Sign In
Upload
Manuals
Brands
Cisco Manuals
Network Router
CSS11501S-C-K9
Cisco CSS11501S-C-K9 Manuals
Manuals and User Guides for Cisco CSS11501S-C-K9. We have
1
Cisco CSS11501S-C-K9 manual available for free PDF download: Configuration Manual
Cisco CSS11501S-C-K9 Configuration Manual (462 pages)
Secure Content Accelerator
Brand:
Cisco
| Category:
Network Router
| Size: 5.81 MB
Table of Contents
Table of Contents
5
About this Guide
31
How to Use this Guide
31
Obtaining Documentation
35
Ordering Documentation
35
Documentation Feedback
36
Obtaining Technical Assistance
37
Technical Assistance Center
37
Obtaining Additional Publications and Information
39
Chapter 1 Overview
42
Product Overview
42
Table 1-1 Secure Content Accelerator Model Differences
43
Site Requirements
45
Required Tools and Equipment
46
CHAPTER 2 Installing the Hardware and Software
46
Shipment Contents
46
Unpacking the Secure Content Accelerator
47
Installing the Hardware
47
Installing as a Free-Standing Unit
48
Installing as a Rack-Mounted Unit
49
Panel Descriptions
49
Figure 2-1 Secure Content Accelerator Front Panel
50
Figure 2-2 Secure Content Accelerator Rear Panel
50
Figure 2-3 SCA Ethernet Port Detail
51
Figure 2-4 SCA2 Ethernet Port Detail
51
Table 2-1 SCA Port LED Descriptions
51
Identifying SCA Models
52
Connecting to Power
52
Table 2-2 SCA2 Port LED Descriptions
52
Connecting to Ethernet
53
Using the Quickstart Wizard
55
Before You Begin
56
Initiating a Management Session
56
Serial Management and IP Address Assignment
56
Chapter 3 Using the Quickstart Wizard
56
Telnet
57
Initiating a Management Session
57
Telnet
58
Starting the Quickstart Wizard
58
Using the Quickstart Wizard
59
Using the Quickstart Wizard with a Configured Appliance
68
Using the Configuration Manager
69
Chapter 4 Using the Configuration Manager
70
Overview
70
Configuration Security
71
Passwords
71
Access Lists
71
Factory Default Reset Password
72
Before You Begin
72
Initiating a Management Session
73
Serial Management and IP Address Assignment
73
Telnet
74
Configuring the Device
74
Example: Setting up Basic Device Parameters
75
Example: Setting up a Secure Server
76
Example: Setting up a Backend Server
78
Example: Setting up a Reverse-Proxy Server
79
Example: Configuring Secure URL Rewrite
80
Example: Configuring SNTP Servers
82
Example: Restricting Access Using an Access List
83
Configuring an Ethernet Interface
84
Example: Saving a Configuration File
85
Step-Up Certificates and Server-Gated Cryptography
85
Configuring Certificate Groups
86
Example: Configuring a Certificate Group
86
Example: Importing Certificate Groups
88
Using Client and Server Certificate Authentication
89
Example: Configuring Server Certificate Authentication
89
Example: Configuring Client Certificate Authentication
91
Generating Keys and Certificates
92
Example: Generating an RSA Key
92
Example: Generating a Certificate
92
Supporting SNMP
93
Example: Configuring SNMP
93
Supporting RIP
94
Example: Configuring RIP
94
Supporting Other Secure Protocols
95
Example: Configuring a Secure Mail Server
95
Supporting FIPS
95
Working with Syslogs
96
Disabling SSL Versions
96
Enabling Keepalives
97
Setting the Idle-Timeout
99
Graphical User Interface Reference
