Download Chapter 4 - Mangd Switch Software Setup
Transcript
Chapter 4 - Managed Switch Software Setup IKE Certificates This screen allows you to configure IKE certificates used to identify the switch and IKE peers with which it communicates over IPv6. Warning: Misconfiguration on this screen may block network access to the Switch’s configuration interface. Providing a reliable time source, such as NTP, is highly recommended, as IKE will reject certificates which are not valid according to the system time, whether it is before the 'not valid before' time or after the expiration time. If NTP is used, pre-shared keys or hard-wired Security Associations should be used for IPsec communications with the NTP server or updating the clock will fail. The HTTPS certificate used by the switch's Web interface cannot be changed on this screen. Switch Certificate: This section may be used to generate or view the details of an X.509 certificate which the switch uses to identify itself via IKE. A certificate request which can be provided to a third-party Certificate Authority (CA) is also generated. A CA-signed certificate can be uploaded using the form at the bottom of the page and will replace the self-signed certificate used by the switch for IKE. Note that the certificate provided should be generated from the certificate request generated by the switch. 4–60 Stride Industrial Ethernet Switches User Manual 2nd Ed. Rev. A