61
Step
Command
Remarks
6.
Enable scheme
authentication.
authentication-mode
scheme
In non-FIPS mode, password authentication
is enabled for VTY lines by default.
In FIPS mode, scheme authentication is
enabled for VTY lines by default.
In VTY line view, this command is associated
with the
protocol inbound
command. If you
specify a non-default value for one of the two
commands, the other command uses the
default setting, regardless of the setting in
VTY line class view.
7.
(Optional.) Specify
the protocols for the
user lines to support.
•
In non-FIPS mode:
protocol inbound
{
all
|
ssh
|
telnet
}
•
In FIPS mode:
protocol inbound ssh
In non-FIPS mode, Telnet and SSH are
supported by default.
In FIPS mode, SSH is supported by default.
A protocol change does not take effect for
current online users. It takes effect only for
new login users.
In VTY line view, this command is associated
with the
authentication-mode
command. If
you specify a non-default value for one of the
two commands, the other command uses the
default setting, regardless of the setting in
VTY line class view.
8.
(Optional.) Set the
maximum number of
concurrent SSH
users.
aaa session-limit
ssh
max-sessions
The default is 32.
Changing this setting does not affect users
who are currently online. If the new limit is
less than the number of online SSH users, no
additional SSH users can log in until the
number drops below the new limit.
For more information about this command,
see
Security Command Reference
.
9.
Exit to system view.
quit
N/A
10.
(Optional.) Configure
common settings for
VTY lines.
See "
."
N/A
Using the device to log in to an SSH server
You can use the device as an SSH client to log in to an SSH server. If the server is located in a
different subnet than the client, make sure the two devices can reach each other.
Figure 12
Logging in to an SSH server from the device
Perform the following tasks in user view:
Task
Command
Log in to an IPv4 SSH server.
ssh2
server
Log in to an IPv6 SSH server.
ssh2
ipv6
server
SSH client
SSH server
IP network
Summary of Contents for FlexNetwork 10500 Series
Page 139: ...130 Sysname display version ...