Huawei AR1200-S Configuration Manual page 237

Enterprise routers
Hide thumbs Also See for AR1200-S:
Table of Contents

Advertisement

Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
As shown in
configured. During an SSL handshake, the AR1200-S uses the SSL parameters in the client SSL
policy to negotiate session parameters with the SSL server. After the handshake is complete, the
AR1200-S establishes a session with the server.
When functioning as an SSL client, the AR1200-S does not allow SSL servers to authenticate
it, but it can authenticate SSL servers. When the AR1200-S functions as an SSL client, enable
it to authenticate servers to ensure secure communication.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
ssl policy policy-name type client
A client SSL policy is created.
Step 3 Run:
server-verify enable
SSL server authentication is enabled.
By default, SSL server authentication is disabled in a client SSL policy.
Step 4 Run:
pki-realm realm-name
A PKI domain is specified for the client SSL policy.
By default, no PKI domain is specified for a client SSL policy on the AR1200-S.
The AR1200-S obtains a CA certificate chain from CAs in the specified PKI domain. The AR1200-S
authenticates an SSL server by checking the server certificate and CA certificates against the CA certificate
chain.
Step 5 (Optional) Run:
version { ssl3.0 | tls1.0 | tls1.1 }
The SSL protocol version is specified.
By default, a client SSL policy uses Transport Layer Security (TLS) version 1.0.
Ensure that the specified SSL protocol version is supported by the SSL server. Before performing this step,
check the SSL protocol versions that the SSL server supports.
Step 6 (Optional) Run:
prefer-ciphersuite { rsa_aes_128_cbc_sha | rsa_des_cbc_sha | rsa_rc4_128_md5 |
rsa_rc4_128_sha }
A cipher suite is specified.
By default, a client SSL policy uses all the cipher suites: rsa_aes_128_cbc_sha, rsa_des_cbc_sha,
rsa_rc4_128_md5, and rsa_rc4_128_sha.
Issue 02 (2012-03-30)
Figure
11-3, the
NOTE
NOTE
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Figure 11-3
functions as an SSL client and has a client SSL policy
11 SSL Configuration
223

Advertisement

Table of Contents
loading

Table of Contents