Secure Shell (Ssh); Secure Socket Layer (Sslv3/Tlsv1); Traffic/Security Filters - ProCurve 2900 Manual

Table of Contents

Advertisement

Secure Shell (SSH)

SSH provides Telnet-like functions through encrypted, authenticated transac­
tions of the following types:
client public-key authentication: uses one or more public keys (from
clients) that must be stored on the switch. Only a client with a private key
that matches a stored public key can gain access to the switch.
switch SSH and user password authentication: this option is a subset
of the client public-key authentication, and is used if the switch has SSH
enabled without a login access configured to authenticate the client's key.
In this case, the switch authenticates itself to clients, and users on SSH
clients then authenticate themselves to the switch by providing pass­
words stored on a RADIUS or TACACS+ server, or locally on the switch.
secure copy (SC) and secure FTP (SFTP): By opening a secure,
encrypted SSH session, you can take advantage of SC and SFTP to provide
a secure alternative to TFTP for transferring sensitive switch information.
For more information on SSH, refer to Chapter 6, "Configuring Secure Shell
(SSH)". For more on SC and SFTP, refer to the section titled "Using Secure
Copy and SFTP" in the "File Transfers" appendix of the Management and
Configuration Guide for your switch.

Secure Socket Layer (SSLv3/TLSv1)

This feature includes use of Transport Layer Security (TLSv1) to provide
remote web access to the switch via authenticated transactions and encrypted
paths between the switch and management station clients capable of SSL/TLS
operation. The authenticated type includes server certificate authentication
with user password authentication. For more information, refer to Chapter 7,
"Configuring Secure Socket Layer (SSL)".

Traffic/Security Filters

These statically configured filters enhance in-band security (and improve
control over access to network resources) by forwarding or dropping inbound
network traffic according to the configured criteria. Filter options include:
source-port filters: Inbound traffic from a designated, physical source-
port will be forwarded or dropped on a per-port (destination) basis.
multicast filters: Inbound traffic having a specified multicast MAC
address will be forwarded to outbound ports or dropped on a per-port
(destination) basis.
Security Overview
Network Security Features
1-9

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve switch 2900-24gProcurve switch 2900-48g

Table of Contents