380
Step Command
Remarks
x509v3-ecdsa-sha2-nistp3
84
}
*
•
In FIPS mode:
ssh2 algorithm public-key
{
ecdsa-sha2-nistp256
|
ecdsa-sha2-nistp384
|
rsa
|
x509v3-ecdsa-sha2-nistp2
56
|
x509v3-ecdsa-sha2-nistp3
84
}
*
for algorithm negotiation.
Specifying encryption algorithms for SSH2
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Specify encryption
algorithms for SSH2.
•
In non-FIPS mode:
ssh2 algorithm cipher
{
3des-cbc
|
aes128-cbc
|
aes128-ctr
|
aes128-gcm
|
aes192-ctr
|
aes256-cbc
|
aes256-ctr
|
aes256-gcm
|
des-cbc
}
*
•
In FIPS mode:
ssh2 algorithm cipher
{
aes128-cbc
|
aes128-ctr
|
aes128-gcm
|
aes192-ctr
|
aes256-cbc
|
aes256-ctr
|
aes256-gcm
}
*
By default, SSH2 uses the
encryption algorithms
aes128-ctr
,
aes192-ctr
,
aes256-ctr
,
aes128-gcm
,
aes256-gcm
,
aes128-cbc
,
3des-cbc
,
aes256-cbc
, and
des-cbc
in
descending order of priority for
algorithm negotiation.
Specifying MAC algorithms for SSH2
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Specify MAC algorithms for
SSH2.
•
In non-FIPS mode:
ssh2 algorithm mac
{
md5
|
md5-96
|
sha1
|
sha1-96
|
sha2-256
|
sha2-512
}
*
•
In FIPS mode:
ssh2 algorithm mac
{
sha1
|
sha1-96
|
sha2-256
|
sha2-512
}
*
By default, SSH2 uses the MAC
algorithms
sha2-256
,
sha2-512,
sha1
,
md5
,
sha1-96
, and
md5-96
in descending order of priority for
algorithm negotiation.
Displaying and maintaining SSH
Execute
display
commands in any view.
Task Command
Display the source IP address configured for
the SFTP client.
display sftp client source
Display the source IP address configured for
display ssh client source
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...