485
•
Preferred key exchange algorithm:
dh-group14-sha1
.
•
Preferred server-to-client encryption algorithm:
aes128-cbc
.
•
Preferred client-to-server HMAC algorithm:
sha1
.
•
Preferred server-to-client HMAC algorithm:
sha1-96
.
•
Preferred compression algorithm:
zlib
.
<Sysname> sftp ipv6 2000::1 prefer-kex dh-group14-sha1 prefer-stoc-cipher aes128-cbc
prefer-ctos-hmac sha1 prefer-stoc-hmac sha1-96 prefer-compress zlib public-key svkey
Username:
sftp ipv6 suite-b
Use
sftp ipv6 suite-b
to establish a connection to an IPv6 SFTP server based on Suite B algorithms
and enter SFTP client view.
Syntax
sftp
ipv6
server
[
port-number
] [
vpn-instance
vpn-instance-name
] [
-i
interface-type
interface-number
]
suite-b
[
128-bit
|
192-bit
]
pki-domain
domain-name
[
server-pki-domain
domain-name
] [
prefer-compress zlib
] [
dscp
dscp-value
|
source
{
interface
interface-type
interface-number
|
ipv6
ipv6-address
} ] *
Views
User view
Predefined user roles
network-admin
mdc-admin
Parameters
server
: Specifies a server by its IPv6 address or host name, a case-insensitive string of 1 to 253
characters.
port
-
number
: Specifies the port number of the server, in the range of 1 to 65535. The default is 22.
vpn-instance
vpn-instance-name
: Specifies the MPLS L3VPN instance to which the server belongs.
The
vpn-instance-name
argument represents the VPN instance name, a case-sensitive string of 1 to
31 characters.
-i interface-type interface-number:
Specifies an output interface by its type and number for IPv6
SFTP packets. The specified outgoing interface must have a link-local address. This option is used
only when the server uses a link-local address to provide the SFTP service for the client.
suite-b
: Specifies the Suite B algorithms. If neither the 128-bit keyword nor the 192-bit keyword is
specified, all algorithms in Suite B are used. For more information about the Suite B algorithms, see
128-bit
: Specifies the 128-bit Suite B security level.
192-bit
: Specifies the 192-bit Suite B security level.
pki-domain
domain-name
: Specifies the PKI domain of the client's certificate. The
domain-name
argument represents the PKI domain name, a case-insensitive string of 1 to 31 characters. Invalid
characters are tildes (~), asterisks (*), backslashes (\), vertical bars (|), colons (:), dots (.), angle
brackets (< >), quotation marks ("), and apostrophes (').
server-pki-domain
domain-name
: Specifies the PKI domain for verifying the server's certificate.
The
domain-name
argument represents the PKI domain name, a case-insensitive string of 1 to 31
characters. Invalid characters are tildes (~), asterisks (*), backslashes (\), vertical bars (|), colons (:),
dots (.), angle brackets (< >), quotation marks ("), and apostrophes ('). If you do not specify the