101
Overview
102
C H a P T E R 5 Graphical User Interface Reference
102
Browser and System Support
102
Enabling Web Management
102
Figure
102
Restricting Access to Web Management
103
Starting the GUI
103
Configuring for Client-Side Access
104
Figure 5-1 Password Request Dialog Box
104
Administrative Time out
105
Web Management User Interface
105
Figure 5-2 Basic User Interface Example
106
General Configuration Examples
107
Example: Setting the Device Name (Hostname)
107
Example: Resetting the IP Address
108
Example: Configuring an Ethernet Interface
109
Figure
109
Example: Enabling RIP
110
Figure
110
Example: Adding a Route to the Routing Table
111
Figure
111
Figure 5-8 Adding a Route Example
112
Example: Working with Syslogs
113
Example: Restricting Access Using an Access List
114
Figure 5-11 Add Access List Entry Example
115
Example: Reloading (Rebooting) the Appliance
117
Figure 5-13 Device Reloading Example
117
Figure 5-14 Save Changes Button
117
Example: Setting an Enable Password
118
Figure 5-15 Change Password Example
118
Example: Configuring SNMP
119
Figure 5-17 SNMP Trap Example
120
Figure 5-18 Add SNMP Trap Host Example
121
SSL Configuration Examples
122
Example: Setting up a Secure Server
122
Figure 5-19 Private Keys Tab
122
Figure 5-20 Add Private Key Example
123
Figure 5-21 Importing a Private Key File Example
124
Figure
125
Figure
126
Figure
127
Figure 5-25 Security Policies Tab
128
Figure 5-26 Add Security Policy Example
129
Figure 5-27 Secure Servers Tab
130
Figure 5-28 Add Secure Server Information Example
131
Figure 5-30 SSL Session Cache Example
132
Figure 5-31 Add URL Rewrite Rule Example
133
Figure 5-32 Add Secure Server Information Example
133
Figure 5-33 Add HTTP Headers Example
134
Figure 5-34 Add Keepalives Example
134
Example: Creating and Using Certificate Groups
135
Figure
135
Figure
136
Example: Supporting Other Secure Protocols
137
Figure
137
Example: Generating an RSA Private Key
138
Figure
138
Figure 5-39 Generating a Private Key
139
Figure 5-40 Key Not Displayed Example
140
Figure 5-41 Key Displayed Example
141
Example: Generating a Self-Signed Certificate
142
Figure 5-42 Generate CSR Example
142
Figure
143
Figure
144
Figure
145
Example: Importing a PKCS#7 Certificate Group
146
Example: Importing a PKCS#12 Certificate Group
147
Running the Secure Server Wizard
148
Figure 5-48 Starting the Secure Server Wizard
148
FIPS Operation
149
Chapter 6 FIP Operation
150
FIPS Capabilities
150
Using FIPS Mode
150
Creating a Server in FIPS Mode
153
Command Changes
155
Unavailable Commands
155
Differing Command Behaviors
155
Table 6-1 Unavailable Commands
155
Table 6-2 FIPS Mode Command Changes
156
Returning to Normal Operation
157
More Information
158
Appendix
159
Specifications
159
Electrical Specifications
160
Environmental Specifications
160
Physical Specifications
161
Appendix A Specification
161
Appendix
163
Deployment Examples
163
Appendix B Deployment Example
164
Single Device
164
Load Balancing
164
Figure B-1 Single Secure Content Accelerator Installation
164
Figure B-2 Secure Content Accelerator Installation with a Load Balancer
165
Use with the CSS
166
In-Line
166
Figure B-3 Secure Content Accelerator In-Line Installation
167
