394
[SwitchB] ssh user client002 service-type stelnet authentication-type publickey
assign publickey switchkey
# Create a local device management user named
client002
.
[SwitchB] local-user client002 class manage
# Authorize local user
client002
to use the
SSH
service.
[SwitchB-luser-manage-client002] service-type ssh
# Assign the
network-admin
user role to local user
client002
.
[SwitchB-luser-manage-client002] authorization-attribute user-role network-admin
[SwitchB-luser-manage-client002] quit
3.
Establish an SSH connection to the Stelnet server.
<SwitchA> ssh2 192.168.1.40 identity-key dsa
Username: client002
Press CTRL+C to abort.
Connecting to 192.168.1.40 port 22.
The server is not authenticated. Continue? [Y/N]:y
Do you want to save the server public key? [Y/N]:n
Enter a character ~ and a dot to abort.
******************************************************************************
* Copyright (c) 2010-2016 Hewlett Packard Enterprise Development LP *
* Without the owner's prior written consent, *
* no decompiling or reverse-engineering shall be allowed. *
******************************************************************************
<SwitchB>
Select
Yes
to access the server and download the server's host public key. At the next
connection attempt, the client authenticates the server by using the saved server's host public
key on the client.
Stelnet configuration example based on 128-bit Suite B
algorithms
Network requirements
As shown in
, Switch A acts as an Stelnet client (SSH2). Switch B acts as the Stelnet
server (SSH2), and it uses publickey authentication.
Configure Switch A to establish an Stelnet connection to Switch B based on the 128-bit Suite B
algorithms. After the connection is established, you can log in to Switch B as a network-admin to
configure and manage Switch B.
Figure 110 Network diagram
Configuration procedure
1.
Generate the client's certificate and the server's certificate. (Details not shown.)
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...