Ssl Global Settings - D-Link DXS-3600 Series Reference Manual

Layer 2/3 managed 10gigabut ethernet switch
Hide thumbs Also See for DXS-3600 Series:
Table of Contents

Advertisement

DXS-3600 Series Layer 3 Managed 10Gigabit Ethernet Switch Web UI Reference Guide
Switch supports the 3DES EDE encryption code defined by the Data Encryption Standard
(DES) to create the encrypted text.
Hash Algorithm: This part of the cipher suite allows the user to choose a message digest function
which will determine a Message Authentication Code. This Message Authentication Code will be
encrypted with a sent message to provide integrity and prevent against replay attacks. The Switch
supports two hash algorithms, MD5 (Message Digest 5) and SHA (Secure Hash Algorithm).
These three parameters are uniquely assembled in four choices on the Switch to create a three-layered
encryption code for secure communication between the server and the host. The user may implement
any one or combination of the cipher suites available, yet different cipher suites will affect the security
level and the performance of the secured connection. The information included in the cipher suites is not
included with the Switch and requires downloading from a third source in a file form called a certificate.
This function of the Switch cannot be executed without the presence and implementation of the certificate
file and can be downloaded to the Switch by utilizing a TFTP server. The Switch supports SSLv3. Other
versions of SSL may not be compatible with this Switch and may cause problems upon authentication
and transfer of messages from client to host.
When the SSL function has been enabled, the web will become disabled. To manage the Switch through
the web based management while utilizing the SSL function, the web browser must support SSL
encryption and the header of the URL must begin with https://. (Ex. https://xx.xx.xx.xx) Any other method
will result in an error and no access can be authorized for the web-based management.
Users can download a certificate file for the SSL function on the Switch from a TFTP server. The
certificate file is a data record used for authenticating devices on the network. It contains information on
the owner, keys for authentication and digital signatures. Both the server and the client must have
consistent certificate files for optimal use of the SSL function. The Switch only supports certificate files
with .der file extensions. Currently, the Switch comes with a certificate pre-loaded though the user may
need to download more, depending on user circumstances.

SSL Global Settings

This window is used to view and configure the SSL feature's global settings.
To view the following window, click Security > SSL > SSL Global Settings, as shown below:
The fields that can be configured in SSL Global Settings are described below:
Parameter
SSL Status
Service Policy
Click the Apply button to accept the changes made.
Figure 9-89 SSL Global Settings Window
Description
Select to enable or disable the SSL feature's global status here.
Enter the service policy name here. This name can be up to 32
characters long.
535

Advertisement

Table of Contents
loading

Table of Contents