EasyManuals Logo

HP ProCurve 3500yl Series User Manual

HP ProCurve 3500yl Series
390 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #202 background imageLoading...
Page #202 background image
Configuring Secure Shell (SSH)
Further Information on SSH Client Public-Key Authentication
Further Information on SSH Client
Public-Key Authentication
The section titled “5. Configuring the Switch for SSH Authentication” on page
7-18 lists the steps for configuring SSH authentication on the switch. However,
if you are new to SSH or need more details on client public-key authentication,
this section may be helpful.
When configured for SSH operation, the switch automatically attempts to use
its own host public-key to authenticate itself to SSH clients. To provide the
optional, opposite service—client public-key authentication to the switch—
you can configure the switch to store up to ten RSA or DSA public keys for
authenticating clients. This requires storing an ASCII version of each client’s
public key (without babble conversion, or fingerprint conversion) in a client
public-key file that you create and TFTP-copy to the switch. In this case, only
clients that have a private key corresponding to one of the stored public keys
can gain access to the switch using SSH. That is, if you use this feature, only
the clients whose public keys are in the client public-key file you store on
the switch will have SSH access to the switch over the network. If you do not
allow secondary SSH login (Operator) access via local password, then the
switch will refuse other SSH clients.
SSH clients that support client public-key authentication normally provide a
utility to generate a key pair. The private key is usually stored in a password-
protected file on the local host; the public key is stored in another file and is
not protected.
(Note that even without using client public-key authentication, you can still
require authentication from whoever attempts to access the switch from an
SSH client— by employing the local username/password, TACACS+, or
RADIUS features. Refer to
“5. Configuring the Switch for SSH Authentication”
on page 7-18.)
If you enable client public-key authentication, the following events occur
when a client tries to access the switch using SSH:
1. The client sends its public key to the switch with a request for authenti-
cation.
2. The switch compares the client’s public key to those stored in the switch’s
client-public-key file. (As a prerequisite, you must use the switch’s copy
tftp command to download this file to flash.)
7-22

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HP ProCurve 3500yl Series and is the answer not in the manual?

HP ProCurve 3500yl Series Specifications

General IconGeneral
ModelHP ProCurve 3500yl Series
Switching Capacity176 Gbps
LayerLayer 3
Input Voltage100-240 VAC
PoEAvailable on some models
ManagementWeb, CLI, SNMP
Routing ProtocolRIP, OSPF, BGP
Remote Management ProtocolTelnet
FeaturesVLAN
Power Consumption OperationalVaries by model
Memory256 MB
Power SupplyInternal
Security Features802.1X, RADIUS, TACACS+
Ports24 or 48 x 10/100/1000Base-T ports

Related product manuals