1-12
Configuring Authentication and Authorization on the FTP Server
To allow an FTP user to access certain directories on the FTP server, you need to create an account for
the user, authorizing access to the directories and associating the username and password with the
account.
The following configuration is used when the FTP server authenticates and authorizes a local FTP user.
If the FTP server needs to authenticate a remote FTP user, you need to configure authentication,
authorization and accounting (AAA) policy instead of the local user. For detailed configuration, refer to
AAA Configuration
in the
Security Volume
.
Follow these steps to configure authentication and authorization for FTP server:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Create a local user
and enter its view
local-user user-name
Required
No local user exists by default, and the
system does not support FTP
anonymous user access.
Assign a password to
the user
password
{
simple
|
cipher
}
password
Required
Assign the FTP
service to the user
service-type ftp
Required
By default, the system does not support
anonymous FTP access, and does not
assign any service. If the FTP service is
assigned, the root directory of the device
is used by default.
Configure user
properties
authorization-attribute
{
acl
acl-number
|
callback-number
callback-number
|
idle-cut
minute
|
level
level
|
user-profile
profile-name
|
vlan
vlan-id
|
work-directory
directory-name
} *
Optional
By default, the FTP/SFTP users can
access the root directory of the device,
and the user level is 0. You can change
the default configuration by using this
command.
z
For more information about the
local-user
,
password
,
service-type ftp
, and
authorization-attribute
commands, refer to
AAA Commands
in the
Security Volume
.
z
When the device serves as the FTP server, if the client is to perform the write operations (upload,
delete, create, and delete for example) on the device’s file system, the FTP login users must be
level 3 users; if the client is to perform other operations, for example, read operation, the device
has no restriction on the user level of the FTP login users, that is, any level from 0 to 3 is allowed.
Содержание S7906E - Switch
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45...
Страница 598: ...ii...
Страница 1757: ...4 9...
Страница 1770: ...6 4...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20...