85
Step
Command
Remarks
3.
(Optional.) Use an ACL to
control access to the FTP
server.
ftp server acl
{
ipv4-acl-number
|
ipv6
ipv6-acl-number
}
By default, no ACL is used for access
control.
4.
(Optional.) Enable logging
for FTP login attempts that
are denied by the FTP login
control ACL.
ftp server acl-deny-log
enable
By default, logging is disabled for FTP
login attempts that are denied by the
FTP login control ACL.
5.
(Optional.) Associate an SSL
server policy with the FTP
server to ensure data
security.
ftp server
ssl-server-policy
policy-name
By default, no SSL server policy is
associated with the FTP server.
6.
(Optional.) Set the FTP
connection idle-timeout
timer.
ftp
timeout minutes
By default, the FTP connection
idle-timeout timer is 30 minutes.
If no data transfer occurs on an FTP
connection within the idle-timeout
interval, the FTP server closes the FTP
connection to release resources.
7.
(Optional.) Set the DSCP
value for outgoing FTP
packets.
•
For an IPv4 FTP
server:
ftp server dscp
dscp-value
•
For an IPv6 FTP
server:
ftp server ipv6 dscp
dscp-value
By default, the DSCP value is 0.
8.
(Optional.) Set the maximum
number of concurrent FTP
users.
aaa session-limit ftp
max-sessions
The default is 32.
Changing this setting does not affect
users who are currently online. If the
new list is less than the number of online
FTP users, no additional FTP users can
log in until the number drops below the
new limit.
For more information about this
command, see
Security Command
Reference
.
Configuring authentication and authorization
Perform this task on the FTP server to authenticate FTP clients and set the authorized directories
that authenticated clients can access.
The following authentication modes are available:
•
Local authentication
—The device looks up the client's username and password in the local
user account database. If a match is found, authentication succeeds.
•
Remote authentication
—The device sends the client's username and password to a remote
authentication server for authentication. The user account is configured on the remote
authentication server rather than the device.
The following authorization modes are available:
•
Local authorization
—The device assigns authorized directories to FTP clients based on the
locally configured authorization attributes.
•
Remote authorization
—A remote authorization server assigns authorized directories on the
device to FTP clients.
Summary of Contents for FlexNetwork 10500 Series
Page 139: ...130 Sysname display version ...