HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 195

Setting the DSCP value for packets sent by the SSH server, Configuring the switch as an SSH client

Page 195 highlights

Step Command 4. Set the SSH user ssh server authentication-timeout authentication timeout period. time-out-value 5. Set the maximum number of ssh server authentication-retries SSH authentication attempts. times Remarks Optional. 60 seconds by default. Optional. 3 by default. Setting the DSCP value for packets sent by the SSH server A field in an IPv4 or IPv6 header contains 8 bits and is used to identify the service type of an IP packet. In an IPv4 packet, this field is called"Type of Service (ToS)."In an IPv6 packet, this field is called"Traffic class." According to RFC 2474, the ToS field is redefined as the differentiated services (DS) field, where a DSCP value is represented by the first six bits (0 to 5) and is in the range 0 to 63. The remaining two bits (6 and 7) are reserved. When a packet is being transmitted, the network devices can identify its DSCP value, and determines the transmission priority of the packet according to the DSCP value. To set the DSCP value for packets sent by the SSH server: Step 1. Enter system view. 2. Set the DSCP value for packets sent by the SSH server. Command system-view Remarks N/A • Set the DSCP value for IPv4 packets sent by the SSH server: Optional. ssh server dscp dscp-value By default, the DSCP value is 16 in • Set the DSCP value for IPv6 IPv4 packets sent by the SSH server packets sent by the SSH server: and is 0 in IPv6 packets sent by the ssh server ipv6 dscp dscp-value SSH server. Configuring the switch as an SSH client SSH client configuration task list Task Specifying a source IP address/interface for the SSH client Configuring whether first-time authentication is supported Establishing a connection between the SSH client and server Setting the DSCP value for packets sent by the SSH client Remarks Optional Optional Required Optional Specifying a source IP address/interface for the SSH client This configuration task allows you to specify a source IP address or interface for the client to access the SSH server, improving service manageability. To specify a source IP address or interface for the client: 185

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

185
Step
Command
Remarks
4.
Set the SSH user
authentication timeout period.
ssh server authentication-timeout
time-out-value
Optional.
60 seconds by default.
5.
Set the maximum number of
SSH authentication attempts.
ssh server authentication-retries
times
Optional.
3 by default.
Setting the DSCP value for packets sent by the SSH server
A field in an IPv4 or IPv6 header contains 8 bits and is used to identify the service type of an IP packet.
In an IPv4 packet, this field is called
Type of Service (ToS).
In an IPv6 packet, this field is called
Traffic
class.
According to RFC 2474, the ToS field is redefined as the differentiated services (DS) field, where
a DSCP value is represented by the first six bits (0 to 5) and is in the range 0 to 63. The remaining two
bits (6 and 7) are reserved. When a packet is being transmitted, the network devices can identify its
DSCP value, and determines the transmission priority of the packet according to the DSCP value.
To set the DSCP value for packets sent by the SSH server:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Set the DSCP value for
packets sent by the SSH
server.
Set the DSCP value for IPv4
packets sent by the SSH server:
ssh server dscp
dscp-value
Set the DSCP value for IPv6
packets sent by the SSH server:
ssh server ipv6 dscp
dscp-value
Optional.
By default, the DSCP value is 16 in
IPv4 packets sent by the SSH server
and is 0 in IPv6 packets sent by the
SSH server.
Configuring the switch as an SSH client
SSH client configuration task list
Task
Remarks
Specifying a source IP address/interface for the SSH client
Optional
Configuring whether first-time authentication is supported
Optional
Establishing a connection between the SSH client and server
Required
Setting the DSCP value for packets sent by the SSH client
Optional
Specifying a source IP address/interface for the SSH client
This configuration task allows you to specify a source IP address or interface for the client to access the
SSH server, improving service manageability.
To specify a source IP address or interface for the client: