13.07.2015 Views

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Accessing <strong>the</strong> <strong>Avaya</strong> <strong>G350</strong> <strong>Media</strong> <strong>Gateway</strong>When you create a new user, you must define <strong>the</strong> user’s password and privilege level. Thefollowing example creates a user named John with <strong>the</strong> password johnny and a Read-writeprivilege level:<strong>G350</strong>-001> username john password johnny access-type read-writeSSH protocol supportSSH (Secure Shell) protocol is a security protocol that enables you to establish a remotesession over a secured tunnel, also called a remote shell. SSH accomplishes this by creating atransparent, encrypted channel between <strong>the</strong> local and remote devices. In addition to <strong>the</strong> remoteshell, SSH provides secure file transfer between <strong>the</strong> local and remote devices. SSH is used fortelnet file transfers. The <strong>G350</strong> supports two concurrent SSH users.There are two ways to establish an SSH session:● RSA au<strong>the</strong>ntication● Password au<strong>the</strong>nticationUse <strong>the</strong> ssh enable command to determine which <strong>of</strong> <strong>the</strong>se ways is used on <strong>the</strong> <strong>G350</strong>. SeeSSH Configuration on page 39.RSA au<strong>the</strong>ntication works as follows:● The <strong>G350</strong> generates a key <strong>of</strong> variable length (512-2048 bits) using <strong>the</strong> DSA encryptionmethod. This is <strong>the</strong> private key.●●●●●The <strong>G350</strong> calculates an MD5 Hash <strong>of</strong> <strong>the</strong> private key, called a fingerprint (<strong>the</strong> public key).The fingerprint is always 16 bytes long. This fingerprint is displayed.The <strong>G350</strong> sends <strong>the</strong> public key (<strong>the</strong> fingerprint) to <strong>the</strong> client computer. This public key isused by <strong>the</strong> client to encrypt <strong>the</strong> data it sends to <strong>the</strong> <strong>G350</strong>. The <strong>G350</strong> decrypts <strong>the</strong> datausing <strong>the</strong> private key.Both sides negotiate and must agree on <strong>the</strong> same chipper type. The <strong>G350</strong> only supports3DES-CBC encryption. The user on <strong>the</strong> client side accepts <strong>the</strong> fingerprint. The clientmaintains a cache containing a list <strong>of</strong> fingerprints per server IP address. If <strong>the</strong> informationin this cache changes, <strong>the</strong> client notifies <strong>the</strong> user.The client chooses a random number that is used to encrypt and decrypt <strong>the</strong> informationsent.This random number is sent to <strong>the</strong> <strong>G350</strong>, after encryption based on <strong>the</strong> <strong>G350</strong>’s public key.● When <strong>the</strong> <strong>G350</strong> receives <strong>the</strong> encrypted random number, it decrypts it using <strong>the</strong> privatekey. This random number is now used with <strong>the</strong> 3DES-CBC encryption method for allencryption and decryption <strong>of</strong> data. The public and private keys are no longer used.Password au<strong>the</strong>ntication works as follows:●Before any data is transferred, <strong>the</strong> <strong>G350</strong> requires <strong>the</strong> client to supply a user name andpassword. This au<strong>the</strong>nticates <strong>the</strong> user on <strong>the</strong> client side to <strong>the</strong> <strong>G350</strong>.38 <strong>Administration</strong> <strong>of</strong> <strong>the</strong> <strong>Avaya</strong> <strong>G350</strong> <strong>Media</strong> <strong>Gateway</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!