02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Step Task Command Syntax Command Mode<br />

2 Create shosts by copying <strong>the</strong> public<br />

RSA key to <strong>the</strong> to <strong>the</strong> file shosts in<br />

<strong>the</strong> diretory .ssh, and write <strong>the</strong> IP<br />

address of <strong>the</strong> host to <strong>the</strong> file.<br />

Figure 80 Creating shosts<br />

cp /etc/ssh/ssh_host_rsa_key.pub /.ssh/shosts<br />

admin@Unix_client# cd /etc/ssh<br />

admin@Unix_client# ls<br />

moduli sshd_config ssh_host_dsa_key.pub ssh_host_key.pub<br />

ssh_host_rsa_key.pub ssh_config ssh_host_dsa_key ssh_host_key<br />

ssh_host_rsa_key<br />

admin@Unix_client# cat ssh_host_rsa_key.pub<br />

ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAIEA8K7jLZRVfjgHJzUOmXxuIbZx/<br />

AyWhVgJDQh39k8v3e8eQvLnHBIsqIL8jVy1QHhUeb7GaDlJVEDAMz30myqQbJgXBBRTWgBpLWwL/<br />

doyUXFufjiL9YmoVTkbKcFmxJEMkE3JyHanEi7hg34LChjk9hL1by8cYZP2kYS2lnSyQWk=<br />

admin@Unix_client# ls<br />

id_rsa id_rsa.pub shosts<br />

admin@Unix_client# cat shosts<br />

10.16.127.201, ssh-rsa AAAAB3NzaC1yc2EAAAABIwAAAIEA8K7jLZRVfjgHJzUOmXxuIbZx/AyW<br />

hVgJDQh39k8v3e8eQvLnHBIsqIL8jVy1QHhUeb7GaDlJVEDAMz30myqQbJgXBBRTWgBpLWwL/<br />

doyUXFufjiL9YmoVTkbKcFmxJEMkE3JyHanEi7hg34LChjk9hL1by8cYZP2kYS2lnSyQWk=<br />

3 Create a list of IP addresses and usernames that are permitted to SSH in a file called rhosts, as shown<br />

in Figure 81.<br />

Figure 81 Creating rhosts<br />

admin@Unix_client# ls<br />

id_rsa id_rsa.pub rhosts shosts<br />

admin@Unix_client# cat rhosts<br />

10.16.127.201 admin<br />

4 Copy <strong>the</strong> file shosts and rhosts to <strong>the</strong> <strong>Force10</strong> system.<br />

5 Disable password au<strong>the</strong>ntication<br />

and RSA au<strong>the</strong>ntication, if<br />

configured<br />

• no ip ssh password-au<strong>the</strong>ntication<br />

• no ip ssh rsa-au<strong>the</strong>ntication<br />

• CONFIGURATION<br />

• EXEC Privilege<br />

6 Enable host-based au<strong>the</strong>ntication. ip ssh hostbased-au<strong>the</strong>ntication enable CONFIGURATION<br />

7 Bind shosts and rhosts to<br />

host-based au<strong>the</strong>ntication.<br />

ip ssh pub-key-file flash://filename<br />

ip ssh rhostsfile flash://filename<br />

CONFIGURATION<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 165

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!