Configuring the SSH Server
393
remote server. And the user can use its username and password configured on
the remote server to access the network.
■
Both publickey and rsa indicate public key authentication. They are
implemented with the same method.
■
Under the
publickey
authentication mode, the level of commands available to
a logged-in SSH user can be configured using the
user privilege level
command on the server, and all the users with this authentication mode will
enjoy this level.
■
Under the
password
or
password-publickey
authentication mode, the level
of commands available to a logged-in SSH user is determined by the AAA
scheme. Meanwhile, for different users, the available levels of commands are
also different.
■
Under the
all
authentication mode, the level of commands available to a
logged-in SSH user is determined by the actual authentication method used for
the user.
Specifying a Service
Type for an SSH User
c
CAUTION:
If the
ssh user service-type
command is executed with a username
that does not exist, the system will automatically create the SSH user. However,
the user cannot log in unless you specify an authentication type for it.
Configuring SSH
Management
The SSH server provides a number of management functions that prevent illegal
operations such as malicious password guess, to further guarantee the security of
SSH connections.
c
CAUTION:
■
You can configure a login header only when the service type is
stelnet
. For
configuration of service types, see “Specifying a Service Type for an SSH User”.
Table 305
Specify the service type of an SSH user:
Operation
Command
Remarks
Enter system view
system-view
-
Specify a service type for an
SSH user
ssh user
username
service-type
{
stelnet
|
sftp
|
all
}
Required
stelnet
by default
Table 306
Configure SSH management
Operation
Command
Description
Enter system view
system-view
-
Set SSH authentication
timeout time
ssh server timeout
seconds
Optional
By default, the timeout time is
60 seconds.
Set SSH authentication retry
times
ssh server
authentication-retries
times
Optional
By default, the number of
retry times is 3.
Configure a login header
header shell
text
Optional
By default, no login header is
configured.
Summary of Contents for Switch 4210 9-Port
Page 22: ...20 CHAPTER 1 CLI CONFIGURATION ...
Page 74: ...72 CHAPTER 3 CONFIGURATION FILE MANAGEMENT ...
Page 84: ...82 CHAPTER 5 VLAN CONFIGURATION ...
Page 96: ...94 CHAPTER 8 IP PERFORMANCE CONFIGURATION ...
Page 108: ...106 CHAPTER 9 PORT BASIC CONFIGURATION ...
Page 122: ...120 CHAPTER 11 PORT ISOLATION CONFIGURATION ...
Page 140: ...138 CHAPTER 13 MAC ADDRESS TABLE MANAGEMENT ...
Page 234: ...232 CHAPTER 17 802 1X CONFIGURATION ...
Page 246: ...244 CHAPTER 20 AAA OVERVIEW ...
Page 270: ...268 CHAPTER 21 AAA CONFIGURATION ...
Page 292: ...290 CHAPTER 26 DHCP BOOTP CLIENT CONFIGURATION ...
Page 318: ...316 CHAPTER 29 MIRRORING CONFIGURATION ...
Page 340: ...338 CHAPTER 30 CLUSTER ...
Page 362: ...360 CHAPTER 33 SNMP CONFIGURATION ...
Page 368: ...366 CHAPTER 34 RMON CONFIGURATION ...
Page 450: ...448 CHAPTER 39 TFTP CONFIGURATION ...
Page 451: ......
Page 452: ...450 CHAPTER 39 TFTP CONFIGURATION ...
Page 470: ...468 CHAPTER 40 INFORMATION CENTER ...
Page 496: ...494 CHAPTER 44 DEVICE MANAGEMENT ...