798Chapter 17 Configuration example

Generate and activate the SSH key for communication with the network access devices:

>>Main# cfg/domain 1/sshkey/generate

Generating new SSH key, this operation takes a few seconds... done.

Apply to activate.

>> NSNAS SSH key# apply

Create a test SRS rule and specify it for the tunnelguard group:

>>Group 1# /cfg/domain 1/aaa/tg/quick

In the event that the TunnelGuard checks fails on a client, the session can be teardown, or left in restricted mode with limited access.

Which action do you want to use for TunnelGuard failure? (teardown/restricted) [restricted]:

Do you want to create a tunnelguard test user? (yes/no) [yes]: no

Using existing tg_passed filter Using existing tg_failed filter Using existing tg_passed linkset Using existing tg_failed linkset Adding test SRS rule srs-rule-test

This rule check for the presence of the file C:\tunnelguard\tg.txt

Using existing tg_passed filter

Use 'diff' to view pending changes, and 'apply' to commit

>>TG#../group 1/tgsrs srs-rule-test

>>Group 1# apply

Adding the network access devices

This example adds the Ethernet Routing Switch 8300 manually, and uses the quick switch wizard to add the Ethernet Routing Switch 5510. In both cases, the example assumes that the switch is not reachable when it is added, and the switch public SSH key is therefore not automatically retrieved by the Nortel SNAS 4050.

320818-A

Page 798
Image 798
Nortel Networks 4050 manual Adding the network access devices, Main# cfg/domain 1/sshkey/generate, Group 1# apply