HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 7

Setting the DSCP value for packets sent by the SSH server, Configuring the switch as an SFTP client, v

Page 7 highlights

Configuring CRL-checking-disabled PKI certificate verification 165 Destroying a local RSA key pair 165 Deleting a certificate 166 Configuring an access control policy 166 Displaying and maintaining PKI 166 PKI configuration examples 167 Certificate request from an RSA Keon CA server 167 Certificate request from a Windows 2003 CA server 170 Certificate attribute access control policy configuration example 173 Troubleshooting PKI 175 Failed to retrieve a CA certificate 175 Failed to request a local certificate 175 Failed to retrieve CRLs 176 Configuring SSH2.0 177 Overview 177 SSH operation 177 SSH connection across VPNs 179 Configuring the switch as an SSH server 180 SSH server configuration task list 180 Generating DSA or RSA key pairs 180 Enabling the SSH server function 181 Configuring the user interfaces for SSH clients 181 Configuring a client public key 182 Configuring an SSH user 183 Setting the SSH management parameters 184 Setting the DSCP value for packets sent by the SSH server 185 Configuring the switch as an SSH client 185 SSH client configuration task list 185 Specifying a source IP address/interface for the SSH client 185 Configuring whether first-time authentication is supported 186 Establishing a connection between the SSH client and server 187 Setting the DSCP value for packets sent by the SSH client 187 Displaying and maintaining SSH 188 SSH server configuration examples 188 When the switch acts as a server for password authentication 188 When the switch acts as a server for publickey authentication 190 SSH client configuration examples 195 When switch acts as client for password authentication 195 When switch acts as client for publickey authentication 198 Configuring SFTP 201 Overview 201 Configuring the switch as an SFTP server 201 Enabling the SFTP server 201 Configuring the SFTP connection idle timeout period 201 Configuring the switch as an SFTP client 202 Specifying a source IP address or interface for the SFTP client 202 Establishing a connection to the SFTP server 202 Working with SFTP directories 203 Working with SFTP files 204 Displaying help information 204 Terminating the connection to the remote SFTP server 205 Setting the DSCP value for packets sent by the SFTP client 205 SFTP client configuration example 205 v

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

v
Configuring CRL-checking-disabled PKI certificate verification ······································································ 165
Destroying a local RSA key pair ································································································································ 165
Deleting a certificate ···················································································································································· 166
Configuring an access control policy ························································································································ 166
Displaying and maintaining PKI ································································································································· 166
PKI configuration examples········································································································································· 167
Certificate request from an RSA Keon CA server ···························································································· 167
Certificate request from a Windows 2003 CA server ···················································································· 170
Certificate attribute access control policy configuration example ································································· 173
Troubleshooting PKI ····················································································································································· 175
Failed to retrieve a CA certificate······················································································································ 175
Failed to request a local certificate ··················································································································· 175
Failed to retrieve CRLs ········································································································································ 176
Configuring SSH2.0 ··············································································································································· 177
Overview······································································································································································· 177
SSH operation ····················································································································································· 177
SSH connection across VPNs ····························································································································· 179
Configuring the switch as an SSH server ·················································································································· 180
SSH server configuration task list ······················································································································ 180
Generating DSA or RSA key pairs ···················································································································· 180
Enabling the SSH server function······················································································································· 181
Configuring the user interfaces for SSH clients ································································································ 181
Configuring a client public key·························································································································· 182
Configuring an SSH user ···································································································································· 183
Setting the SSH management parameters ········································································································ 184
Setting the DSCP value for packets sent by the SSH server
············································································ 185
Configuring the switch as an SSH client ··················································································································· 185
SSH client configuration task list························································································································ 185
Specifying a source IP address/interface for the SSH client ·········································································· 185
Configuring whether first-time authentication is supported ············································································· 186
Establishing a connection between the SSH client and server ······································································· 187
Setting the DSCP value for packets sent by the SSH client ············································································· 187
Displaying and maintaining SSH ······························································································································· 188
SSH server configuration examples ··························································································································· 188
When the switch acts as a server for password authentication ····································································· 188
When the switch acts as a server for publickey authentication ····································································· 190
SSH client configuration examples····························································································································· 195
When switch acts as client for password authentication ················································································ 195
When switch acts as client for publickey authentication ················································································ 198
Configuring SFTP····················································································································································· 201
Overview······································································································································································· 201
Configuring the switch as an SFTP server ················································································································· 201
Enabling the SFTP server ···································································································································· 201
Configuring the SFTP connection idle timeout period ····················································································· 201
Configuring the switch as an SFTP client
··················································································································· 202
Specifying a source IP address or interface for the SFTP client······································································ 202
Establishing a connection to the SFTP server···································································································· 202
Working with SFTP directories ··························································································································· 203
Working with SFTP files ······································································································································ 204
Displaying help information ······························································································································· 204
Terminating the connection to the remote SFTP server ···················································································· 205
Setting the DSCP value for packets sent by the SFTP client ············································································ 205
SFTP client configuration example ····························································································································· 205