HP 6120XG HP ProCurve Series 6120 Blade Switches IPv6 Configuration Guide - Page 152

Secure Copy and Secure FTP for IPv6, Notes

Page 152 highlights

IPv6 Management Security Features Secure Copy and Secure FTP for IPv6 Notes 6-20 Secure Copy and Secure FTP for IPv6 You can take advantage of the Secure Copy (SCP) and Secure FTP (SFTP) client applications to provide a secure alternative to TFTP for transferring sensitive switch information, such as configuration files and login informa­ tion, between the switch and an administrator workstation. By default, SSH is enabled for IPv4 and IPv6 connections on a switch, and a single command set is used for both IPv4 and IPv6 file transfers. SCP and SFTP run over an encrypted SSH session, allowing you to use a secure SSH tunnel to: ■ Transfer files and update ProCurve software images. ■ Distribute new software images with automated scripts that make it easier to upgrade multiple switches simultaneously and securely. You can perform secure file transfers to and from IPv4 and IPv6 client devices by entering the ip ssh filetransfer command. Syntax:. [no] ip ssh filetransfer Enables SSH on the switch to connect to an SCP or SFTP client application to transfer files to and from the switch. Use the no ip ssh filetransfer command to disable the switch's ability to perform secure file transfers with an SCP or SFTP client, without disabling SSH on the switch. After an IPv6 client running SCP/SFTP successfully authenticates and opens an SSH session on the switch, you can copy files to and from the switch using secure, encrypted file transfers. Refer to the documentation that comes with an SCP or SFTP client application for information on the file transfer com­ mands and software utilities to use. Enabling SSH file transfer disables TFTP and Auto-TFTP operation. The switch supports one SFTP session or one SCP session at a time. All files on the switch have read-write permission. However, several SFTP commands, such as create or remove, are not supported and return an error. For complete information on how to configure SCP or SFTP in an SSH session to copy files to and from the switch, refer to the "File Transfers" appendix in the Management and Configuration Guide for your switch.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178

IPv6 Management Security Features
Secure Copy and Secure FTP for IPv6
Secure Copy and Secure FTP for IPv6
You can take advantage of the Secure Copy (SCP) and Secure FTP (SFTP)
client applications to provide a secure alternative to TFTP for transferring
sensitive switch information, such as configuration files and login informa-
tion, between the switch and an administrator workstation.
By default, SSH is enabled for IPv4 and IPv6 connections on a switch, and a
single command set is used for both IPv4 and IPv6 file transfers.
SCP and SFTP run over an encrypted SSH session, allowing you to use a secure
SSH tunnel to:
Transfer files and update ProCurve software images.
Distribute new software images with automated scripts that make it easier
to upgrade multiple switches simultaneously and securely.
You can perform secure file transfers to and from IPv4 and IPv6 client devices
by entering the
ip ssh filetransfer
command.
Syntax:.
[no] ip ssh filetransfer
Enables SSH on the switch to connect to an SCP or SFTP client
application to transfer files to and from the switch.
Use the
no ip ssh filetransfer
command to disable the switch’s
ability to perform secure file transfers with an SCP or SFTP
client, without disabling SSH on the switch.
After an IPv6 client running SCP/SFTP successfully authenticates and opens
an SSH session on the switch, you can copy files to and from the switch using
secure, encrypted file transfers. Refer to the documentation that comes with
an SCP or SFTP client application for information on the file transfer com-
mands and software utilities to use.
Notes
Enabling SSH file transfer disables TFTP and Auto-TFTP operation.
The switch supports one SFTP session or one SCP session at a time.
All files on the switch have read-write permission. However, several SFTP
commands, such as
create
or
remove
, are not supported and return an error.
For complete information on how to configure SCP or SFTP in an SSH session
to copy files to and from the switch, refer to the
“File Transfers”
appendix in
the
Management and Configuration Guide
for your switch.
6-20