EasyManuals Logo

HP ProCurve 5412ZL Access Security Guide

HP ProCurve 5412ZL
390 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #200 background imageLoading...
Page #200 background image
Configuring Secure Shell (SSH)
Configuring the Switch for SSH Operation
Caution To allow SSH access only to clients having the correct public key, you must
configure the secondary (password) method for login public-key to none.
Otherwise a client without the correct public key can still gain entry by
submitting a correct local login password.
Syntax: aaa authentication ssh enable < local | tacacs | radius > < local | none >
Configures a password method for the primary and second-
ary enable (Manager) access. If you do not specify an
optional secondary method, it defaults to none.
For example, assume that you have a client public-key file named Client-
Keys.pub (on a TFTP server at 10.33.18.117) ready for downloading to the
switch. For SSH access to the switch you want to allow only clients having a
private key that matches a public key found in Client-Keys.pub. For Manager-
level (enable) access for successful SSH clients you want to use TACACS+ for
primary password authentication and local for secondary password authenti-
cation, with a Manager username of "1eader" and a password of "m0ns00n".
To set up this operation you would configure the switch in a manner similar
to the following:
ProCurve(config)# password manager user-name leader
New password for Manager: ********
Please retype new password for Manager: ********
ProCurve(config)# aaa authentication ssh login public-key none
ProCurve(config)# aaa authentication ssh enable tacacs local
ProCurve(config)# coy tftp pub-key-file 10.33.18.117
ProCurve(config)# write memory
Configures Manager user-
name and password.
Configures the
switch to allow
SSH access only
for a client whose
public key
matches one of the
keys in the public
key file.
Configures the primary and
secondary password methods for
Manager (enable) access. (Becomes
available after SSH access is granted
Copies a public key file
named "Client-Keys.pub"
into the switch.
Figure 7-11. Configuring for SSH Access Requiring a Client Public-Key Match and Manager Passwords
7-20

Table of Contents

Other manuals for HP ProCurve 5412ZL

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HP ProCurve 5412ZL and is the answer not in the manual?

HP ProCurve 5412ZL Specifications

General IconGeneral
Input Voltage100-240 VAC
Jumbo Frame SupportYes
LayerLayer 3
Port Type10/100/1000Base-T, SFP
ManagementCLI, Web, SNMP

Related product manuals