© Copyright Lenovo 2018
Chapter 1: Switch Administration
51
Boot Strict Mode
The
implementations
specified
in
this
section
are
compliant
with
National
Institute
of
Standards
and
Technology
(NIST)
Special
Publication
(SP)
800
‐
131A.
The
NE2552E
Flex
Switch
can
operate
in
two
boot
modes:
Compatibility
mode
(default):
This
is
the
default
switch
boot
mode.
This
mode
may
use
algorithms
and
key
lengths
that
may
not
be
allowed/acceptable
by
NIST
SP
800
‐
131A
specification.
This
mode
is
useful
in
maintaining
compatibility
with
previous
releases
and
in
environments
that
have
lesser
data
security
requirements.
Strict
mode:
Encryption
algorithms,
protocols,
and
key
lengths
in
strict
mode
are
compliant
with
NIST
SP
800
‐
131A
specification.
When
in
boot
strict
mode,
the
switch
uses
Secure
Sockets
Layer
(SSL)/Transport
Layer
Security
(TLS)
1.2
protocols
to
ensure
confidentiality
of
the
data
to
and
from
the
switch.
By
default,
HTTP,
Telnet,
and
SNMPv1
and
SNMPv2
are
disabled
on
the
NE2552E.
Before
enabling
strict
mode,
ensure
the
following:
The
software
version
on
all
connected
switches
is
Lenovo
ENOS
8.4.
NIST
Strict
compliance
is
enabled
on
the
Chassis
Management
Module.
The
supported
protocol
versions
and
cryptographic
cipher
suites
between
clients
and
servers
are
compatible.
For
example:
if
using
SSH
to
connect
to
the
switch,
ensure
that
the
SSH
client
supports
SSHv2
and
a
strong
cipher
suite
that
is
compliant
with
the
NIST
standard.
Compliant
Web
server
certificate
is
installed
on
the
switch,
if
using
BBI.
A
new
self
‐
signed
certificate
is
generated
for
the
switch
(
NE2552E(config)#
access https generate-certificate
).
The
new
certificate
is
generated
using
2048
‐
bit
RSA
key
and
SHA
‐
256
digest.
Protocols
that
are
not
NIST
SP
800
‐
131A
compliant
must
be
disabled
or
not
used.
Only
SSHv2
or
higher
is
used.
The
current
configuration,
if
any,
must
be
saved
in
a
location
external
to
the
switch.
When
the
switch
reboots,
both
the
startup
and
running
configuration
are
lost.
Содержание ThinkSystem NE2552E
Страница 27: ... Copyright Lenovo 2018 27 Part 1 Getting Started ...
Страница 28: ...28 NE2552E Application Guide for ENOS 8 4 ...
Страница 70: ...70 NE2552E Application Guide for ENOS 8 4 ...
Страница 85: ... Copyright Lenovo 2018 85 Part 2 Securing the Switch ...
Страница 86: ...86 NE2552E Application Guide for ENOS 8 4 ...
Страница 112: ...112 NE2552E Application Guide for ENOS 8 4 ...
Страница 134: ...134 NE2552E Application Guide for ENOS 8 4 ...
Страница 154: ...154 NE2552E Application Guide for ENOS 8 4 ...
Страница 194: ...194 NE2552E Application Guide for ENOS 8 4 ...
Страница 218: ...218 NE2552E Application Guide for ENOS 8 4 ...
Страница 234: ...234 NE2552E Application Guide for ENOS 8 4 ...
Страница 238: ...238 NE2552E Application Guide for ENOS 8 4 ...
Страница 239: ... Copyright Lenovo 2018 239 Part 4 Advanced Switching Features ...
Страница 240: ...240 NE2552E Application Guide for ENOS 8 4 ...
Страница 242: ...242 NE2552E Application Guide for ENOS 8 4 ...
Страница 278: ...278 NE2552E Application Guide for ENOS 8 4 ...
Страница 284: ...284 NE2552E Application Guide for ENOS 8 4 ...
Страница 314: ...314 NE2552E Application Guide for ENOS 8 4 ...
Страница 338: ...338 NE2552E Application Guide for ENOS 8 4 ...
Страница 374: ...374 NE2552E Application Guide for ENOS 8 4 ...
Страница 388: ...388 NE2552E Application Guide for ENOS 8 4 ...
Страница 418: ...418 NE2552E Application Guide for ENOS 8 4 ...
Страница 430: ...430 NE2552E Application Guide for ENOS 8 4 ...
Страница 432: ...432 NE2552E Application Guide for ENOS 8 4 ...
Страница 436: ...436 NE2552E Application Guide for ENOS 8 4 ...
Страница 460: ...460 NE2552E Application Guide for ENOS 8 4 ...
Страница 461: ... Copyright Lenovo 2018 461 Part 7 Network Management ...
Страница 462: ...462 NE2552E Application Guide for ENOS 8 4 ...
Страница 476: ...476 NE2552E Application Guide for ENOS 8 4 ...
Страница 498: ...498 NE2552E Application Guide for ENOS 8 4 ...
Страница 520: ...520 NE2552E Application Guide for ENOS 8 4 ...
Страница 534: ...534 NE2552E Application Guide for ENOS 8 4 ...
Страница 536: ...536 NE2552E Application Guide for ENOS 8 4 ...
Страница 544: ...544 NE2552E Application Guide for ENOS 8 4 ...
Страница 549: ... Copyright Lenovo 2018 549 Part 9 Appendices ...
Страница 550: ...550 NE2552E Application Guide for ENOS 8 4 ...
Страница 566: ...566 NE2552E Application Guide for ENOS 8 4 ...
Страница 572: ...572 NE2552E Application Guide for ENOS 8 4 ...
Страница 573: ......
Страница 574: ...Part Number 01KN246 Printed in USA IP P N 01KN246 ...