627
publickey keyname
: Specifies the host public key of the server, which is used to authenticate the
server. The
keyname
argument is a case-insensitive string of 1 to 64 characters.
source
: Specifies a source IPv6 address or source interface for IPv6 SCP packets. By default, the
device automatically selects a source IPv6 address for IPv6 SCP packets in compliance with RFC
3484. As a best practice to ensure successful IPv6 SCP connections, specify a loopback interface or
dialer interface as the source interface or specify that interface's IPv6 address as the source IPv6
address.
interface interface-type interface-number
: Specifies a source interface by its type and number. The
IPv6 address of this interface is the source IPv6 address of the IPv6 SCP packets.
ipv6 ipv6-address
: Specifies a source IPv6 address.
Examples
# Connect an SCP client to the SCP server
2000::1
. Specify the public key of the server as
svkey
,
and download the file
abc.txt
from the server. The SCP client uses publickey authentication. Use the
following algorithms:
•
Preferred key exchange algorithm:
dh-group14-sha1
.
•
Preferred server-to-client encryption algorithm:
aes128-cbc
.
•
Preferred client-to-server HMAC algorithm:
sha1
.
•
Preferred server-to-client HMAC algorithm:
sha1-96
.
•
Preferred compression algorithm:
zlib
.
<Sysname> scp ipv6 2000::1 get abc.txt prefer-kex dh-group14-sha1 prefer-stoc-cipher
aes128-cbc prefer-ctos-hmac sha1 prefer-stoc-hmac sha1-96 prefer-compress zlib public-key
svkey
sftp
Use
sftp
to establish a connection to an IPv4 SFTP server and enter SFTP client view.
Syntax
In non-FIPS mode:
sftp
server
[
port-number
]
[
vpn-instance
vpn-instance-name
] [
identity-key
{
dsa
|
ecdsa
|
rsa
} |
prefer-compress
zlib
|
prefer-ctos-cipher
{
3des-cbc
|
aes128-cbc
|
aes256-cbc
|
des-cbc
} |
prefer-ctos-hmac
{
md5
|
md5-96
|
sha1
|
sha1-96
} |
prefer-kex
{
dh-group-exchange-sha1
|
dh-group1-sha1
|
dh-group14-sha1
} |
prefer-stoc-cipher
{
3des-cbc
|
aes128-cbc
|
aes256-cbc
|
des-cbc
} |
prefer-stoc-hmac
{
md5
|
md5-96
|
sha1
|
sha1-96
} ] * [
dscp
dscp-value
|
public-key
keyname
|
source
{
interface
interface-type interface-number
|
ip
ip-address
} ] *
In FIPS mode:
sftp
server
[
port-number
]
[
vpn-instance
vpn-instance-name
] [
identity-key
{
ecdsa
|
rsa
} |
prefer-compress
zlib
|
prefer-ctos-cipher
{
aes128-cbc |
aes256-cbc
} |
prefer-ctos-hmac
{
sha1
|
sha1-96
} |
prefer-kex
dh-group14-sha1
|
prefer-stoc-cipher
{
aes128-cbc
|
aes256-cbc
} |
prefer-stoc-hmac
{
sha1
|
sha1-96
} ] * [
public-key
keyname
|
source
{
interface
interface-type interface-number
|
ip
ip-address
} ] *
Views
User view
Predefined user roles
network-admin
Parameters
server
: Specifies a server by its IPv4 address or host name, a case-insensitive string of 1 to 253
characters.