Configuration manual
4. FTP, FTPS, TFTP and SFTP
57
www.qtech.ru
2048 JUN-27-2015 16:26:10 snmp <DIR>
11698172 JUN-30-2015 10:36:18 sp8-g-6.6.7(76)-dbg.pck
4.3.6
Configure a Device as an FTPS Client
Network Requirements
A PC acts as an FTP server, and Device acts as an FTP client. The network between the
Device and the Client is normal.
Set up the security data channel between FTP Server and FTP Client, providing the security
guarantee for the data transmission.
The file can be uploaded and downloaded between FTP Client and FTP Server.
Network Topology
Figure 4-9 Networking for configuring a device as an FTPS client
Configuration Steps
Step 1:
Configure the IPv4 address of the interface (omitted).
Step 2:
Install the certificate at the FTP Server, and set the FTP user certificate path, private
key path, and CA certificate path:
Step 3:
FTP Client imports the FTP CA certificate, user certificate, and private key.
#Create one domain test on the device:
Device#configure terminal
Device(config)#crypto ca identity test
Device(ca-identity)#exit
#Bind FTP with the domain test:
Device(config)#ip ftp secure-identity test
#Open the CA certificate (rsaRoot.cer) by the notepad, copy the content, input crypto ca
import certificate to test on the shell, and import the certificate to the device domain test
according to the prompt:
Device(config)#crypto ca import certificate to test
% Input the certificate data, press <Enter> twice to finish:
-----BEGIN CERTIFICATE-----
MIIDBzCCAnCgAwIBAgIITpXH17Hj/AswDQYJKoZIhvcNAQEFBQAwYjELMAkGA1UE
BhMCQ04xEDAOBgNVBAgMB0JFSUpJTkcxDjAMBgNVBAoMBUNJRUNDMQ8wDQYDVQQL
DAZHRkEgQ0ExIDAeBgNVBAMMF01pbmlDQSBGcmVCU0QgUm9vdCBDZXJ0MB4XDTA5