SA-250 Server Installation Guide
49
11. Appendix A Sensor-Server Mutual Authentication
The sensor-server communication begins with a mutual authentication step in which the sensor and server
authenticate each other using a shared secret. Sensor-server communication takes place only if this
authentication succeeds.
After the authentication succeeds, a session key is generated. All communication between the sensor and server
from this point on is encrypted using the session key.
The sensor and server are shipped with the same default value of the shared secret. The CLI commands for
changing the shared secret are provided on both server and sensor. Alternatively, you can modify this shared
secret from Server GUI console as well.
Note
: When the server is backward compatible, that is, pre version 6.2 sensors can connect to a version 6.8
server. However, this is not recommended. After all sensors have been upgraded to version 6.8, the
set
sensor legacy authentication
CLI command can be used to disable older sensors from connecting to
the server.
Note
: After the shared secret (communication key) is changed on the server, all sensors connected to the server
will automatically be setup to use the new communication key. Sensors that are not connected to the server at
this time must be setup with the same communication key for them to be able to communicate with this server.