Enabling Device Access Methods

By default, management access is disabled and must be specifically enabled.
Each of the following management access methods must be specifically enabled.
  • SSHv2—To allow SSHv2 access to a RUCKUS ICX device, you must generate a Crypto Key. In addition, you must use AAA authentication to create a password to allow SSHv2 access.

  • SNMP access—You can enable SNMP management of the device.

  • Web management through HTTP or HTTPS—You can allow Web Management access through HTTP and HTTPS. For HTTPS access you must also generate a crypto SSL certificate or import digital certificates issued by a third-party Certificate Authority (CA).

Each of the following steps is optional and in no specific order.

  1. Enter global configuration mode.
    device# configure terminal
  2. Enable SSHv2 access.
    device(config)# crypto key generate
    device(config)# aaa authentication login default tacacs+ local
    This example generates a DSA key pair and configures AAA authentication to use TACACS+ for authentication as the default or local authentication if TACACS+ is not available.
  3. Enable SNMP access.
    device(config)# snmp-server
  4. Enable web management access through both HTTP access and HTTPS access.
    device(config)# web-management
    To enable HTTPS access, you must generate a crypto SSL certificate or import a digital certificate issued by a third-party Certificate Authority (CA). See the following steps for examples and details.
  5. Enable web management access through HTTP only.
    device(config)# web-management http
  6. Enable web management access through HTTPS and generate a crypto SSL certificate.
    device(config)# web-management https
    device(config)# crypto-ssl certificate generate
    This example generates a crypto SSL certificate.
  7. Enable web management access through HTTPS, import a digital certificate issued by a third-party CA, and save it in the flash memory.
    Previous example used a command deprecated and replaced in 9.0 (Management 2.0). Here is how the prev. example read:
    device(config)# web-management https
    device(config)# ip ssl certificate-data-file tftp 10.10.10.1 cacert.pem
    device(config)# web-management https
    device(config)# copy tftp flash 10.10.10.1 cacert.pem certificate-data-file
    This example downloads the digital certificate file cacert.pem from the TFTP server with the IP address 10.10.10.1.