368
Generating local key pairs
Generate local key pairs on the Stelnet client when the Stelnet server uses the authentication
method
publickey
,
password-publickey
, or
any
.
Configuration restrictions and guidelines
When you generate local key pairs on an Stelnet client, follow these restrictions and guidelines:
•
The Stelnet client operating in FIPS mode supports only ECDSA and RSA key pairs.
•
Local DSA, ECDSA, and RSA key pairs for SSH use default names. You cannot assign names
to the key pairs.
•
The key modulus length must be less than 2048 bits when you generate a DSA key pair.
Configuration procedure
To generate local key pairs on the Stelnet client:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Generate local key pairs.
public-key local create
{
dsa
|
ecdsa
{
secp256r1 | secp384r1 }
|
rsa
}
By default, no local key pairs exist
on an Stelnet client.
Specifying the source IP address for SSH packets
As a best practice, specify the IP address of a loopback interface as the source address of SSH
packets for the following purposes:
•
Ensuring the communication between the Stelnet client and the Stelnet server.
•
Improving the manageability of Stelnet clients in authentication service.
To specify the source IP address for SSH packets:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Specify the source
address for SSH packets.
•
Specify the source IPv4 address for
SSH packets:
ssh client source
{
interface
interface-type interface-number
|
ip
ip-address
}
•
Specify the source IPv6 address for
SSH packets:
ssh client ipv6 source
{
interface
interface-type interface-number
|
ipv6
ipv6-address
}
By default, the source IP
address for SSH packets is not
configured. For IPv4 SSH
packets, the device uses the
primary IPv4 address of the
output interface specified in
the routing entry as the source
address of the packets. For
IPv6 SSH packets, the device
automatically selects an IPv6
address as the source address
of the packets in compliance
with RFC 3484.
Establishing a connection to an Stelnet server
When you try to access an Stelnet server, the device must use the server's host public key to
authenticate the server. If the server's host public key is not configured on the device, the device will
notify you to confirm whether to continue with the access.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...