![SNR S2940-8G-v2 Скачать руководство пользователя страница 345](http://html1.mh-extra.com/html/snr/s2940-8g-v2/s2940-8g-v2_configuration-manual_1310630345.webp)
SNR S2940-8G-v2 Switch Configuration Guide
SSL Configuration
the other program in sequence, lose packet and re-forwarding will not appear. A lot of transmis-
sion protocols can provide such kind of service in theory, but in actual application, SSL is almost
running on TCP, and not running on UDP and IP directly.
When web function is running on the switch and client visit our web site through the internet
browser, we can use SSL function. The communication between client and switch through SSL
connect can improve the security.
Firstly, SSL should be enabled on the switch. When the client tries to access the switch through
https method, a SSL session will be set up between the switch and the client. When the SSL
session has been set up, all the data transmission in the application layer will be encrypted.
SSL handshake is done when the SSL session is being set up. The switch should be able to
provide certification keys. Currently the keys provided by the switch are not the formal certification
keys issued by official authentic, but the private certification keys generated by SSL software under
Linux which may not be recognized by the web browser. With regard to the switch application, it
is not necessary to apply for a formal SSL certification key. A private certification key is enough
to make the communication safe between the users and the switch. Currently it is not required
that the client is able to check the validation of the certification key. The encryption key and the
encryption method should be negotiated during the handshake period of the session which will be
then used for data encryption.
SSL session handshake process:
1
Client ->
encryption algorithm random key for encryption
-> Server
2
Client <-
The selected encryption algorithm, the certification
which is randomly generated
<- Server
3
Client ->
The encrypted master_key
-> Server
4
Client <-
To compute the encryption key
<- Server
5
Client ->
The MAC value of the handshaking messages
-> Server
6
Client <-
The MAC value of the handshaking messages
<- Server
51.2
SSL Configuration Task List
1. Enable/disable SSL function
2. Configure/delete port number by SSL used
3. Configure/delete secure cipher suite by SSL used
4. Maintenance and diagnose for the SSL function
1. Enable/disable SSL function
Command
Explanation
Global Mode
ip http secure-server
no ip http secure-server
Enable/disable SSL function.
345
Содержание S2940-8G-v2
Страница 11: ...SNR S2940 8G v2 Switch Configuration Guide Part I Basic Management Configuration 11...
Страница 46: ...SNR S2940 8G v2 Switch Configuration Guide Part II Port Configuration 46...
Страница 123: ...SNR S2940 8G v2 Switch Configuration Guide Part III VLAN and MAC Table Configuration 123...
Страница 164: ...SNR S2940 8G v2 Switch Configuration Guide Part IV MSTP Configuration 164...
Страница 176: ...SNR S2940 8G v2 Switch Configuration Guide Part V QoS and Flow based Redirection Configuration 176...
Страница 198: ...SNR S2940 8G v2 Switch Configuration Guide Part VI L3 Forward and ARP Configuration 198...
Страница 218: ...SNR S2940 8G v2 Switch Configuration Guide Part VII DHCP Configuration 218...
Страница 257: ...SNR S2940 8G v2 Switch Configuration Guide Part VIII Multicast Protocol 257...
Страница 278: ...SNR S2940 8G v2 Switch Configuration Guide Part IX Security Function Configuration 278...
Страница 376: ...SNR S2940 8G v2 Switch Configuration Guide Part X Reliability Configuration 376...
Страница 395: ...SNR S2940 8G v2 Switch Configuration Guide Part XI Flow Monitor Configuration 395...
Страница 403: ...SNR S2940 8G v2 Switch Configuration Guide Part XII Network Time Management Configuration 403...
Страница 411: ...SNR S2940 8G v2 Switch Configuration Guide Part XIII Debugging and Diagnosis 411...