Enabling Ssh On The Switch And Anticipating Ssh Client Contact Behavior - HP procurve switch 2650 Access Security Manual

Hide thumbs Also See for procurve switch 2650:
Table of Contents

Advertisement

Configuring Secure Shell (SSH)
Configuring the Switch for SSH Operation
4. Enabling SSH on the Switch and Anticipating SSH
Client Contact Behavior
T
he ip ssh command enables or disables SSH on the switch and modifies
parameters the switch uses for transactions with clients. After you enable
SSH, the switch can authenticate itself to SSH clients.
N o t e
Before enabling SSH on the switch you must generate the switch's public/
private key pair. If you have not already done so, refer to "2. Generating the
Switch's Public and Private Key Pair" on page 4-10.
When configured for SSH, the switch uses its host public-key to authenticate
itself to SSH clients. If you also want SSH clients to authenticate themselves
to the switch you must configure SSH on the switch for client public-key
authentication at the login (Operator) level. To enhance security, you should
also configure local, TACACS+, or RADIUS authentication at the enable
(Manager) level.
Refer to "5. Configuring the Switch for SSH Authentication" on page 4-18.
SSH Client Contact Behavior. At the first contact between the switch and
an SSH client, if you have not copied the switch's public key into the client,
your client's first connection to the switch will question the connection and,
for security reasons, give you the option of accepting or refusing. As long as
you are confident that an unauthorized device is not using the switch's IP
address in an attempt to gain access to your data or network, you can accept
the connection. (As a more secure alternative, you can directly connect the
client to the switch's serial port and copy the switch's public key into the client.
See the following Note.)
4-15

Advertisement

Table of Contents
loading

This manual is also suitable for:

Procurve 6108

Table of Contents