Step

 

Command

Remarks

 

 

 

Optional.

 

 

 

By default, the HTTPS service is not associated

 

 

 

with any SSL server policy, and the device uses

 

 

 

a self-signed certificate for authentication.

3.

Associate the HTTPS

ip https ssl-server-policy

If you disable the HTTPS service, the system

 

service with an SSL server

automatically de-associates the HTTPS service

 

policy.

policy-name

from the SSL service policy. Before re-enabling

 

 

 

the HTTPS service, associate the HTTPS service

 

 

 

with an SSL server policy first.

 

 

 

If the HTTPS service has been enabled, any

 

 

 

changes to the SSL server policy associated

 

 

 

with it do not take effect.

 

 

 

 

 

 

 

By default, HTTPS is disabled.

 

 

 

Enabling the HTTPS service triggers an SSL

 

 

 

handshake negotiation process. During the

 

 

 

process, if the local certificate of the device

 

 

 

exists, the SSL negotiation succeeds, and the

 

 

 

HTTPS service can be started properly. If no

4.

Enable the HTTPS service.

ip https enable

local certificate exists, a certificate application

 

 

 

process will be triggered by the SSL

 

 

 

negotiation. Because the application process

 

 

 

takes much time, the SSL negotiation often fails

 

 

 

and the HTTPS service cannot be started

 

 

 

normally. In that case, execute the ip https

 

 

 

enable command multiple times to start the

 

 

 

HTTPS service.

 

 

 

 

 

 

 

Optional.

 

 

 

By default, the HTTPS service is not associated

 

 

 

with any certificate-based attribute access

 

 

 

control policy.

 

 

 

Associating the HTTPS service with a

 

 

 

certificate-based attribute access control policy

5.

Associate the HTTPS

 

enables the device to control the access rights

ip https certificate

of clients.

 

service with a certificate

 

access-control-policy

You must configure the client-verify enable

 

attribute-based access

 

control policy.

policy-name

command in the associated SSL server policy.

 

 

 

If not, no clients can log in to the device.

 

 

 

The associated SSL server policy must contain

 

 

 

at least one permit rule. Otherwise, no clients

 

 

 

can log in to the device.

 

 

 

For more information about certificate

 

 

 

attribute-based access control policies, see

 

 

 

VPN Configuration Guide.

 

 

 

 

6.

Specify the HTTPS service

ip https port port-number

Optional.

 

port number.

The default HTTPS service port is 443.

 

 

 

 

 

 

 

 

 

55