178Chapter 4 Configuring the domain

Table 25 Server SSL Settings fields (continued)

Field

Description

 

 

CA Chain List

Specifies the CA certificate chain of the server certificate.

 

Select certificates from the list to create the chain. The

 

chain starts with the issuing CA certificate of the server

 

certificate and can range up to the root CA certificate.

 

Note: The SSL server can use chain certificates only if the

 

protocol version is set to ssl3 or ssl23.

 

 

CA Certificate List

Specifies which of the available CA certificates to use for

 

client authentication.

 

Not supported in Nortel Secure Network Access Switch

 

Software Release 1.0.

 

 

3Click Apply on the toolbar to send the current changes to the Nortel

SNAS 4050. Click Commit on the toolbar to save the changes permanently.

Configuring traffic log settings using the SREM

You can configure a syslog server to receive User Datagram Protocol (UDP) syslog messages for all HTTP requests handled by the portal server.

Nortel does not recommend routinely enabling this functionality for the following reasons:

Logging traffic with syslog messages generates a substantial amount of network traffic.

Logging traffic places an additional CPU load on each Nortel SNAS 4050 device in the cluster.

In general, syslog servers are not intended for the traffic type of log message. Therefore, the syslog server might not be able to cope with the quantity of syslog messages generated within a cluster of Nortel SNAS 4050 devices.

Enable traffic logging with syslog messages in environments where laws or regulations require traffic logging to be performed on the SSL terminating device itself. You can also enable it temporarily for debugging purposes.

Because of the amount of traffic generated, Nortel recommends that you set up syslog on the backend server if possible.

320818-A

Page 178
Image 178
Nortel Networks 4050 Configuring traffic log settings using the Srem, Configuring the domain Server SSL Settings fields