02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Secure Shell<br />

Secure Shell (SSH) is disabled by default. Enable it using <strong>the</strong> command ip ssh server enable.<br />

SSH supports three methods of au<strong>the</strong>ntication:<br />

• Password Au<strong>the</strong>ntication on page 163<br />

• RSA Au<strong>the</strong>ntication on page 163<br />

• Host-based Au<strong>the</strong>ntication on page 164<br />

Important Points to Remember<br />

• If more than one method is enabled, <strong>the</strong> order in which <strong>the</strong> methods are preferred is based on <strong>the</strong><br />

ssh_config file on <strong>the</strong> Unix machine.<br />

• When all <strong>the</strong> three au<strong>the</strong>ntication methods are enabled, password au<strong>the</strong>ntication is <strong>the</strong> backup method<br />

when <strong>the</strong> RSA method fails.<br />

• The files known_hosts and known_hosts2 are generated when a user tries to SSH using version 1 or<br />

version 2, respectively.<br />

Password Au<strong>the</strong>ntication<br />

Au<strong>the</strong>nticate an SSH client by prompting <strong>for</strong> a password when attempting to connect to <strong>the</strong> <strong>Force10</strong><br />

system. This is <strong>the</strong> simplest methods of au<strong>the</strong>ntication and uses SSH version 1.<br />

Enable SSH password au<strong>the</strong>ntication using <strong>the</strong> command ip ssh password-au<strong>the</strong>ntication enable from<br />

CONFIGURATION mode. View your SSH configuration using <strong>the</strong> command show ip ssh from EXEC<br />

Privilege mode.<br />

Figure 78 Enabling SSH Password Au<strong>the</strong>ntication<br />

<strong>Force10</strong>(conf)#ip ssh server enable<br />

% Please wait while SSH Daemon initializes ... done.<br />

<strong>Force10</strong>(conf)#ip ssh password-au<strong>the</strong>ntication enable<br />

<strong>Force10</strong>#sh ip ssh<br />

SSH server : enabled.<br />

Password Au<strong>the</strong>ntication : enabled.<br />

Hostbased Au<strong>the</strong>ntication : disabled.<br />

RSA Au<strong>the</strong>ntication : disabled.<br />

Vty Encryption Remote IP<br />

RSA Au<strong>the</strong>ntication<br />

Au<strong>the</strong>nticate an SSH client based on an RSA key using RSA au<strong>the</strong>ntication. This method uses SSH<br />

version 2.<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 163

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!