Enabling Snmpv3; Securing The Network Management Interface With Access Policies - Nortel 8300 Important Notice

Ethernet routing switch administration and security
Hide thumbs Also See for 8300:
Table of Contents

Advertisement

20 Administration and Security
Use the following commands to verify the SSH parameters:
In NNCLI, these commands can be executed from Privilege Exec Mode,
User Exec Mode, Global configuration mode, and the Interface level.
show ssh global
show ssh session
The JDM support for this feature is available under Edit > Security > SSH.

Enabling SNMPv3

To enable the SNMPv3 protocol, you must load the DES encryption image
into the Ethernet Routing Switch 8300 switch memory. You can obtain the
DES encryption image from the Nortel web site. For more information about
configuring and enabling SNMPv3, refer to Nortel Ethernet Routing Switch
8300 Configuration — Security using CLI and NNCLI (NN46200-503) and
Nortel Ethernet Routing Switch 8300 Configuration — Security using Device
Manager (NN46200-508).

Securing the network management interface with access policies

You can use access policies to quickly secure the network access interfaces
of the device. The following three sections show examples that demonstrate
how you can quickly implement such policies. Bold Courier text indicates
command input. Normal Courier indicates system responses. For detailed
Copyright © 2005-2007, Nortel Networks
.
config sys set ssh version <both|v2only>
or use the following NNCLI command in the global configuration mode:
ssh version <both|v2only>
The default value is v2only.
Use the following CLI command to create the user-defined access policy
to enable the service connections:
config sys access-policy policy <id> service ssh enable
or use the following NNCLI command in the global configuration mode:
access-policy policy <id> ssh
no access-policy policy <id> ssh
The user defined policy must be created before enabling or disabling
any service.
Use the following CLI command to load the encryption module in the
switch:
config load-module [<3DES>|<DES>|<AES>] [<src-file>]
or use the following NNCLI command in the global configuration mode:
load-module [<3DES>|<DES>|<AES>] [WORD<1-1536>]
Nortel Ethernet Routing Switch 8300
Important Notice — Administration and Security
NN46200-601 3.01 Standard
4.0 27 August 2007

Advertisement

Table of Contents
loading

Table of Contents