Using Scp2 From An External Ssh2 Client - Extreme Networks ExtremeWare 7.2e Installation And User Manual

Software version 7.2e
Table of Contents

Advertisement

Security
• Generating or specifying an authentication key for the SSH2 session.
To enable SSH2, use the following command:
enable ssh2 {access-profile [<access profile> | none]} {port <tcp_port_number>}
You can specify a list of predefined clients that are allowed SSH2 access to the switch. To do this, you
must create an access profile that contains a list of allowed IP addresses.
You can also specify a TCP port number to be used for SSH2 communication. By default the TCP port
number is 22.
The supported ciphers are 3DES-CBC and Blowfish. The supported key exchange is DSA.
An authentication key must be generated before the switch can accept incoming SSH2 sessions. This can
be done automatically by the switch, or you can enter a previously generated key. To have the key
generated by the switch, use the following command:
configure ssh2 key
You are prompted to enter information to be used in generating the key. The key generation process
takes approximately ten minutes. Once the key has been generated, you should save your configuration
to preserve the key.
To use a key that has been previously created, use the following command:
configure ssh2 key {pregenerated}
You are prompted to enter the pregenerated key.
The key generation process generates the SSH2 private host key. The SSH2 public host key is derived
from the private host key, and is automatically transmitted to the SSH2 client at the beginning of an
SSH2 session.
Before you initiate a session from an SSH2 client, ensure that the client is configured for any nondefault
access list or TCP port information that you have configured on the switch. Once these tasks are
accomplished, you may establish an SSH2-encrypted session with the switch. Clients must have a valid
user name and password on the switch in order to log into the switch after the SSH2 session has been
established.
For additional information on the SSH protocol refer to [FIPS-186] Federal Information Processing
Standards Publication (FIPSPUB) 186, Digital Signature Standard, 18 May 1994. This can be download
from: ftp://ftp.cs.hut.fi/pub/ssh. General technical information is also available from:
http://www.ssh.fi

Using SCP2 from an External SSH2 Client

In ExtremeWare version 6.2.1 or later, the SCP2 protocol is supported for transferring image and
configuration files to the switch from the SSH2 client, and for copying the switch configuration from the
switch to an SSH2 client.
CAUTION
You can download a configuration to an Extreme Networks switch using SCP. If you do this, you cannot
save this configuration. If you save this configuration and reboot the switch, the configuration will be
corrupted.
178
ExtremeWare 7.2e Installation and User Guide

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents