Generating A New Ssh Server Key; Configuring Tls; About Tls - Cisco 4215 - Intrusion Detection Sys Sensor Configuration Manual

Configuration guide
Hide thumbs Also See for 4215 - Intrusion Detection Sys Sensor:
Table of Contents

Advertisement

Configuring TLS

Generating a New SSH Server Key

Use the ssh generate-key command to change the SSH server host key. The displayed fingerprint
matches the one displayed in the remote SSH client in future connections with this sensor if the remote
client is using SSH 1.5.
To generate a new SSH server host key, follow these steps:
Log in to the CLI using an account with administrator privileges.
Step 1
Generate the new server host key:
Step 2
sensor# ssh generate-key
MD5: 93:F5:51:58:C7:FD:40:8C:07:26:5E:29:13:C8:33:AE
Bubble Babble: ximal-sudez-kusot-gosym-levag-fegoc-holez-cakar-kunel-nylis-kyxox
sensor#
The new key replaces the existing key, which requires you to update the known hosts tables on remote
Caution
systems with the new host key so that future connections succeed. You can update the known hosts tables
on remote systems using the ssh host-key command. For the procedure, see
Hosts List, page
Step 3
Display the current SSH server host key:
sensor# show ssh server-key
1024 35
137196765426571419509124895787229630062726389801071715581921573847280637533000158590028798
074385824867184332364758899959675370523879609376174812179228415215782949029183962207840731
771645803509837259475421477212459797170806510716077556010753169312675023860474987441651041
217710152766990480431898217878170000647
MD5: 93:F5:51:58:C7:FD:40:8C:07:26:5E:29:13:C8:33:AE
Bubble Babble: ximal-sudez-kusot-gosym-levag-fegoc-holez-cakar-kunel-nylis-kyxox
sensor#
Configuring TLS
This section describes how to configure TLS on the sensor, and contains the following topics:

About TLS

IPS 5.0 contains a web server that is running the IDM and ASDM and that the management stations, such
as VMS, connect to. Blocking forwarding sensors also connect to the web server of the master blocking
sensor. To provide security, this web server uses an encryption protocol known as TLS, which is closely
related to SSL protocol. When you enter a URL into the web browser that starts with
https://
encrypted session with the host.
Cisco Intrusion Prevention System Sensor CLI Configuration Guide for IPS 5.0
4-34
4-31.
About TLS, page 4-34
Adding TLS Trusted Hosts, page 4-35
Displaying and Generating the Server Certificate, page 4-37
ip_address, the web browser responds by using either TLS or SSL protocol to negotiate an
Chapter 4
Initial Configuration Tasks
Adding Hosts to the Known
78-16527-01

Advertisement

Table of Contents
loading

Table of Contents