HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 141

Configuring the device as an Stelnet client, Stelnet client configuration task list

Page 141 highlights

• SFTP connection idle timeout period. When the idle period of an SFTP connection exceeds the specified threshold, the system automatically tears the connection down. • Maximum number of concurrent online SSH users. When the number of online SSH users reaches the upper limit, the system refuses new SSH connection requests. To set the SSH management parameters: Step 1. Enter system view. 2. Enable the SSH server to support SSH1 clients. Command system-view ssh server compatible-ssh1x enable 3. Set the RSA server key pair update interval. ssh server rekey-interval hours 4. Set the SSH user ssh server authentication-timeout authentication timeout period. time-out-value 5. Set the maximum number of ssh server authentication-retries SSH authentication attempts. times 6. Configure an ACL for IPv4 SSH clients. ssh server acl acl-number 7. Configure an ACL for IPv6 SSH clients. ssh server ipv6 acl [ ipv6 ] acl-number 8. Configure the SFTP connection idle timeout period. sftp server idle-timeout time-out-value 9. Specify the maximum number of concurrent online SSH aaa session-limit ssh max-sessions users. Remarks N/A By default, the SSH server supports SSH1 clients. This command is not available in FIPS mode. By default, the RSA server key pair is not updated. This command is not available in FIPS mode. The default setting is 60 seconds. The default setting is 3. By default, all IPv4 SSH users are allowed to initiate connections with the SSH server. By default, all IPv6 SSH users are allowed to initiate connections with the SSH server. The default setting is 10 minutes. The default setting is 16. Changing the upper limit does not affect online SSH users. Configuring the device as an Stelnet client Stelnet client configuration task list Tasks at a glance (Optional.) Specifying a source IP address or source interface for the Stelnet client (Required.) Establishing a connection to an Stelnet server 132

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

132
SFTP connection idle timeout period. When the idle period of an SFTP connection exceeds the
specified threshold, the system automatically tears the connection down.
Maximum number of concurrent online SSH users. When the number of online SSH users reaches
the upper limit, the system refuses new SSH connection requests.
To set the SSH management parameters:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable the SSH server to
support SSH1 clients.
ssh server compatible-ssh1x
enable
By default, the SSH server supports
SSH1 clients.
This command is not available in
FIPS mode.
3.
Set the RSA server key pair
update interval.
ssh server rekey-interval
hours
By default, the RSA server key pair
is not updated.
This command is not available in
FIPS mode.
4.
Set the SSH user
authentication timeout period.
ssh server authentication-timeout
time-out-value
The default setting is 60 seconds.
5.
Set the maximum number of
SSH authentication attempts.
ssh server authentication-retries
times
The default setting is 3.
6.
Configure an ACL for IPv4
SSH clients.
ssh server acl
acl-number
By default, all IPv4 SSH users are
allowed to initiate connections with
the SSH server.
7.
Configure an ACL for IPv6
SSH clients.
ssh server ipv6 acl
[
ipv6
]
acl-number
By default, all IPv6 SSH users are
allowed to initiate connections with
the SSH server.
8.
Configure the SFTP
connection idle timeout
period.
sftp server idle-timeout
time-out-value
The default setting is 10 minutes.
9.
Specify the maximum number
of concurrent online SSH
users.
aaa session-limit ssh
max-sessions
The default setting is 16.
Changing the upper limit does not
affect online SSH users.
Configuring the device as an Stelnet client
Stelnet client configuration task list
Tasks at a glance
(Optional.)
Specifying a source IP address or source interface for the Stelnet client
(Required.)
Establishing a connection to an Stelnet server