Specifying A Pki Domain For The Ssh Server; Specifying The Ssh Service Port - HPE FlexNetwork 7500 Series Security Configuration Manual

Table of Contents

Advertisement

Step
7.
Set the DSCP value in the
packets that the SSH server
sends to the SSH clients.
8.
Set the SFTP connection idle
timeout timer.
9.
Set the maximum number of
concurrent online SSH
users.

Specifying a PKI domain for the SSH server

The PKI domain specified for the SSH server has the following functions:
The SSH server uses the PKI domain to send its certificate to the client in the key exchange
stage.
The SSH server uses the PKI domain to authenticate the client's certificate if no PKI domain is
specified for the client authentication by using the ssh user command.
To specify a PKI domain for the SSH server:
Step
1.
Enter system view.
2.
Specify a PKI domain for the
SSH server.

Specifying the SSH service port

The default port of SSH service is 22. Perform this task to specify another port for the SSH service.
If you modify the SSH port number when the SSH server is enabled, the SSH service is restarted and
all SSH connections are terminated after the modification. SSH users must reconnect to the SSH
server to access the server.
If you set the SSH port to a well-known port number, the service that uses the well-known port
number might fail to start. Well-known port numbers are in the range of 1 to 1024.
To specify the SSH service port:
Step
1.
Enter system view.
2.
Specify a port for the SSH
service.
Command
Set the DSCP value in IPv4
packets:
ssh server dscp dscp-value
Set the DSCP value in IPv6
packets:
ssh server ipv6 dscp
dscp-value
sftp server idle-timeout
time-out-value
aaa session-limit ssh
max-sessions
Command
system-view
ssh server pki-domain
domain-name
Command
system-view
ssh server port port-number
316
Remarks
The default setting is 48.
The DSCP value of a packet
defines the priority of the packet
and affects the transmission
priority of the packet. A bigger
DSCP value represents a higher
priority.
The default setting is 10 minutes.
When the idle timeout timer
expires, the system automatically
tears the connection down.
The default setting is 32.
When the number of online SSH
users reaches the upper limit, the
system denies new SSH
connection requests.
Changing the upper limit does not
affect online SSH users.
Remarks
N/A
By default, no PKI domain is
specified for the SSH server.
Remarks
N/A
By default, the SSH port is 22.

Advertisement

Table of Contents
loading

Table of Contents