HP StorageWorks 2/16V HP StorageWorks Fabric OS 5.X Procedures User Guide (AA- - Page 41

Configuring the telnet interface, Disabling telnet

Page 41 highlights

Commands that require a secure login channel must be issued from an original SSH session. If you start an SSH session, and then use the login command to start a nested SSH session, commands that require a secure channel are rejected. Fabric OS 4.4.0 and later supports SSH protocol 2.0 (ssh2). For more information on SSH, see the SSH IETF web site: http://www.ietf.org/ids.by.wg/secsh.html. Another informative source is SSH, The Secure Shell: The Definitive Guide by Daniel J. Barrett, Richard Silverman. Fabric OS 4.4.0 comes with the SSH server preinstalled; however, you must select and install the SSH client. For information on installing and configuring the F-Secure SSH client, visit the following web site: http://www.f-secure.com. Configuring the telnet interface Telnet is enabled by default. To prevent users from passing clear text passwords over the network when they connect to the switch, you can disable the telnet interface. NOTE: Before disabling the telnet interface, make sure you have an alternate method of establishing a connection with the switch. Disabling telnet 1. Connect to the switch and log in as admin. Connect through some other means than telnet, for example, through SSH. 2. Issue the following command: configure telnetd 3. In response to the System Services prompt, enter y. 4. In response to the telnetd prompt, enter off. The telnet interface is disabled. If you entered the command during a standard telnet session, the session terminates. For example: switch:admin> configure telnetd Not all options will be available on an enabled switch. To disable the switch, use the "switchDisable" command. Configure... ssl attributes (yes, y, no, n): [no] http attributes (yes, y, no, n): [no] snmp attributes (yes, y, no, n): [no] rpcd attributes (yes, y, no, n): [no] cfgload attributes (yes, y, no, n): [no] [31454]: Read 1 license entries for generation 1. [31454]: Read 1 license records. System services (yes, y, no, n): [no] y rstatd (on, off): [off] rusersd (on, off): [off] telnetd (on, off): [on] off Enabling telnet 1. Connect to the switch through a means other than telnet (for example, SSH) and log in as admin. 2. Issue the following command: configure telnetd 3. In response to the System Services prompt, enter y. Fabric OS 5.x administrator guide 41

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248

Fabric OS 5.x administrator guide
41
Commands that require a secure login channel must be issued from an original SSH session. If you start
an SSH session, and then use the
login
command to start a nested SSH session, commands that require
a secure channel are rejected.
Fabric OS 4.4.0 and later supports SSH protocol 2.0 (ssh2). For more information on SSH, see the SSH
IETF web site:
. Another informative source is
SSH, The Secure
Shell: The Definitive Guide
by Daniel J. Barrett, Richard Silverman.
Fabric OS 4.4.0 comes with the SSH server preinstalled; however, you must select and install the SSH
client. For information on installing and configuring the F-Secure SSH client, visit the following web site:
.
Configuring the telnet interface
Telnet is enabled by default. To prevent users from passing clear text passwords over the network when
they connect to the switch, you can disable the telnet interface.
NOTE:
Before disabling the telnet interface, make sure you have an alternate method of establishing a
connection with the switch.
Disabling telnet
1.
Connect to the switch and log in as admin.
Connect through some other means than telnet, for example, through SSH.
2.
Issue the following command:
configure telnetd
3.
In response to the System Services prompt, enter
y
.
4.
In response to the telnetd prompt, enter
off
.
The telnet interface is disabled. If you entered the command during a standard telnet session, the
session terminates. For example:
Enabling telnet
1.
Connect to the switch through a means other than telnet (for example, SSH) and log in as admin.
2.
Issue the following command:
configure telnetd
3.
In response to the System Services prompt, enter
y
.
switch:admin>
configure telnetd
Not all options will be available on an enabled switch.
To disable the switch, use the “switchDisable” command.
Configure...
ssl attributes (yes, y, no, n): [no]
http attributes (yes, y, no, n): [no]
snmp attributes (yes, y, no, n): [no]
rpcd attributes (yes, y, no, n): [no]
cfgload attributes (yes, y, no, n): [no]
[31454]: Read 1 license entries for generation 1.
[31454]: Read 1 license records.
System services (yes, y, no, n): [no]
y
rstatd (on, off): [off]
rusersd (on, off): [off]
telnetd (on, off): [on]
off