Sonicwall Ssl Configuration Components - SonicWALL SSL-R User Manual

Secure sockets layer ffloading solutions that allow servers to provide both secure and non-secure services at the same high speeds
Hide thumbs Also See for SSL-R:
Table of Contents

Advertisement

Access Lists
Access lists control which computers can attach to a specific device. When you initially set
up the SSL appliance, no access lists exist. You can restrict the computers allowed to
manage the appliance by adding their IP addresses to one or more access lists for each
device. For more information about configuring access lists, see the commands show
access-list, show access-lists, access-list, remote-management access-list, telnet
access-list, and web-mgmt access-list in Chapter C Command Summary.
Encrypted Management Sessions
To further protect the configuration security, you can specify that remote (non-serial and
non-telnet) configuration sessions be encrypted using AES, DES, or ARC4. See remote-
management encryption in Chapter C Command Summary.
Appliance Factory Default Reset Password
If you have forgotten your access or enable password, you can use a factory-set password
during a serial configuration session. When prompted for a password, enter "FailSafe"
(case-sensitive, without quotation marks). You are asked to confirm the action. The
appliance configuration reboots (reloads) with factory default settings.
Caution: All configuration is lost when using the factory default reset.

SonicWALL SSL Configuration Components

When you configure an appliance to perform SSL offloading you are actually setting up one
or more logical secure servers whose SSL-related configurations reside in the appliance.
Each logical secure server has several attributes:
A unique IP address and TCP port for the web server providing content
An associated key specifying the public/private key pair to use
A single certificate or certificate group to use
A security policy specifying the cryptographic scheme(s) to use
Web Server IP Addresses
Each SSL server is associated with a specific IP address and TCP port. The address and TCP
port are unique and may not be used for more than one SSL server on a single SSL device.
Keys
A single key can be used with each an individual SSL server. You may load multiple keys
into the device; however, only one may be used with each SSL server. Keys can be
imported from PEM, DER, NET-IIS, and PKCS12 format fields.
Chapter 3 SSL Introduction
Page 31

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ssl-ia

Table of Contents