Controlling Management Access to the ProCurve Secure Router
Securing Management Access to the ProCurve Secure Router
N o t e
If you want to use an ACL to restrict SSH access, you apply this ACL at the
SSH line configuration mode context. For more information, see the Advanced
Management and Configuration Guide, Chapter 5: Applying Access Control
to Router Interfaces.
Using FTP to Access the Router
After you add one username and password to the local user list, you can use
FTP to access the router. You can then copy configuration files to and from
the router's compact flash or internal flash. If you want to encrypt these files
as they are copied to and from the router, see "Enabling Secure Copy Server"
on page 2-14.
Using the Local User List for Console or Telnet Access
You can configure the ProCurve Secure Router to use the usernames and
passwords you configure from the global configuration mode context to
control access to console terminal, SSH, or Telnet sessions. To use these
passwords for console terminal sessions, move to the console configuration
mode context and enter:
ProCurve(config-con0)# login local-userlist
By default, no login password is required for console terminal sessions.
To use these passwords for SSH or Telnet access, move to the appropriate line
configuration mode context and enter the following command:
ProCurve(config-ssh0–4)# login local-userlist
ProCurve(config-telnet0–4)# login local-userlist
Encrypting All the Passwords Configured on the Router
By default, the passwords that you enter in the local user list are not encrypted.
You can enter one command to encrypt these passwords and all the other
passwords configured on the ProCurve Secure Router, including the pass-
words configured for Telnet access, console access, and Point-to-Point Proto-
col (PPP) authentication. From the global configuration mode context, enter:
ProCurve(config)# service password-encryption
2-13
Need help?
Do you have a question about the ProCurve 7000dl Series and is the answer not in the manual?
Questions and answers