© Copyright Lenovo 2017 Chapter 4: Securing Administration 89
Secure Shell and Secure Copy
BecauseusingTelnetdoesnotprovideasecureconnectionformanaginga
CN4093,SecureShell(SSH)andSecureCopy(SCP)featureshavebeenincluded
forCN4093management.SSHandSCPusesecuretunnelstoencryptandsecure
messagesbetweenaremoteadministratorandtheswitch.
SSHisaprotocolthatenables
remoteadministratorstologsecurelyintothe
CN4093overanetworktoexecutemanagementcommands.
SCPistypicallyusedtocopyfilessecurelyfromonemachinetoanother.SCPuses
SSHforencryptionofdataonthenetwork.OnaCN4093,SCPisusedtodownload
anduploadtheswitchconfiguration
viasecurechannels.
AlthoughSSHandSCParedisabledbydefault,enablingandusingthesefeatures
providesthefollowingbenefits:
IdentifyingtheadministratorusingName/Password
Authenticationofremoteadministrators
Authorizationofremoteadministrators
Determiningthepermittedactionsandcustomizingserviceforindividual
administrators
Encryptionofmanagementmessages
Encryptingmessagesbetweentheremoteadministratorandswitch
Securecopysupport
TheEnterpriseNOSimplementationofSSHsupportsbothversions1.5and2.0and
supportsSSHclientsversion1.5‐2.x.ThefollowingSSHclientshavebeentested:
SSH1.2.23andSSH1.2.27forLinux(freeware)
SecureCRT3.0.2andSecureCRT3.0.3forWindowsNT(VanDykeTechnologies,
Inc.)
F‐SecureSSH1.1forWindows(DataFellows)
PuttySSH
CygwinOpenSSH
MacXOpenSSH
Solaris8OpenSSH
AxeSSHSSHPro
SSHCommunicationsVandykeSSHA
F‐Secure