334
Step Command
Remarks
authentication when the timeout
timer expires, the connection
cannot be established.
6.
Specify an ACL to control
SSH user connections.
•
Control IPv4 SSH user
connections:
ssh server acl
acl-number
•
Control IPv6 SSH user
connections:
ssh server ipv6 acl
[
ipv6
]
acl-number
By default, no ACLs are specified
and all SSH users can initiate
connections to the server.
7.
Set the DSCP value in the
packets that the SSH server
sends to the SSH clients.
•
Set the DSCP value in IPv4
packets:
ssh server dscp dscp-value
•
Set the DSCP value in IPv6
packets:
ssh server ipv6 dscp
dscp-value
The default setting is 48.
The DSCP value of a packet
defines the priority of the packet
and affects the transmission
priority of the packet. A bigger
DSCP value represents a higher
priority.
8.
Configure the SFTP
connection idle timeout timer.
sftp server idle-timeout
time-out-value
The default setting is 10 minutes.
When the idle timeout timer
expires, the system automatically
terminates the connection.
9.
Specify the maximum
number of concurrent online
SSH users.
aaa session-limit ssh
max-sessions
The default setting is 32.
When the number of online SSH
users reaches the upper limit, the
system denies new SSH
connection requests.
Changing the upper limit does not
affect online SSH users.
Specifying a PKI domain for the SSH server
The PKI domain specified for the SSH server has the following functions:
•
The SSH server uses the PKI domain to send its certificate to the client in the key exchange
stage.
•
The SSH server uses the PKI domain to authenticate the client's certificate if no PKI domain is
specified for the client authentication by using the
ssh user
command.
To specify a PKI domain for the SSH server:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Specify a PKI domain for the
SSH server.
ssh server pki-domain
domain-name
By default, no PKI domain is
specified for the SSH server.