HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 142

Specifying a source IP address or source interface for the Stelnet client

Page 142 highlights

Specifying a source IP address or source interface for the Stelnet client By default, an Stelnet client uses the IP address of the outbound interface specified by the route to the Stelnet server when communicating with the Stelnet server. You can specify a source IP address or source interface for the client to communicate with the server. To make sure the Stelnet client and the Stelnet server can communicate with each other, and to improve the manageability of Stelnet clients in the authentication service, HP recommends that you specify a loopback interface as the source interface. To specify a source IP address or source interface for the Stelnet client: Step 1. Enter system view. 2. Specify a source address or source interface for the Stelnet client. Command Remarks system-view • Specify a source IPv4 address or source interface for the Stelnet client: ssh client source { interface interface-type interface-number | ip ip-address } • Specify a source IPv6 address or source interface for the Stelnet client: ssh client ipv6 source { interface interface-type interface-number | ipv6 ipv6-address } N/A Use either command. By default, an Stelnet client uses the IP address of the outbound interface specified by the route to the Stelnet server when communicating with the Stelnet server. Establishing a connection to an Stelnet server You can start the Stelnet client to establish a connection to an Stelnet server, and specify the public key algorithm, the preferred encryption algorithm, the preferred HMAC algorithm, and the preferred key exchange algorithm. When an Stelnet client accesses an Stelnet server, it uses the locally saved host public key of the server to authenticate the server. When acting as an Stelnet client, the device supports the first authentication by default. When the device accesses an Stelnet server for the first time but it is not configured with the host public key of the SSH server, it can access the server and locally save the server's host public key for future use. In a secure network, the first authentication can simplify the configuration on the SSH client, but it is not reliable. To establish a connection to an Stelnet server: 133

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

133
Specifying a source IP address or source interface for the
Stelnet client
By default, an Stelnet client uses the IP address of the outbound interface specified by the route to the
Stelnet server when communicating with the Stelnet server. You can specify a source IP address or source
interface for the client to communicate with the server. To make sure the Stelnet client and the Stelnet
server can communicate with each other, and to improve the manageability of Stelnet clients in the
authentication service, HP recommends that you specify a loopback interface as the source interface.
To specify a source IP address or source interface for the Stelnet client:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Specify a source address
or source interface for the
Stelnet client.
Specify a source IPv4 address or
source interface for the Stelnet client:
ssh client source
{
interface
interface-type interface-number
|
ip
ip-address
}
Specify a source IPv6 address or
source interface for the Stelnet client:
ssh client ipv6 source
{
interface
interface-type interface-number
|
ipv6
ipv6-address
}
Use either command.
By default, an Stelnet client uses
the IP address of the outbound
interface specified by the route
to the Stelnet server when
communicating with the Stelnet
server.
Establishing a connection to an Stelnet server
You can start the Stelnet client to establish a connection to an Stelnet server, and specify the public key
algorithm, the preferred encryption algorithm, the preferred HMAC algorithm, and the preferred key
exchange algorithm.
When an Stelnet client accesses an Stelnet server, it uses the locally saved host public key of the server
to authenticate the server. When acting as an Stelnet client, the device supports the first authentication by
default. When the device accesses an Stelnet server for the first time but it is not configured with the host
public key of the SSH server, it can access the server and locally save the server's host public key for
future use. In a secure network, the first authentication can simplify the configuration on the SSH client,
but it is not reliable.
To establish a connection to an Stelnet server: