Configuration Guide
66
Managing System
Access Security Configurations
Step 4
ip http secure-ciphersuite { [ 3des-ede-cbc-sha ] [ rc4-128-md5 ] [ rc4-128-sha ] [ des-cbc-
sha ] }
Enable the corresponding ciphersuite. By default, these types are all enabled.
[ 3des-ede-cbc-sha ]
: Key exchange with 3DES and DES-EDE3-CBC for message encryption
and SHA for message digest.
[ rc4-128-md5 ]
: Key exchange with RC4 128-bit encryption and MD5 for message digest.
[ rc4-128-sha ]
: Key exchange with RC4 128-bit encryption and SHA for message digest.
[ des-cbc-sha ]
: Key exchange with DES-CBC for message encryption and SHA for message
digest.
Step 5
ip http secure-session timeout
minutes
Specify the Session Timeout time. The system will log out automatically if users do nothing
within the Session Timeout time.
minutes
: Specify the timeout time, which ranges from 5 to 30 minutes. The default value is 10.
Step 6
ip https max-users
admin-num
operator-num poweruser-num user-num
Specify the maximum number of users that are allowed to connect to the HTTPS server. The
total number of users should be no more than 16.
admin-num
: Enter the maximum number of users whose access level is Admin. The valid values
are from 1 to 16.
operator-num
: Enter the maximum number of users whose access level is Operator. The valid
values are from 0 to 15.
poweruser-num
: Enter the maximum number of users whose access level is Power User. The
valid values are from 0 to 15.
user-num
: Enter the maximum number of users whose access level is User. The valid values are
from 0 to 15.
Step 7
ip http secure-server download certificate
ssl-cert
ip-address
ip-addr
Download the desired certificate to the switch from TFTP server.
ssl-cert
: Specify the name of the SSL certificate, which ranges from 1 to 25 characters. The
certificate must be BASE64 encoded. The SSL certificate and key downloaded must match
each other.
ip-addr
: Specify the IP address of the TFTP server. Both IPv4 and IPv6 addresses are
supported.
Step 8
ip http secure-server download key
ssl-key
ip-address
ip-addr
Download the desired key to the switch from TFTP server.
ssl-key
: Specify the name of the key file saved in TFTP server. The key must be BASE64
encoded.
ip-addr
: Specify the IP address of the TFTP server. Both IPv4 and IPv6 addresses are
supported.
Step 9
show ip http secure-server
Verify the global configuration of HTTPS.
Содержание T2500G-10MPS
Страница 1: ...User Guide T2500G 10MPS 1910012405 REV1 0 1 April 2018...
Страница 24: ...Using the CLI 767 Appendix Default Parameters 773...
Страница 27: ...Part 1 Accessing the Switch CHAPTERS 1 Overview 2 Web Interface Access 3 Command Line Interface Access...
Страница 129: ...Part 4 Configuring LAG CHAPTERS 1 LAG 2 LAG Configuration 3 Configuration Example 4 Appendix Default Parameters...
Страница 145: ...Part 5 Monitoring Traffic CHAPTERS 1 Traffic Monitor 2 Appendix Default Parameters...
Страница 172: ...Part 7 Configuring DDM CHAPTERS 1 Overview 2 DDM Configuration 3 Appendix Default Parameters...
Страница 190: ...Part 8 Configuring L2PT CHAPTERS 1 Overview 2 L2PT Configuration 3 Configuration Example 4 Appendix Default Parameters...
Страница 274: ...Part 13 Configuring GVRP CHAPTERS 1 Overview 2 GVRP Configuration 3 Configuration Example 4 Appendix Default Parameters...
Страница 800: ...Configuration Guide 776 Configuring SNMP RMON Appendix Default Parameters Parameter Default Setting Status Disable...
Страница 803: ...BSMI Notice Pb Cd Hg CrVI PBB PBDE PCB 1 2...