I had a chance to configure an HP ProCurve 4208vl switch the other day. The first impression was that the command line interface is heavily influenced by, if not directly copied from, the Cisco IOS command line interface. So if you have experience with IOS, you will probably feel almost at home on an HP switch. There are some differences, though.
The first thing I wanted to do was to enable ssh access and authentication, and disable telnet. Here’s a quick howto.
Connect to the switch using the console cable or telnet.
First thing to do is to enter the configuration mode and generate a key for ssh. Only after the key has been generated is it possible to enable ssh:
1 2 3 4 5 6 |
ProCurve Switch 4208vl# <strong>configure</strong> ProCurve Switch 4208vl(config)# <strong>crypto key generate ssh</strong> depleted, this could take up to a minute. ProCurve Switch 4208vl(config)# <strong>ip ssh</strong> ProCurve Switch 4208vl(config)# <strong>ip ssh filetransfer</strong> ProCurve Switch 4208vl(config)# <strong>end</strong> |
That is not enough, however. You must set the operator and manager passwords to actually authenticate to the switch.
1 2 3 4 5 6 7 8 |
ProCurve Switch 4208vl# <strong>configure</strong> ProCurve Switch 4208vl(config)# <strong>password manager</strong> New password for Manager: Please retype new password for Manager: ProCurve Switch 4208vl(config)# <strong>password operator</strong> New password for Operator: Please retype new password for Operator: ProCurve Switch 4208vl(config)# <strong>end</strong> |
After the above changes, the web interface will also require a password. For some reason, you must leave the username field empty and input either the manager or the operator password in the password field.
To disable the telnet server:
1 2 3 |
ProCurve Switch 4208vl# <strong>configure</strong> ProCurve Switch 4208vl(config)# <strong>no telnet-server</strong> ProCurve Switch 4208vl(config)# <strong>end</strong> |
To create a key and a self-signed certificate for SSL web access:
1 2 3 4 5 6 7 |
ProCurve Switch 4208vl(config)# <strong>crypto key generate cert 1024 </strong> Installing new RSA key. If the key/entropy cache is depleted, this could take up to a minute. ProCurve Switch 4208vl(config)# <strong>crypto host-cert generate self-signed 11/01/2007 11/01/2017 sw1.koo.fi _ Techelp Helsinki _ fi</strong> ProCurve Switch 4208vl(config)# <strong>web-management ssl</strong> ProCurve Switch 4208vl(config)# <strong>aaa authentication web login local </strong> ProCurve Switch 4208vl(config)# <strong>end</strong> |
Write your configuration changes:
1 |
ProCurve Switch 4208vl# <strong>write memory</strong> |