Table B-1 In-Line Installation Device Configuration
168
One-Armed Non-Transparent Proxy
172
Figure B-4 Secure Content Accelerator One-Armed Non-Transparent Proxy Installation
173
One-Armed Transparent Proxy
181
Figure B-5 Secure Content Accelerator One-Armed Transparent Proxy Installation
182
Connecting the Device to a Terminal Server
192
Web Site Changes
192
Transparent Local-Listen
193
Appendix
195
Command Summary
195
Input Data Format Specification
196
Text Conventions
196
Table C-1 Input Data Formats
196
Appendix C Command Summary
197
Editing and Completion Features
197
Table C-2 Key Reference
197
Command Hierarchy
199
Figure C-1 Command Hierarchy
199
Configuration Security
200
Passwords
200
Access Lists
201
Factory Default Reset Password
201
Methods to Manage the Device
201
Initiating a Management Session
203
Serial Management and IP Address Assignment
203
Telnet
204
Command Listing
204
Table C-3 Non-Privileged Command Description
205
Table C-4 Privileged Command Description
209
Table C-5 Configuration Command Description
210
Table C-7 SSL Configuration Command Description
214
Table C-10 Certificate Group Configuration Command Description
217
Table C-9 Certificate Configuration Command Description
217
Table C-11 Key Configuration Command Description
218
Table C-12 Reverse-Proxy Server Configuration Command Description
219
Table C-13 Security Policy Configuration Command Description
220
Table C-14 Server Configuration Command Description
221
Table C-15 TCP Tuning Configuration Command Description
223
Top Level Command Set
225
Non-Privileged Command Set
225
Clear Screen
225
Cls
225
Enable
225
Exit
226
Help
226
Monitor
227
Paws
227
Ping
227
Quit
228
Set Monitor-Interval
228
Show Arp
229
Show Copyrights
229
Show Cpu
229
Show Date
230
Show Device
230
Show Dns
231
Show Flows
231
Show History
231
Show Interface
232
Show Interface Errors
232
Show Interface Statistics
233
Show Ip Domain-Name
234
Show Ip Name-Server
234
Show Ip Routes
235
Show Ip Statistics
235
Show Keepalive-Monitor
235
Show Log
236
Show Memory
236
Show Messages
236
Show Netstat
237
Show Password
237
Show Password Access
237
Show Password Enable
238
Show Password Idle-Timeout
238
Show Processes
238
Show Rdate-Server
239
Show Rip
239
Show Route
239
Show Sessions
240
Show Sntp
240
Show Sntp-Server
240
Show Ssl
241
Show Ssl Cert
241
Show Ssl Certgroup
242
Show Ssl Errors
243
Table C-16 Output Description for Show Ssl Errors
243
Table C-17 Abbreviations Used for Show Ssl Errors Continuous
247
Show Ssl Key
248
Show Ssl Secpolicy
248
Show Ssl Server
249
Show Ssl Session-Stats
250
Table C-18 Output Description for Show Ssl Session-Stats
251
Show Ssl Statistics
252
Table C-19 Output Description for Show Ssl Statistics
253
Show Ssl Tcp-Tuning
254
Show Syslog
255
Show System-Resources
255
Show Telnet
256
Show Terminal
256
Show Timezone
256
Show Version
257
Show Web-Management
257
Terminal Baud
257
Terminal History
258
Terminal Length
259
Terminal Pager
259
Terminal Reset
260
Terminal Width
260
Traceroute
261
Privileged Command Set
262
Clear Interface Statistics
262
Clear Ip Routes
262
Clear Ip Statistics
263
Clear Line
263
Clear Log
263
Clear Messages
264
Clear Ssl Session-Stats
264
Clear Ssl Statistics
264
Configure
