DGS-3700-12/DGS-3700-12G Series Layer 2 Gigabit Ethernet Switch User Manual

the ciphersuites available, yet different ciphersuites will affect the security level and the performance of the secured connection. The information included in the ciphersuites is not included with the Switch and requires downloading from a third source in a file form called a certificate. This function of the Switch cannot be executed without the presence and implementation of the certificate file and can be downloaded to the Switch by utilizing a TFTP server. The Switch supports SSLv3 and TLSv1. Other versions of SSL may not be compatible with this Switch and may cause problems upon authentication and transfer of messages from client to host.

Download Certificate

This window is used to download a certificate file for the SSL function on the Switch from a TFTP server. The certificate file is a data record used for authenticating devices on the network. It contains information on the owner, keys for authentication and digital signatures. Both the server and the client must have consistent certificate files for optimal use of the SSL function. The Switch only supports certificate files with .der file extensions. The Switch is shipped with a certificate pre-loaded though the user may need to download more, depending on user circumstances.

Ciphersuite

This window will allow the user to enable SSL on the Switch and implement any one or combination of listed ciphersuites on the Switch. A ciphersuite is a security string that determines the exact cryptographic parameters, specific encryption algorithms and key sizes to be used for an authentication session. The Switch possesses four possible ciphersuites for the SSL function, which are all enabled by default. To utilize a particular ciphersuite, disable the unwanted ciphersuites, leaving the desired one for authentication.

When the SSL function has been enabled, the web will become disabled. To manage the Switch through the web based management while utilizing the SSL function, the web browser must support SSL encryption and the header of the URL must begin with https://. (Ex. https://10.90.90.90) Any other method will result in an error and no access can be authorized for the web-based management.

To view this window click, Security > SSL Settings as shown below:

Figure 5 - 30 SSL Settings

To set up the SSL function on the Switch, configure the following parameters and click Apply.

ParameterDescription

 

SSL Settings

 

 

SSL Status

Enable or Disable the SSL status on the switch. The default is disabled.

 

 

Cache Timeout

This field will set the time between a new key exchange between a client and a host using

(60-86400)

the SSL function. A new SSL session is established every time the client and host go

 

through a key exchange. Specifying a longer timeout will allow the SSL session to reuse the

 

master key on future connections with that particular host, therefore speeding up the

 

negotiation process. The default setting is 600 seconds.

 

 

 

166

Page 177
Image 177
D-Link DGS-3700 user manual Download Certificate, Ciphersuite