Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
298
Command reference
213455-L, October 2005
/cfg/sys/adm/web/ssl
SSL Configuration Menu
The SSL Configuration Menu is used to configure BBI access using HTTPS. HTTPS uses
Secure Socket Layer (SSL) to provide server host authentication, encryption of management
messages, and encryption of passwords for user authentication. Using SSL with the Browser-
Based Interface is highly recommended for security reasons. By default, SSL is disabled.
In addition to enabling/disabling the HTTPS feature, this menu allows you to set the HTTPS
port, set SSL version, and access menus for generating SSL certificates.
For more information, see the
NSF 2.3.3 Browser-Based Interface User’s Guide
(216383-D)
.
[SSL Configuration Menu]
port - Set SSL port number
ena - Enable SSL
dis - Disable SSL
tls - Set TLS
sslv2 - Set SSL version 2
sslv3 - Set SSL version 3
certs - Certificate Management Menu
Table 32
SSL Configuration Menu (/cfg/sys/adm/web/ssl)
Command Syntax and Usage
port
<HTTPS port number>
This command sets the logical HTTPS port which is used by the built-in BBI web server.
By default, the web server uses well-known HTTPS port 443. This can be changed to use
any port number, but should not be set to any port which is being used by other services.
ena
This command enables HTTPS access to the BBI. When enabled, HTTPS access to the
host IP address is allowed for trusted clients which have been added to the access list
(see
Defining the remote access list on page 252
).
N
OTE
–
An SSL certificate must be generated using the Certificate Management Menu
(
certs
) before HTTPS will function.
dis
This command disables HTTPS access to the BBI. This is the default. When disabled,
HTTPS requests to the host IP address will be dropped.
tls y
|
n
This command enables or disables Transport Level Security (TLS) for SSL.