Chapter 10 Configuring system settings 485

Enabling TunnelGuard SRS administration using the CLI

To create and modify the TunnelGuard Software Requirement Set (SRS) rules, you must use the SREM (see “TunnelGuard SRS Builder” on page 317). Before you can access the Rule Builder utility in the SREM, you must enable support for SRS administration.

To configure support for managing the SRS rules, use the following command:

/cfg/sys/adm/srsadmin

The SRS Admin menu displays.

The SRS Admin menu includes the following options:

/cfg/sys/adm/srsadmin followed by:

port <port>

Specifies the TCP port used for communication with

 

the SRS administration server. The default is

 

port 4443.

 

 

ena

Enables SRS administration, for creating and

 

managing SRS rules.

 

 

dis

Disables SRS administration. The default is disabled.

 

 

Configuring Nortel SNAS 4050 host SSH keys using the CLI

The Nortel SNAS 4050 functions as both SSH client (for importing and exporting logs using SFTP) and SSH server for secure management communications between the Nortel SNAS 4050 devices in a cluster.

Note: SCP is not supported.

The SSH host keys are a set of keys to be used by all hosts in the cluster in accordance with the Single System Image (SSI) concept. As a result, connections to the MIP always appear to an SSH client to be to the same host.

Nortel Secure Network Access Switch 4050 User Guide

Page 485
Image 485
Nortel Networks 4050 manual Enabling TunnelGuard SRS administration using the CLI, Cfg/sys/adm/srsadmin