Security Overview
Switch Access Security
1-4
nity for access and possible malicious actions. Since security incidents can
originate with sources inside as well as outside of an organization, your access
security provisions must protect against internal and external threats while
preserving the necessary network access for authorized clients and users.
Default Configuration Settings and Access Security
In its default configuration, the switch is open to unauthorized access of
various types. In addition to applying local passwords, ProCurve recommends
that you consider using the switch's other security features to provide a more
complete security fabric.
Switch management access is available through the following methods:
Inbound Telnet access and Web-browser access
■
■
SNMP access
■
Front-Panel access (serial port access to the console, plus resets and
clearing the password(s) or current configuration)
It is important to evaluate the level of management access vulnerability
existing in your network and take steps to ensure that all reasonable security
precautions are in place. This includes both configurable security options and
physical access to the switch hardware.
Local Manager Password
In the default configuration, there is no password protection. Configuring a
local Manager password is a fundamental step in reducing the possibility of
unauthorized access through the switch's Web browser and console (CLI and
Menu) interfaces. The Manager password can easily be set using the CLI
password manager command, the Menu interface Console Passwords option, or
the password options under the Security tab in the Web browser interface.
Inbound Telnet Access and Web Browser Access
The default remote management protocols enabled on the switch are plain
text protocols, which transfer passwords in open or plain text that is easily
captured. To reduce the chances of unauthorized users capturing your pass
words, secure and encrypted protocols such as SSH and SSL must be used for
remote access. This enables you to employ increased access security while
still retaining remote client access.
SSHv2 provides Telnet-like connections through encrypted and authenti
■
cated transactions.
Need help?
Do you have a question about the 2900 and is the answer not in the manual?