McAfee MAP-3300-SWG Product Guide - Page 216

Secure Shell Configuration, Table 207, Option definitions - Secure Shell Configuration

Page 216 highlights

Overview of System features Appliance Management Secure Shell Configuration Table 207 Option definitions - Secure Shell Configuration Option Enable the secure shell Definition Click to enable the use of Secure Shell (SSH) to connect remotely to your appliance. By default, when you enable the use of SSH, it allows all hosts or networks that can access the appliance. Click Allow permitted hosts / networks listed below, then select New Address to add only the specified devices access. You can use your SSH client to access the support account on the appliance. Use the same password that you use to access the interface from a remote computer. If you are using out-of-band management and have blocked port 22, change the SSH configuration to allow Secure Shell access. Permitted Displays details of devices that can access the appliance. By default, access is available Host / Network to ALL hosts or networks that can use Secure Shell (SSH). The entries here are added to the /etc/hosts.allow file, and therefore must follow its conventions. We recommend that you allow access to known domains or users initially. To add a network use the following notation formats: • IPv4: 192.168.5.0/24 or 192.168.5.0/255.255.255.0 (allows every host with a network address beginning 192.168.5 to access the secure shell) • IPv6: [3ffe:505:2:1::]/64 (allows every address in the range `3ffe:505:2:1::´ through `3ffe:505:2:1:ffff:ffff:ffff:ffff´) • domain wildcards: *.example.com (allows all hosts in the example.com domain to access the secure shell) To add an individual host, use the following notation formats: • IPv4: 192.168.0.5 (only allows the particular IP address to access the secure shell) • IPv6: [2001:470:921b:7896::3c]. The [ ] must be typed. • hostname: host1.example.com (only allows host1 in the example.com domain to access the secure shell) To add individual hosts, netmasks can not be used. 216 McAfee Email and Web Security Appliances 5.6.0 Product Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336

Secure Shell Configuration
Table 207
Option definitions — Secure Shell Configuration
Option
Definition
Enable the
secure shell
Click to enable the use of Secure Shell (SSH) to connect remotely to your appliance. By
default, when you enable the use of SSH, it allows all hosts or networks that can access
the appliance.
Click
Allow permitted hosts / networks listed below
, then select
New Address
to add only the
specified devices access.
You can use your SSH client to access the support account on the appliance. Use the
same password that you use to access the interface from a remote computer.
If you are using out-of-band management and have blocked port 22, change the SSH
configuration to allow Secure Shell access.
Permitted
Host / Network
Displays details of devices that can access the appliance. By default, access is available
to
ALL
hosts or networks that can use Secure Shell (SSH).
The entries here are added to the /etc/hosts.allow file, and therefore must follow its
conventions. We recommend that you allow access to known domains or users initially.
To add a network use the following notation formats:
• IPv4:
192.168.5.0/24
or
192.168.5.0/255.255.255.0
(allows every host with a
network address beginning 192.168.5 to access the secure shell)
• IPv6:
[3ffe:505:2:1::]/64
(allows every address in the range `3ffe:505:2:1::´
through `3ffe:505:2:1:ffff:ffff:ffff:ffff´)
domain wildcards:
*.example.com
(allows all hosts in the example.com domain to
access the secure shell)
To add an individual host, use the following notation formats:
• IPv4:
192.168.0.5
(only allows the particular IP address to access the secure shell)
• IPv6:
[2001:470:921b:7896::3c]
. The [ ] must be typed.
• hostname:
host1.example.com
(only allows host1 in the example.com domain to
access the secure shell)
To add individual hosts, netmasks can not be used.
Overview of System features
Appliance Management
216
McAfee Email and Web Security Appliances 5.6.0 Product Guide