Symantec 10521146 Administration Guide - Page 307

Generating SSH keys, Using SCP to transfer log files, Configuration > Generate SSH Keys

Page 307 highlights

Advanced configuration 307 Backing up and restoring Generating SSH keys The Network Security console provides a way to generate SSH keys. Use SSH keys when using SCP to securely transfer log files from a 7100 Series appliance to another machine, or target host, which must support SSH and SCP. To use SCP, you must first generate SSH keys for your account on the 7100 Series node and install the resulting public key on the target host. To generate SSH keys 1 Do one of the following: ■ On Devices, right-click the 7100 Series node object on which you wish to generate SSH keys, then click Configuration > 7100 Series Configuration > Generate SSH Keys. ■ On Devices, click Configuration > Node > 7100 Series Configuration > Generate SSH Keys and choose a node from the pull-down list in Select Node. Click OK. 2 If a Warning is displayed, read the message and do one of the following: ■ Click Yes to generate new SSH keys. This replaces any existing keys. ■ Click No to exit the process. 3 In Generating SSH Keys, wait while Symantec Network Security generates the SSH keys. 4 In Public Key, read the public key filename at the top, and the instructions for installing it on the target host. In the instructions, is the home directory of user on the target host who can use the public key to decrypt the transferred log files. This user should not be root. 5 Follow the instructions to add the public key to the target host, and click Close. Using SCP to transfer log files After generating and installing the SSH keys, you can configure log and database parameters for automatic log rotation to the target host. To configure automatic log rotation 1 Do one of the following: ■ On Devices, right-click the 7100 Series node object, then click Configuration > Network Security Parameters.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392

307
Advanced configuration
Backing up and restoring
Generating SSH keys
The Network Security console provides a way to generate SSH keys. Use SSH
keys when using SCP to securely transfer log files from a 7100 Series appliance
to another machine, or target host, which must support SSH and SCP. To use
SCP, you must first generate SSH keys for your account on the 7100 Series node
and install the resulting public key on the target host.
To generate SSH keys
1
Do one of the following:
On
Devices
, right-click the 7100 Series node object on which you wish
to generate SSH keys, then click
Configuration
>
7100 Series
Configuration > Generate SSH Keys
.
On
Devices
, click
Configuration
>
Node
>
7100 Series Configuration >
Generate SSH Keys
and choose a node from the pull-down list in
Select
Node
. Click
OK.
2
If a
Warning
is displayed, read the message and do one of the following:
Click
Yes
to generate new SSH keys. This replaces any existing keys.
Click
No
to exit the process.
3
In
Generating SSH Keys
, wait while Symantec Network Security generates
the SSH keys.
4
In
Public Key
, read the public key filename at the top, and the instructions
for installing it on the target host.
In the instructions, <user_home_dir> is the home directory of user on the
target host who can use the public key to decrypt the transferred log files.
This user should not be root.
5
Follow the instructions to add the public key to the target host, and click
Close
.
Using SCP to transfer log files
After generating and installing the SSH keys, you can configure log and
database parameters for automatic log rotation to the target host.
To configure automatic log rotation
1
Do one of the following:
On
Devices
, right-click the 7100 Series node object, then click
Configuration
>
Network Security Parameters
.