Using Scp With Ssh To Copy A Software Image; Removing The Rsa Host Keys And Zeroizing Storage - Dell Z9000 Configuration Manual

10/25/40/50/100gbe throughput
Hide thumbs Also See for Z9000:
Table of Contents

Advertisement

Specifying an SSH Version
The following example uses the ip ssh server version 2 command to enable SSH version 2 and
the show ip ssh command to confirm the setting.
Dell(conf)#ip ssh server version 2
Dell(conf)#do show ip ssh
SSH server
SSH server version
SSH server vrf
SSH server ciphers
ctr,aes192-ctr,aes256-ctr.
SSH server macs
sha2-256,hmac-sha2-256-96.
SSH server kex algorithms : diffie-hellman-group-exchange-sha1,diffie-hellman-
group1-sha1,diffie-hellman-group14-sha1.
Password Authentication
Hostbased Authentication
RSA
Authentication
Vty
Encryption
Dell(conf)#
To disable SSH server functions, use the no ip ssh server enable command.

Using SCP with SSH to Copy a Software Image

To use secure copy (SCP) to copy a software image through an SSH connection from one switch to
another, use the following commands.
On the chassis, invoke SCP.
CONFIGURATION mode
copy scp: flash:
Example of Using SCP to Copy from an SSH Server on Another Switch
The following example shows the use of SCP and SSH to copy a software image from one switch running
SSH server on UDP port 99 to the local switch.
Dell#copy scp: flash:
Address or name of remote host []: 10.10.10.1
Port number of the server [22]: 99
Source file name []: test.cfg
User name to login remote host: admin
Password to login remote host:

Removing the RSA Host Keys and Zeroizing Storage

Use the crypto key zeroize rsa command to delete the host key pairs, both the public and private
key information for RSA 1 and or RSA 2 types. Note that when FIPS mode is enabled there is no RSA 1 key
pair. Any memory currently holding these keys is zeroized (written over with zeroes) and the NVRAM
location where the keys are stored for persistence across reboots is also zeroized.
To remove the generated RSA host keys and zeroize the key storage location, use the crypto key
zeroize rsa command in CONFIGURATION mode.
Dell(conf)#crypto key zeroize rsa
Security
: enabled.
: v2.
: default.
: 3des-cbc,aes128-cbc,aes192-cbc,aes256-cbc,aes128-
: hmac-md5,hmac-md5-96,hmac-sha1,hmac-sha1-96,hmac-
: enabled.
: disabled.
: disabled.
HMAC
Remote IP
733

Advertisement

Table of Contents
loading

Table of Contents