Chapter5ServiceConguration
5.47SSLConguration
SSLOverview
TheSSLprotocolisanintermediateprotocol.Itislocatedbetweentheapplicationlayer
andtransportlayerinthenetworkmodel.Throughthedataencryption,identication
authentication,andmessageintegrityvalidationmechanisms,SSLensuressecurityfor
connectionsestablishedbasedonreliableapplicationlayerprotocols(forexample,TCP).
TheSSLfunctionalmoduleenablestheZXR102900EtooperateasanSSLserverand
completeinteractionwithaclient.TheinteractionprocedureincludesSSLhandshaking,
andpacketmonitoring,receiving,parsingandsending.TheSSLhandshakingprocedure
includesnegotiatinganencryptionalgorithm,verifyingthelocalcerticateontheserver,
exchangingkeys,andverifyingaMACaddress.Theencryptionalgorithm,localcerticate
ontheserver,keys,andMACaddressareusedfordataencryptionanddecryption,
identicationauthentication,andmessageintegrityvalidationinasubsequentsession.
EncryptioncerticatemanagementistheprerequisiteforSSLhandshaking.Certicate
managementincludeskeygenerationmanagement,localcerticategenerationonthe
server,androotcerticategenerationontheclient.
UserscanaccesstheZXR102900EbyusingbrowsersandHTTPStoperformWeb-based
congurationandmanagement.
ConguringSSL
TheSSLcongurationincludesthefollowingcommands:
CommandFunction
zte(cfg)#setssl{enable|disable}EnablesordisablestheSSLfunction.
zte(cfg)#createca{<A.B.C.D/M>|<A.B.C.D><n
etworkmask>}
Managestheencryptioncerticate,andcreates
anRSAkey,alocalcerticateontheserverand
arootcerticateontheclient.
showssl(allcongurationmodes)DisplaystheSSLcongurationandstate.
SSLCongurationInstance
lCongurationDescription
SeeFigure5-62,alayer-3portisconguredontheswitch,andtheIPaddressisset
to192.168.100.110/24.TheIPaddressofthePCissetto192.168.100.109/24.The
switchoperatesastheSSLserver,andthebrowseronthePCoperatesastheSSL
client.
5-167
SJ-20130731155059-002|2013-11-27(R1.0)ZTEProprietaryandCondential