[Telnet Server] aaa [Telnet Server-aaa] local-user admin1234 password Please configure the login password (8-128) It is recommended that the password consist of at least 2 types of characters, i ncluding lowercase letters, uppercase letters, numerals and special characters. Please enter password: Please confirm password: Info: Add a new user. [Telnet Server-aaa] local-user admin1234 service-type telnet [Telnet Server-aaa] local-user admin1234 privilege level 3 [Telnet Server-aaa] quit
检查配置结果
1.进入CMD命令行,执行相关命令 C:\Documents and Settings\Administrator> telnet 10.137.217.177 1025
2.输入Enter键后,在登录窗口输入AAA验证方式配置的登录用户名和密码,验证通过后,出现用户试图的命令行提示登录设备
1 2 3 4
Username:admin1234 Password: Info: The max number of VTY users is 8, the number of current VTY users online is 1, and total number of terminal users online is 1. <Telnet Server>
[Device2] aaa [Device2-aaa] local-user admin1234 password Please configure the login password (8-128) It is recommended that the password consist of at least 2 types of characters, i ncluding lowercase letters, uppercase letters, numerals and special characters. Please enter password: Please confirm password: Info: Add a new user. [Device2-aaa] local-user admin1234 service-type telnet [Device2-aaa] local-user admin1234 privilege level 3 [Device2-aaa] quit
<HUAWEI> system-view [HUAWEI] sysname Device1 [Device1] quit <Device1> telnet 10.2.1.1 Username:admin1234 Password: Info: The max number of VTY users is 8, the number of current VTY users online is 1, and total number of terminal users online is 1. <Device2>
<HUAWEI> system-view [HUAWEI] sysname SSH Server [SSH Server] interface meth 0/0/0 [SSH Server-MEth0/0/0] ip address 10.248.103.194 255.255.255.0 [SSH Server-MEth0/0/0] quit
2.在SSH服务器端生成本地密钥对
1 2 3 4 5
[SSH Server] rsa local-key-pair create The key name will be:Host The range of public key size is (2048, 4096). NOTE: Key pair generation will take a short while. Please input the modulus [default = 3072]:
[SSH Server] aaa [SSH Server-aaa] local-user admin123 password Please configure the login password (8-128) It is recommended that the password consist of at least 2 types of characters, i ncluding lowercase letters, uppercase letters, numerals and special characters. Please enter password: Please confirm password: Info: Add a new user. [SSH Server-aaa] local-user admin123 service-type terminal ssh [SSH Server-aaa] local-user admin123 privilege level 3 [SSH Server-aaa] quit
5.在服务器端创建SSH用户,并配置认证方式
1 2
[SSH Server] ssh user admin123 [SSH Server] ssh user admin123 authentication-type rsa
6.配置SSH服务器的公钥算法、加密算法、密钥交换算法列表、HMAC认证算法和最小密钥长度。
1 2 3 4 5
[SSH Server] ssh server cipher aes128_ctr aes256_ctr aes192_ctr aes128_gcm aes256_gcm [SSH Server] ssh server hmac sha2_256 sha2_512 [SSH Server] ssh server key-exchange dh_group_exchange_sha256 [SSH Server] ssh server publickey rsa_sha2_256 rsa_sha2_512 [SSH Server] ssh server dh-exchange min-len 3072