страница 633: ......
Страница 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...