DGS-3700-12/DGS-3700-12G Series Layer 2 Gigabit Ethernet Switch User Manual
166
the ciphersuites available, yet different ciphersuites will affect the security level and th e performance of the secured
connection. The information included in the ciphersuites is not incl uded with the Switch and requires downloading from
a third source in a file form called a certificate. This function of the Switch cannot be executed without the presence
and implementation of the certificate file and can be downloaded t o the S witch by util izing a T FTP server. T he S witch
supports SSLv3 and TLSv1. Other versions of SSL may not be com patible with t his Switch a nd may caus e problem s
upon authentication and transfer of messages from client to host.
Download Certificate
This window is used to download a certificate file for the SSL function on the Switch from a TFTP s erver. The
certificate file is a data record used for authenticating devices on the network. It contains infor mation on the owner,
keys for authentication and digital signatures. Both the server a nd the client m ust have consistent certificate files for
optimal use of the SSL function. The Switch only supports certificate files with .der file extensions. The Switch is
shipped with a certificate pre-loaded though the user may need to download more, dep ending on user circumstances.
Ciphersuite
This window will allow the user to enable SSL on the S witch and implement any one or combination of listed
ciphersuites on the Switch. A ciphersuite is a security string that determ ines the exact cryptographic parameters,
specific encryption algorithms and key sizes to be used for an authentication session. T he Switch possesses four
possible ciphersuites for the SSL function, which are all enabled by def ault. To utili ze a particular ci phersuite, d isable
the unwanted ciphersuites, leaving the desired one for authentication.
When the SSL function has been enabled, the web will become disabled. To manage the Switch through the web
based management while utilizing the SSL function, the web browser m ust suppor t SSL encr yption and the header of
the URL must begin with https://. (Ex. https://10.90.90.90) Any other m ethod will res ult in an error an d no acc ess can
be authorized for the web-based management.
To view this window click, Security > SSL Settings as shown below:
Figure 5 - 30 SSL Settings
To set up the SSL function on the Switch, configure the following param eters and click Apply.
Parameter Description
SSL Settings
SSL Status Enable or Disable the SSL status on the switch. The default is disabled.
Cache Timeout
(60-86400) This field will set the time between a new key exchange between a client and a host us ing
the SSL function. A new SSL session is established every time the client an d host go
through a key exchange. Specifying a longer timeout will allow the SSL sessio n to reus e the
master key on future connections with that particular host, therefore speeding up the
negotiation process. The default setting is 600 seconds.