149
Step
Command
Remark
2.
Enable NETCONF over
SOAP.
•
Enable NETCONF over SOAP
over HTTP (not available in FIPS
mode):
netconf soap http enable
•
Enable NETCONF over SOAP
over HTTPS:
netconf soap https enable
By default, the NETCONF over
SOAP feature is disabled.
3.
Set the DSCP value for
NETCONF over SOAP
packets.
•
Set the DSCP value for
NETCONF over SOAP over
HTTP packets:
netconf soap http dscp
dscp-value
•
Set the DSCP value for
NETCONF over SOAP over
HTTPs packets:
netconf soap https dscp
dscp-value
By default, the DSCP value is 0
for NETCONF over SOAP
packets.
4.
Apply an ACL to
NETCONF over SOAP
traffic.
•
Apply an ACL to NETCONF over
SOAP over HTTP traffic (not
available in FIPS mode):
netconf soap http acl
{
acl-number
|
name acl-name
}
•
Apply an ACL to NETCONF over
SOAP over HTTPS traffic:
netconf soap https
acl
{
acl-number
|
name acl-name
}
By default, no ACL is applied to
NETCONF over SOAP traffic.
5.
Specify a mandatory
authentication domain for
NETCONF users.
netconf soap domain
domain-name
By default, no mandatory
authentication domain is
specified for NETCONF users.
For information about
authentication domains, see
Security Configuration Guide
.
Enabling NETCONF over SSH
This feature allows users to use a client to perform NETCONF operations on the device through a
NETCONF over SSH connection.
To enable NETCONF over SSH:
Step
Command
Remark
1.
Enter system view.
system-view
N/A
2.
Enable NETCONF over
SSH.
netconf ssh server enable
By default, NETCONF over SSH is
disabled.
3.
Specify a port to listen for
NETCONF over SSH
connections.
netconf ssh server port
port-number
By default, port 830 listens for
NETCONF over SSH connections.
Enabling NETCONF logging
NETCONF logging generates logs for different NETCONF operation sources and NETCONF
operations.