141
[SwitchB] ssh server enable
Configure an IP address for VLAN interface 1, which the SSH client will use as the destination for
SSH connection.
[SwitchB] interface vlan-interface 1
[SwitchB-Vlan-interface1] ip address 10.165.87.136 255.255.255.0
[SwitchB-Vlan-interface1] quit
Set the authentication mode for the user interfaces to AAA.
[SwitchB] user-interface vty 0 4
[SwitchB-ui-vty0-4] authentication-mode scheme
Enable the user interfaces to support SSH.
[SwitchB-ui-vty0-4] protocol inbound ssh
Set the user command privilege level to 3.
[SwitchB-ui-vty0-4] user privilege level 3
[SwitchB-ui-vty0-4] quit
Before performing the following tasks, you must use the client software to generate an RSA key pair on the
client, save the public key in a file named
key.pub
, and then upload the file to the SSH server through FTP
or TFTP. For more information, see
below.
Import the peer public key from the file
key.pub
.
[SwitchB] public-key peer Switch001 import sshkey key.pub
Specify the authentication type for user
client002
as publickey, and assign the public key
Switch001
to the user.
[SwitchB] ssh user client002 service-type stelnet authentication-type publickey
assign publickey Switch001
2.
Configure the SSH client
Configure an IP address for Vlan interface 1.
<SwitchA> system-view
[SwitchA] interface vlan-interface 1
[SwitchA-Vlan-interface1] ip address 10.165.87.137 255.255.255.0
[SwitchA-Vlan-interface1] quit
Generate a DSA key pair.
[SwitchA] public-key local create dsa
Export the DSA public key to the file
key.pub
.
[SwitchA] public-key local export dsa ssh2 key.pub
[SwitchA] quit
After generating a key pair on a client, you need to transmit the saved public key file to the server through
FTP or TFTP and have the configuration on the server done before continuing configuration of the client.
# Establish an SSH connection to the server (10.165.87.136).
<SwitchA> ssh2 10.165.87.136
Username: client002