Chapter15
SystemSecurity
Conguration
Systemsecuritycongurationcanpreventillegalnetwork-sidepacketsfromattacking
devices,thustoensurestablerunningofthedevices.
TheZXA10C300supportsthefollowingsystemsecurityfeatures:
lSecureShell(SSH)
lTerminalAccessControllerAccess-Control(TACACS+)
lRemoteAuthenticationDialInUserService(RADIUS)
lManagementACL
lControlpanelsafety
TableofContents
ConguringSSH.....................................................................................................
15-1
ConguringTACACS+..............................................................................................
15-3
ConguringRADIUS................................................................................................
15-4
ConguringManagementACL.................................................................................
15-5
ConguringControlPanelSafety..............................................................................15-6
15.1ConguringSSH
SSHcanreplaceT elnettoimplementsecureremotelogin.
Prerequisite
TheSSHclientsoftwarehasbeeninstalled.
Context
SSHcanencryptthedataduringtransmissiontopreventthe"intermediate"attacks.In
addition,SSHcompressesthedatatobetransmitted,thusincreasingthetransmission
speed.WhentheSSHclientcommunicateswiththeSSHserver,theusernameand
passwordareencrypted,thustopreventthepasswordfrombeingintercepted.
TheZXA10C300supportstheSSHserverfunction.
Steps
1.Inglobalcongurationmode,enableSSHserver.
ZXAN(config)#sshserverenable
15-1
SJ-20130520164529-007|2013-06-30(R1.0)ZTEProprietaryandCondential