<Huawei>
system-view
[Huawei]
user-interface maximum-vty 15
Step 7
Check that an ACL is configured in the VTY user interface view on the SSH server.
Run the
user-interface
command on the SSH server to enter the SSH user interface view. Then,
run the
display this
command to check whether an ACL is configured in the VTY user interface
view. If an ACL is configured, record the ACL number.
Run the
display acl
command on the SSH server to check whether the SSH client address is
denied in an ACL. If an ACL is configured but the client address to be denied is not specified
in the ACL, the user will fail to log in to the server by means of STelnet or SFTP. To enable a
user with a specific IP address to log in to the server through STelnet, permit the user IP address
in the ACL.
Step 8
Check the SSH versions on the SSH client and SSH server.
On the SSH server, run the
display ssh server status
command to check the SSH version.
<Huawei>
display ssh server status
SSH version :1.99
SSH connection timeout :60 seconds
SSH server key generating interval :0 hours
SSH Authentication retries :3 times
SFTP server :Disable
If the client logging in to the server adopts SSHv1, the version compatible capability needs to
be enabled on the server.
<Huawei>
system-view
[Huawei]
ssh server compatible-ssh1x enable
Step 9
Check whether first-time authentication is enabled on the SSH client.
Run the
display this
command in the system view on the SSH client to check whether first-time
authentication is enabled.
After first-time authentication is enabled, the validity of the RSA public key of the SSH server
does not need to be checked when an SFTP user logs in to the SSH server for the first time. This
is because the RSA public key of the SSH server is not kept on the SFTP client.
If first-time authentication is not enabled, an SFTP user fails to log in to the SSH server. This
is because checking the validity of the RSA public fails.
<Huawei>
system-view
[Huawei]
ssh client first-time enable
Step 10
Collect the following information and contact Huawei technical support personnel:
l
Results of the preceding troubleshooting procedures
l
Configuration files, log files, and alarm files of the devices
----End
Relevant Alarms and Logs
Relevant Alarms
None.
Huawei AR2200-S Series Enterprise Routers
Troubleshooting
2 System
Issue 01 (2012-01-06)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
16