265
Copy Running-Configuration
265
Copy Running-Configuration Startup-Configuration
266
Copy Startup-Configuration
266
Copy Startup-Configuration Running-Configuration
267
Copy to Flash
267
Copy to Running-Configuration
268
Copy to Startup-Configuration
268
Disable
269
Erase Running-Configuration
269
Erase Startup-Configuration
269
Fips Enable
270
Quick-Start
270
Refresh
271
Reload
271
Show Access-List
271
Show Diagnostic-Report
272
Show Running-Configuration
273
Show Snmp
273
Show Startup-Configuration
274
Write Flash
275
Write Memory
275
Write Messages
276
Write Network
276
Write Terminal
277
Configuration Command Set
278
Access-List
278
Clock
279
End
280
Exit
280
Finished
280
Help
281
Hostname
281
Interface
282
Ip Address
282
Ip Domain-Name
283
Ip Name-Server
283
Ip Route
284
Ip Route Default
285
Keepalive-Monitor
285
Mode One-Port
286
Mode Pass-Thru
286
Password
286
Rdate-Server
287
Registration-Code
288
Rip
288
No Snmp
289
Snmp Access-List
290
Snmp Contact
291
Snmp Default Community
291
Snmp Enable
292
Snmp Location
293
Snmp Trap-Host
294
Snmp Trap-Type Enterprise
295
Snmp Trap-Type Generic
296
Sntp Interval
297
Sntp Server
298
Ssl
298
Syslog
299
Telnet Access-List
300
Telnet Enable
301
Telnet Port
301
Timezone
302
Web-Mgmt Access-List
302
Web-Mgmt Enable
303
Web-Mgmt Port
304
Interface Configuration Command Set
305
Auto
305
Duplex
305
End
305
Finished
306
Help
306
Speed
306
SSL Configuration Command Set
307
Backend-Server
307
Cert
308
Certgroup
309
End
310
Exit
310
Finished
310
Gencsr
310
Help
311
Import Pkcs12
312
Import Pkcs7
312
Key
313
Reverse-Proxy-Server
314
Secpolicy
315
Server
316
Tcp-Tuning
316
Backend Server Configuration Command Set
318
Activate
318
Certgroup Serverauth
318
End
319
Exit
319
Finished
319
Help
320
Info
320
Ip Address
320
Keepalive Enable
321
Keepalive Frequency
321
Keepalive Maxfailure
322
Localport
322
Log-Url
323
Remoteport
323
Secpolicy
324
Serverauth Domain-Name
325
Serverauth Enable
325
Serverauth Ignore
326
Session-Cache Enable
326
Session-Cache Size
327
Session-Cache Timeout
327
Sslv2 Enable
328
Sslv3 Enable
328
Suspend
329
Tcp-Tuning
329
Tlsv1 Enable
330
Transparent
330
Urlrewrite
331
Certificate Configuration Command Set
332
Binhex
332
Der
332
End
333
Exit
333
Finished
333
Help
333
Info
334
Pem
334
Pem-Paste
334
Certificate Group Configuration Command Set
336
Cert
336
End
336
Exit
337
Finished
337
Help
337
Info
338
Key Configuration Command Set
339
Binhex
339
Der
339
End
340
Exit
340
Finished
340
Genrsa
340
Help
341
Pem
342
Pem-Paste
343
Reverse-Proxy Server Configuration Command Set
344
Info
342
Net-Iis
342
Activate
344
Certgroup Serverauth
344
End
345
Exit
345
Finished
346
Help
346
Info
346
Localport
347
Log-Url
347
Secpolicy
348
Serverauth Enable
349
Serverauth Ignore
349
Session-Cache Enable
350
Session-Cache Size
350
Session-Cache Timeout
351
Sslv2 Enable
351
Sslv3 Enable
352
Suspend
352
Tcp-Tuning
353
Tlsv1 Enable
353
Urlrewrite
354
Security Policy Configuration Command Set
355
Crypto
355
Exit
357
End
357
Finished
358
Help
358
Info
358
Server Configuration Command Set
359
Activate
359
Cert
359
Certgroup Chain
360
Certgroup Clientauth
361
Clientauth Enable
361
Clientauth Error
362
Clientauth Verifydepth
363
End
364
