论文部分内容阅读
路由器及交换机是当前网络系统的主要设备,也是网络安全的前沿关口。如果路由器连自身的安全都没有保障,整个网络也就毫无安全可言。路由和交换设备的传统管理方法中最方便的是通过Telnet方式来远程管理,由于该方法所传输的用户名及密码为明文传送,因此存在很大的安全隐患。由于现在的路由及交换设备均支持加密协议,因此使用SSH或KerberizedTelnet,或使用IPSec加密路由器所有的管理流,可以大大加强路由交换设备管理的安全性。文中详细介绍了如何在路由交换设备上配置SSH服务以实现安全的路由交换设备的管理,并给出了该方法相对传统管理方法的优点。
Routers and switches are the main equipment of the current network system, but also the frontiers of network security. If the router is not even their own security protection, the entire network there is no safety at all. Routing and switching equipment, the traditional management method is the most convenient way to remote management through Telnet, the method of transmission of user name and password for the plain text transmission, so there is a big security risk. Because current routing and switching devices support cryptographic protocols, using SSH or Kerberized Telnet, or using IPSec to encrypt all of the router’s management streams, can greatly enhance the security of routing-switching device management. This article details how to configure SSH service on the routing switch to realize the management of the secure routing switch and gives the advantages of this method over the traditional management methods.