30.06.2015 Views

8.28 MB - Edge-Core

8.28 MB - Edge-Core

8.28 MB - Edge-Core

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

User Authentication<br />

3<br />

Web – Click Security, HTTPS Settings. Enable HTTPS and specify the port number,<br />

then click Apply.<br />

Figure 3-25 HTTPS Settings<br />

CLI – This example enables the HTTP secure server and modifies the port number.<br />

Console(config)#ip http secure-server 4-30<br />

Console(config)#ip http secure-port 443 4-31<br />

Console(config)#<br />

Replacing the Default Secure-site Certificate<br />

When you log onto the web interface using HTTPS (for secure access), a Secure<br />

Sockets Layer (SSL) certificate appears for the switch. By default, the certificate that<br />

Netscape and Internet Explorer display will be associated with a warning that the<br />

site is not recognized as a secure site. This is because the certificate has not been<br />

signed by an approved certification authority. If you want this warning to be replaced<br />

by a message confirming that the connection to the switch is secure, you must<br />

obtain a unique certificate and a private key and password from a recognized<br />

certification authority.<br />

Caution: For maximum security, we recommend you obtain a unique Secure Sockets<br />

Layer certificate at the earliest opportunity. This is because the default<br />

certificate for the switch is not unique to the hardware you have purchased.<br />

When you have obtained these, place them on your TFTP server, and use the<br />

following command at the switch's command-line interface to replace the default<br />

(unrecognized) certificate with an authorized one:<br />

Console#copy tftp https-certificate 4-63<br />

TFTP server ip address: <br />

Source certificate file name: <br />

Source private file name: <br />

Private password: <br />

Note: The switch must be reset for the new certificate to be activated. To reset the<br />

switch, type: Console#reload<br />

3-39

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!