Ephemeral Error
364
Ephrsa
365
Exit
365
Finished
365
Help
366
Httpheader
366
Table C-20 Headers Inserted with Httpheader Client-Cert Command
367
Table C-21 Headers Inserted with Httpheader Session Command
368
Table C-22 Headers Inserted with Httpheader Server-Cert Command
368
Info
369
Ip Address
369
Keepalive Enable
370
Keepalive Frequency
370
Keepalive Maxfailure
371
Key
371
Localport
372
Log-Url
372
Remoteport
373
Secpolicy
374
Session-Cache Enable
375
Session-Cache Size
375
Session-Cache Timeout
376
Sharedcipher Error
376
Sslport
377
Sslv2 Enable
377
Sslv3 Enable
378
Suspend
378
Tcp-Tuning
379
Tlsv1 Enable
379
Transparent
380
Urlrewrite
381
TCP Tuning Configuration Command Set
383
Msltime
383
Delay-Ack
384
Finwt2Time
385
Keepalive
385
Keepalive-Cnt
386
Keepalive-Intv
387
Max-Rexmit
387
Maxrt
388
Maxseg
388
Mtu
389
Nodelay
390
Nopush
390
Probe-Max
391
Probe-Min
392
Push-All
393
Rto-Def
393
Rto-Max
394
Rto-Min
395
Slow-Start
396
Stdurg
396
Wnd-Scale
398
Appendix
399
Minimax Command Summary
399
Text Conventions
399
Appendix D Minimax Command Summary
400
Getting Help
401
Examples
402
Configuring Basic Device Parameters
402
Installing a Firmware Image (Netcat
403
Table D-1 Firmware Image Selection
403
Installing a Firmware Image (Xmodem
404
Table D-2 Firmware Image Selection
405
Extracting a Device Configuration
406
Resetting the Environment to Factory Defaults
407
Command Set
409
(Question Mark
409
Baud
409
Boot
409
Cat
409
Eaddr
410
Env
411
Hinv
412
Ifconfig
412
Netstat
413
Printenv
413
Rdate-Server
413
Reboot
414
Resetenv
414
Sbridge
414
Version
416
Zap
416
Appendix
417
Troubleshooting
417
Troubleshooting the Hardware
418
Table E-1 Troubleshooting the Hardware
418
Figure E-1 Troubleshooting Flowchart
422
Figure E-2 Troubleshooting Flowchart
423
Figure E-3 Troubleshooting Flowchart
424
Appendix
425
SSL Introduction
425
Introduction to SSL
426
Port Blocking Mechanism
426
Figure F-1 Port Blocking
427
Before You Begin
428
Using Existing Keys and Certificates
428
Apache Mod_Ssl
429
Apachessl
429
Stronghold
429
IIS 4 on Windows NT
429
IIS 5 on Windows 2000
430
Configuration Security
431
Passwords
431
Access Lists
432
Factory Default Reset Password
432
Cisco SSL Configuration Components
432
Real Server IP Addresses
433
Keys
433
Certificates
433
Step-Up Certificates and Server-Gated Cryptography
433
Security Policies
434
Chained Certificates
434
Table F-1 Secure Content Accelerator Cryptographic Algorithms
434
Cisco Secure Content Accelerator Management
436
Appendix
439
Regulatory Information
439
Regulatory Standards Compliance
440
Canadian Radio Frequency Emissions Statement
440
Table G-1 Regulatory Standards Compliance
440
FCC Class a
441
CISPR 22 (en 55022) Class a
442
VCCI
442
Troubleshooting E
461
Advertisement
Advertisement
Related Products
Cisco CSS-11154-256M-AC - 1000Mbps Ethernet Switch
Cisco CSR 1000v Series
Cisco CISCO877W-G-A-K9
Cisco CISCO804-IDSL - 804 Router
Cisco CISCO2801
Cisco C887VAG-4G
Cisco C898EAG-LTE
Cisco C888
Cisco C887VAM
Cisco C1109-2PX
Cisco Categories
Switch
IP Phone
Network Router
Wireless Access Point
Network Hardware
More Cisco Manuals
Login
Sign In
OR
Sign in with Facebook
Sign in with Google
Upload manual
Upload from disk
Upload from URL