EasyManuals Logo

HP ProCurve Switch 2650 User Manual

HP ProCurve Switch 2650
184 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #101 background imageLoading...
Page #101 background image
4-19
Configuring Secure Shell (SSH)
Configuring the Switch for SSH Operation
3. Copy the public-key file into a TFTP server accessible to the switch and
download the file to the switch.
(For more on these topics, refer to MoreInformation on SSH Client Public-
Key Authentication on page 4-21.)
With steps 1 - 3, above, completed and SSH properly configured on the switch,
if an SSH client contacts the switch, login authentication automatically occurs
first, using the switch and client public-keys. After the client gains login
access, the switch controls client access to the manager level by requring the
passwords configured earlier by the aaa authentication ssh enable command.
Caution To allow SSH access only to clients having the correct public key, you must
configure the secondary (password) method for login rsa to none. Otherwise
a client without the correct public key can still gain entry by submitting a
correct local login password.
For example, assume that you have a client public-key file named Client-
Keys.pub (on a TFTP server at 10.33.18.117) ready for downloading to the
switch. For SSH access to the switch you want to allow only clients having a
private key that matches a public key found in Client-Keys.pub. For Manager-
level (enable) access for successful SSH clients you want to use TACACS+ for
primary password authentication and local for secondary password authenti-
cation, with a Manager username of "1eader" and a password of "m0ns00n".
To set up this operation you would configure the switch in a manner similar
to the following:
Syntax: copy tftp pub-key-file < ip-address > < filename > < local | none >
Copies a public key file into the switch.
aaa authentication ssh login rsa
Configures the switch to authenticate a client public-
key at the login level with an optional secondary pass-
word method (default: none).
Syntax: aaa authentication ssh enable < local | tacacs | radius > < local | none >
Configures a password method for the primary and
secondary enable (Mana ger) access. If you do not
specify an optional secondary method, it defaults to
none.
!FishSecurity.book Page 19 Thursday, October 10, 2002 9:19 PM

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HP ProCurve Switch 2650 and is the answer not in the manual?

HP ProCurve Switch 2650 Specifications

General IconGeneral
Switching Capacity13.6 Gbps
Forwarding Rate10.1 Mpps
LayerLayer 2
Form FactorRack-mountable
Flash Memory8 MB
Jumbo Frame SupportYes
Power SupplyInternal
ManagementWeb, CLI, SNMP
FeaturesVLAN support, IGMP snooping, QoS
Operating Temperature0°C to 45°C (32°F to 113°F)
Operating Humidity15% to 95% (non-condensing)
Ports48 x 10/100
MAC Address Table Size8, 000 entries

Related product manuals