Cisco SR224T Administration Guide - Page 266

SSD Management Channels, Menu CLI and Password Recovery, Secure Sensitive Data

Page 266 highlights

Secure Sensitive Data SSD Management Channels 19 SSD Management Channels Devices can be managed over management channels such as telnet, SSH, and web. SSD categories the channels into the following types based on their security and/or protocols: secured, insecure, secure-XML-SNMP, and insecure-XML-SNMP. The following describes whether SSD considers each management channel to be secure or insecure. If it is insecure, the table indicates the parallel secure channel. Security of Management Channels Management Channels Management Channel SSD Management Parallel Secured Channel Type Management Channel GUI/HTTP Insecure GUI/HTTPS GUI/HTTPS Secure XML/HTTP Insecure-XMLSNMP XML/HTTPS XML/HTTPS Secure-XML-SNMP TFTP Insecure HTTP based file transfer Insecure HTTPS-based file transfer HTTPS based file transfer Secure Menu CLI and Password Recovery The Menu CLI interface is only allowed to users if their read permissions are Both or Plaintext Only. Other users are rejected. Sensitive data in the Menu CLI is always displayed as plaintext. Password recovery is currently activated from the boot menu and allows the user to log on to the terminal without authentication. If SSD is supported, this option is only permitted if the local passphrase is identical to the default passphrase. If a device is configured with a user-defined passphrase, the user is unable to activate password recovery. Cisco Small Business 200 Series Smart Switch Administration Guide 267

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283

Secure Sensitive Data
SSD Management Channels
Cisco Small Business 200 Series Smart Switch Administration Guide
267
19
SSD Management Channels
Devices can be managed over management channels such as telnet, SSH, and
web. SSD categories the channels into the following types based on their security
and/or protocols: secured, insecure, secure-XML-SNMP, and insecure-XML-SNMP.
The following describes whether SSD considers each management channel to be
secure or insecure. If it is insecure, the table indicates the parallel secure channel.
Security of Management Channels
Menu CLI and Password Recovery
The Menu CLI interface is only allowed to users if their read permissions are Both
or Plaintext Only. Other users are rejected. Sensitive data in the Menu CLI is always
displayed as plaintext.
Password recovery is currently activated from the boot menu and allows the user
to log on to the terminal without authentication. If SSD is supported, this option is
only permitted if the local passphrase is identical to the default passphrase. If a
device is configured with a user-defined passphrase, the user is unable to activate
password recovery.
Management Channels
Management Channel
SSD Management
Channel Type
Parallel Secured
Management Channel
GUI/HTTP
Insecure
GUI/HTTPS
GUI/HTTPS
Secure
XML/HTTP
Insecure-XML-
SNMP
XML/HTTPS
XML/HTTPS
Secure-XML-SNMP
TFTP
Insecure
HTTP based file transfer
Insecure
HTTPS-based file transfer
HTTPS based file transfer
Secure