![HP ProCurve 2800 Series Скачать руководство пользователя страница 151](http://html.mh-extra.com/html/hp/procurve-2800-series/procurve-2800-series_manual_163164151.webp)
Configuring Secure Shell (SSH)
Configuring the Switch for SSH Operation
Syntax:
aaa authentication ssh login < local | tacacs | radius >[< local | none >]
Configures a password method for the primary and second
ary login (Operator) access. If you do not specify an optional
secondary method, it defaults to
none
.
aaa authentication ssh enable < local | tacacs | radius>[< local | none >]
Configures a password method for the primary and second
ary enable (Manager) access. If you do not specify an
optional secondary method, it defaults to
none
.
Option B: Configuring the Switch for Client Public-Key SSH
Authentication.
If configured with this option, the switch uses its public
key to authenticate itself to a client, but the client must also provide a client
public-key for the switch to authenticate. This option requires the additional
step of copying a client public-key file from a TFTP server into the switch. This
means that before you can use this option, you must:
1. Create a key pair on an SSH client.
2. Copy the client’s public key into a public-key file (which can contain up
to ten client public-keys).
3. Copy the public-key file into a TFTP server accessible to the switch and
download the file to the switch.
(For more on these topics, refer to “Further Information on SSH Client Public-
Key Authentication” on page 6-21.)
With steps 1 - 3, above, completed and SSH properly configured on the switch,
if an SSH client contacts the switch, login authentication automatically occurs
first, using the switch and client public-keys. After the client gains login
access, the switch controls client access to the manager level by requiring the
passwords configured earlier by the
aaa authentication ssh enable
command.
Syntax:
copy tftp pub-key-file <
ip-address
> <
filename
>
Copies a public key file into the switch.
aaa authentication ssh login public-key
Configures the switch to authenticate a client public-key at
the login level with an optional secondary password method
(Default:
none
).
6-19
Содержание ProCurve 2800 Series
Страница 2: ......
Страница 24: ...Getting Started To Set Up and Install the Switch in Your Network This page is intentionally unused 1 12 ...
Страница 44: ...Configuring Username and Password Security Front Panel Security This page is intentionally unused 2 20 ...
Страница 132: ...RADIUS Authentication and Accounting Messages Related to RADIUS Operation This page is intentionally unused 5 32 ...
Страница 182: ...Configuring Secure Socket Layer SSL Common Errors in SSL setup This page is intentionally unused 7 22 ...
Страница 268: ...Configuring and Monitoring Port Security Operating Notes for Port Security This page is intentionally unused 9 38 ...
Страница 299: ......