HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 235

sftp client dscp

Page 235 highlights

prefer-ctos-hmac: Specifies the preferred HMAC algorithm from client to server, defaulted to sha1-96. • md5: Specifies the HMAC algorithm hmac-md5. • md5-96: Specifies the HMAC algorithm hmac-md5-96. • sha1: Specifies the HMAC algorithm hmac-sha1. • sha1-96: Specifies the HMAC algorithm hmac-sha1-96. prefer-kex: Specifies the preferred key exchange algorithm, defaulted to dh-group-exchange. • dh-group-exchange: Specifies the key exchange algorithm diffie-hellman-group-exchange-sha1. • dh-group1: Specifies the key exchange algorithm diffie-hellman-group1-sha1. • dh-group14: Specifies the key exchange algorithm diffie-hellman-group14-sha1. prefer-stoc-cipher: Specifies the preferred encryption algorithm from server to client, defaulted to aes128. prefer-stoc-hmac: Specifies the preferred HMAC algorithm from server to client, defaulted to sha1-96. Description Use sftp to establish a connection to a remote IPv4 SFTP server and enter SFTP client view. When the server adopts publickey authentication to authenticate a client, the client needs to get the local private key for digital signature. As the publickey authentication uses either RSA or DSA algorithm, you must specify an algorithm for the client (by using the identity-key keyword) in order to get the correct data for the local private key. Examples # Connect to SFTP server 10.1.1.2, using the following connection scheme: • Preferred key exchange algorithm: dh-group1. • Preferred encryption algorithm from server to client: aes128. • Preferred HMAC algorithm from client to server: md5. • Preferred HMAC algorithm from server to client: sha1-96. sftp 10.1.1.2 prefer-kex dh-group1 prefer-stoc-cipher aes128 prefer-ctos-hmac md5 prefer-stoc-hmac sha1-96 Input Username: sftp client dscp Syntax sftp client dscp dscp-value View undo sftp client dscp System view Default level 2: System level Parameters dscp-value: Specifies the DSCP value in the IPv4 packets sent by the SFTP client, which ranges from 0 to 63. 226

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

226
prefer-ctos-hmac
: Specifies the preferred HMAC algorithm from client to server, defaulted to
sha1-96
.
md5
: Specifies the HMAC algorithm hmac-md5.
md5-96
: Specifies the HMAC algorithm hmac-md5-96.
sha1
: Specifies the HMAC algorithm hmac-sha1.
sha1-96
: Specifies the HMAC algorithm hmac-sha1-96.
prefer-kex
: Specifies the preferred key exchange algorithm, defaulted to dh-group-exchange.
dh-group-exchange
: Specifies the key exchange algorithm diffie-hellman-group-exchange-sha1.
dh-group1
: Specifies the key exchange algorithm diffie-hellman-group1-sha1.
dh-group14
: Specifies the key exchange algorithm diffie-hellman-group14-sha1.
prefer-stoc-cipher
: Specifies the preferred encryption algorithm from server to client, defaulted to
aes128.
prefer-stoc-hmac
: Specifies the preferred HMAC algorithm from server to client, defaulted to
sha1-96
.
Description
Use
sftp
to establish a connection to a remote IPv4 SFTP server and enter SFTP client view.
When the server adopts publickey authentication to authenticate a client, the client needs to get the local
private key for digital signature. As the publickey authentication uses either RSA or DSA algorithm, you
must specify an algorithm for the client (by using the
identity-key
keyword) in order to get the correct data
for the local private key.
Examples
# Connect to SFTP server 10.1.1.2, using the following connection scheme:
Preferred key exchange algorithm:
dh-group1
.
Preferred encryption algorithm from server to client:
aes128
.
Preferred HMAC algorithm from client to server:
md5
.
Preferred HMAC algorithm from server to client:
sha1-96
.
<Sysname> sftp 10.1.1.2 prefer-kex dh-group1 prefer-stoc-cipher aes128 prefer-ctos-hmac
md5 prefer-stoc-hmac sha1-96
Input Username:
sftp client dscp
Syntax
sftp client dscp
dscp-value
undo sftp client dscp
View
System view
Default level
2: System level
Parameters
dscp-value
: Specifies the DSCP value in the IPv4 packets sent by the SFTP client, which ranges from 0 to
63.