Cisco Systems OL-5742-01 manual Sgm webport Sgm xtermpath, 18-26

Page 26

Chapter 18 Configuring SGM Security

Implementing SSL Support in SGM

sgm webport

sgm xtermpath

If sgm authtype is set to solaris, you must still be logged in as the root user to enter the following commands:

sgm adduser

sgm disableuser

sgm enableuser

sgm updateuser

If the SNMP trap port number on the SGM server is less than 1024, you cannot use the sgm superuser command. To correct this situation, you must specify a new SNMP trap port number that is greater than 1024:

To change the SNMP trap port number in the ITPs in your network, use the snmp-server host command. By default, SGM listens for traps from trap multiplexing devices and NMS applications on port 44750, so that is a good port number to choose. The SNMP trap port number must be the same on all ITPs in your network.

See the description of the snmp-server host command in the “ITP Requirements” section of the Cisco Signaling Gateway Manager Installation Guide for more information.

Use the sgm trapsetup command to change the SNMP trap port number in the SGM server to match the port number in the ITPs in your network. See the “sgm trapsetup” section on page C-122for more information.

Implementing SSL Support in SGM

You can implement Secure Sockets Layer (SSL) support in your SGM system. When you do so, SGM uses secure sockets to encrypt all communication between the SGM clients and server.

This section includes the following information:

Enabling SSL Support in SGM, page 18-27

Downloading the SGM Server’s Self-Signed SSL Certificate, page 18-30

Launching the SGM Certificate Tool for SSL, page 18-31

 

Cisco Signaling Gateway Manager User Guide

18-26

OL-5742-01

Image 26
Contents Configuring SGM Security 18-118-2 Implementing SGM User-Based Access Solaris Only# cd /opt/CSCOsgm/bin # ./sgm useraccess enable # ./sgm authtype local Sgm disablepass Sgm passwordage Sgm userpassSgm adduser Sgm disableuser Sgm enableuser Sgm updateuser 18-318-4 # ./sgm authtype solaris# ./sgm sgm adduser username Creating Secure Passwords 18-5DICTFILE=/dev/null 18-6Basic User Level 1 Access 18-7Power User Level 2 Access 18-8Network Administrator Level 4 Access 18-9Automatically Disabling Users and Passwords Solaris Only 18-1018-11 # ./sgm inactiveuserdays clear # ./sgm passwordage number-of-days# ./sgm inactiveuserdays number-of-days 18-12# ./sgm clitimeout clear # ./sgm passwordage clear# ./sgm clitimeout number-of-minutes 18-13# ./sgm deluser username Manually Disabling Users and Passwords Solaris Only# ./sgm disablepass username 18-14# ./sgm disableuser username 18-1518-16 # ./sgm enableuser username# ./sgm userpass username # ./sgm updateuser username 18-1718-18 Displaying a Message of the Day# ./sgm newlevel username 18-19 # ./sgm motd edit # cd /opt/CSCOsgm/bin # ./sgm motd enableDecline 18-2018-21 Manually Synchronizing Local SGM PasswordsListing All Currently Defined Users Displaying the Contents of the System Security Log # ./sgm seclog clear # cd /opt/CSCOsgm/bin # ./sgm restore securityRestoring Security-Related SGM Data 18-2318-24 Disabling SGM User-Bases AccessSpecifying a Super User Solaris Only 18-25 Sgm webport Sgm xtermpath 18-26Enabling SSL Support in SGM 18-27# ./sgm keytool importcert certfilename 18-28# ./sgm keytool importkey keyfilename certfilename 18-29Right-clickDownload SGM Server SSL Certificate 18-3018-31 Launching the SGM Certificate Tool for SSL# cd /opt/CSCOsgm/bin # ./sgm certgui 18-32 Exit Importing an SSL Certificate to an SGM ClientDetails HelpExporting an SSL Certificate 18-34Save 18-35Viewing Detailed Information About an SSL Certificate 18-3618-37 Certificate Information Dialog18-38 18-39 Managing SSL Support in SGMDisabling SSL Support in SGM Limiting SGM Client Access to the SGM Server Solaris Only 18-4018-41 # ./sgm ipaccess add# ./sgm ipaccess edit 18-42
Related manuals
Manual 136 pages 55.23 Kb

OL-5742-01 specifications

Cisco Systems OL-5742-01 represents an essential advancement in the field of network infrastructure, tailored for organizations that demand robust, reliable, and scalable solutions. As part of Cisco's offerings, this device stands out for its comprehensive features and the technologies embedded within its design.

One of the main features of the OL-5742-01 is its support for advanced routing protocols. The device is engineered to handle both static and dynamic routing, making it versatile for different networking environments. This flexibility allows organizations to efficiently manage data traffic, ensuring optimal performance and minimal downtime. In addition, its built-in redundancy mechanisms ensure that network operations remain uninterrupted, offering peace of mind for mission-critical applications.

The OL-5742-01 is also designed with a focus on security. It incorporates a variety of security features, including advanced encryption protocols, firewall capabilities, and intrusion detection systems. This multilayered approach helps safeguard sensitive data from a myriad of cyber threats, which is particularly crucial in today's digital landscape where data breaches and cyberattacks are prevalent.

Furthermore, the device supports a range of connectivity options, making it suitable for various deployment scenarios. With multiple Ethernet ports and options for fiber connections, it adapts to the specific requirements of an organization's infrastructure. Its ability to support both wired and wireless connections enhances flexibility, allowing for seamless integration into existing networks.

Another noteworthy characteristic of the OL-5742-01 is its scalability. Organizations can easily upgrade their network infrastructure by adding additional units or expanding current capacity without overhauling their entire system. This feature is invaluable for businesses anticipating growth, as it aligns with their evolving needs.

The management of the OL-5742-01 is streamlined through its user-friendly interface, which allows network administrators to monitor and manage the device efficiently. Advanced diagnostic tools assist in troubleshooting, enabling rapid identification and resolution of issues, thus reducing potential network downtime.

In conclusion, Cisco Systems OL-5742-01 is a powerful networking device that encapsulates security, scalability, and advanced routing capabilities. Its features and technologies cater effectively to the demands of contemporary organizations, making it a reliable choice for building and maintaining resilient network infrastructures.