Setting The Dscp Value For Packets Sent By The Ssh Server; Configuring The Switch As An Ssh Client; Ssh Client Configuration Task List - H3C S5120-HI Security Configuration Manual

Hide thumbs Also See for S5120-HI:
Table of Contents

Advertisement

Step
3.
Set the RSA server key pair
update interval.
4.
Set the SSH user
authentication timeout period.
5.
Set the maximum number of
SSH authentication attempts.

Setting the DSCP value for packets sent by the SSH server

A field in an IPv4 or IPv6 header contains 8 bits and is used to identify the service type of an IP packet.
In an IPv4 packet, this field is called "Type of Service (ToS)." In an IPv6 packet, this field is called "Traffic
class." According to RFC 2474, the ToS field is redefined as the differentiated services (DS) field, where
a DSCP value is represented by the first six bits (0 to 5) and is in the range 0 to 63. The remaining two
bits (6 and 7) are reserved. When a packet is being transmitted, the network devices can identify its
DSCP value, and determines the transmission priority of the packet according to the DSCP value.
To set the DSCP value for packets sent by the SSH server:
Step
1.
Enter system view.
2.
Set the DSCP value for
packets sent by the SSH
server.

Configuring the switch as an SSH client

SSH client configuration task list

Task
Specifying a source IP address/interface for the SSH client
Configuring whether first-time authentication is supported
Establishing a connection between the SSH client and server
Setting the DSCP value for packets sent by the SSH client
Command
ssh server rekey-interval hours
ssh server authentication-timeout
time-out-value
ssh server authentication-retries
times
Command
system-view
Set the DSCP value for IPv4
packets sent by the SSH server:
ssh server dscp dscp-value
Set the DSCP value for IPv6
packets sent by the SSH server:
ssh server ipv6 dscp dscp-value
260
Remarks
Optional.
By default, the interval is 0, and the
RSA server key pair is not updated.
This command is not available in
FIPS mode.
Optional.
60 seconds by default.
Optional.
3 by default.
Remarks
N/A
Optional.
By default, the DSCP value is 16 in
IPv4 packets sent by the SSH server
and is 0 in IPv6 packets sent by the
SSH server.
Remarks
Optional
Optional
Required
Optional

Advertisement

Table of Contents
loading

Table of Contents