Configuring An Ssh User And Specifying Sftp As One Of Service Types - Huawei netengine80e Configuration Manual

Hide thumbs Also See for netengine80e:
Table of Contents

Advertisement

HUAWEI NetEngine80E/40E Router
Configuration Guide - Basic Configurations
Context
By default, user interfaces support Telnet. If no user interface is configured to support SSH,
users cannot log in to the router by using SFTP.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
user-interface
The VTY user interface is displayed.
Step 3 Run:
authentication-mode
The AAA authentication mode is configured.
Step 4 Run:
protocol inbound
The VTY user interface is configured to support SSH.
----End
6.4.4 Configuring an SSH User and Specifying SFTP as One of
Service Types
To allow a user to log in to the router by using SFTP, you must configure an SSH user, configure
the router to generate a local RSA key pair, configure a user authentication mode, specify a
service type and authorized directory for the SSH user.
Context
l
l
Issue 02 (2011-09-10)
[ vty ] first-ui-number [ last-ui-number ]
aaa
ssh
NOTE
If a VTY user interface is configured to support SSH, the VTY user interface must be configured with
AAA authentication. Otherwise, the
SSH users can be authenticated in four modes: RSA, password, password-RSA, and all.
Password authentication depends on Authentication, Authorization and Accounting
(AAA). Before a user logs in to the router in password or password-RSA authentication
mode, you must create a local user with the specified user name in the AAA view.
Configuring the router to generate a local RSA key pair is a key step for SSH login. If an
SSH user logs in to an SSH server in password authentication mode, configure the server
to generate a local RSA key pair. If an SSH user logs in to an SSH server in RSA
authentication mode, configure both the server and the client to generate local RSA key
pairs.
NOTE
Password-RSA authentication requires success of both password authentication and RSA authentication.
The all authentication mode requires success of either password authentication or RSA authentication.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
protocol inbound
ssh command cannot be configured.
6 Managing File System
121

Advertisement

Table of Contents
loading

This manual is also suitable for:

Netengine40e

Table of Contents