19.10.2013 Views

7.6.1.0 - Force10 Networks

7.6.1.0 - Force10 Networks

7.6.1.0 - Force10 Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

To apply a MAC ACL on a VTY line, use the same access-class command as IP ACLs (Figure 61).<br />

Figure 61 Example Access Class Configuration Using TACACS+ Without Prompt<br />

<strong>Force10</strong>(conf)#mac access-list standard sourcemac<br />

<strong>Force10</strong>(config-std-mac)#permit 00:00:5e:00:01:01<br />

<strong>Force10</strong>(config-std-mac)#deny any<br />

<strong>Force10</strong>(conf)#<br />

<strong>Force10</strong>(conf)#line vty 0 9<br />

<strong>Force10</strong>(config-line-vty)#access-class sourcemac<br />

<strong>Force10</strong>(config-line-vty)#end<br />

SCP and SSH<br />

Secure Shell (SSH) is a protocol for secure remote login and other secure network services over an<br />

insecure network. FTOS is compatible with SSH versions 1.5 and 2, both the client and server modes. SSH<br />

sessions are encrypted and use authentication. For details on command syntax, see the Security chapter in<br />

the FTOS Command Line Interface Reference.<br />

SCP is a remote file copy program that works with SSH and is supported by FTOS.<br />

To use the SSH client, use the following command in the EXEC privilege mode:<br />

Command Syntax Command Mode Purpose<br />

ssh {hostname} [-l username |<br />

-p port-number | -v {1 | 2}<br />

EXEC privilege Open an SSH connection specifying the hostname,<br />

username, port number, and version of the SSH<br />

client.<br />

hostname is the IP address or hostname of the<br />

remote device.<br />

• Enter an IPv4 address in dotted decimal format<br />

(A.B.C.D),<br />

• Enter an IPv6 address in hexadecimal format<br />

(0000:0000:0000:0000:0000:0000:0000:0000).<br />

Elision of zeros is supported.<br />

To enable the SSH server for version 1 and 2, use the following command in the CONFIGURATION<br />

mode:<br />

Command Syntax Command Mode Purpose<br />

ip ssh server {enable | port<br />

port-number }<br />

CONFIGURATION To configure the E-Series as an SCP/SSH<br />

server, use this command.<br />

126 Security

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!