Chapter5ServiceConguration
UserscanaccesstheZXR105250byusingbrowsersandHTTPStoperformWeb-based
congurationandmanagement.
ConguringSSL
TheSSLcongurationincludesthefollowingcommands:
CommandFunction
zte(cfg)#setssl{enable|disable}EnablesordisablestheSSLfunction.
zte(cfg)#createca{<A.B.C.D/M>|<A.B.C.D><n
etworkmask>}
Managestheencryptioncerticate,andcreates
anRSAkey,alocalcerticateontheserverand
arootcerticateontheclient.
showssl(allcongurationmodes)DisplaystheSSLcongurationandstate.
SSLCongurationInstance
lCongurationDescription
SeeFigure5-54,alayer-3portisconguredontheswitch,andtheIPaddressisset
to192.168.100.110/24.TheIPaddressofthePCissetto192.168.100.109/24.The
switchoperatesastheSSLserver,andthebrowseronthePCoperatesastheSSL
client.
Figure5-54SSLCongurationInstance
lCongurationProcedure
Conguretheswitch:
zte(cfg)#createca192.168.100.110/24
caiscreating,pleasewait......
Rootcafile/flash/data/root.cer,hascreated!
Servercafile/flash/data/server.pem,hascreated!
Serverkeyfile/flash/data/server.key,hascreated!
FSisreleasing,pleasewait......
Done!
zte(cfg)#setsslen
Thecurrentcaisforipaddress192.168.100.110,
Pleasemakesureipoftheswitchmatches.
Thenupload/flash/data/root.cer,andimporttoexplore,thesslisavailible.
zte(cfg)#configtffs
zte(cfg-tffs)#cddata
5-149
SJ-20131111172707-002|2013-11-27(R1.0)ZTEProprietaryandCondential