HP 6125XLG R2306-HP 6125XLG Blade Switch Security Command Reference - Page 191

scp ipv6, Usage guidelines, Examples, Syntax

Page 191 highlights

• sha1-96: Specifies the HMAC algorithm hmac-sha1-96. prefer-kex: Specifies the preferred key exchange algorithm. The default algorithm is dh-group-exchange in non-FIPS mode and is dh-group14 in FIPS mode. Algorithm dh-group14 features stronger security but costs more time in calculation than dh-group1. • dh-group-exchange: Specifies the key exchange algorithm diffie-hellman-group-exchange-sha1. • dh-group1: Specifies the key exchange algorithm diffie-hellman-group1-sha1. • dh-group14: Specifies the key exchange algorithm diffie-hellman-group14-sha1. prefer-stoc-cipher: Specifies the preferred server-to-client encryption algorithm. The default is aes128. prefer-stoc-hmac: Specifies the preferred server-to-client HMAC algorithm. The default is sha1. publickey keyname: Specifies the host public key of the sever, which is used to authenticate the server. The keyname argument is a case-insensitive string of 1 to 64 characters. source: Specifies a source IP address or source interface to connect to the server. By default, the device automatically selects a source IP address based on the routing entry. To avoid the communication failure between the client and the server due to interface faults, use the specified loopback interface as the source interface, and IP address of this interface as the source IP address. interface interface-type interface-number: Specifies a source interface by its type and number. The IPv4 address of this interface is the source IP address to send packets. ip ip-address: Specifies a source IPv4 address. Usage guidelines When the client's authentication method is publickey, the client must get the local private key for digital signature. Because the publickey authentication uses either RSA or DSA algorithm, you must specify an algorithm (by using the identity-key keyword) in order to get the correct data for the local private key. Examples # Connect an SCP client to the SCP server 200.1.1.1, specify the public key of the server as svkey, and download the file abc.txt from the server. The SCP client uses publickey authentication. Use the following algorithms: • Preferred key exchange algorithm: dh-group14. • Preferred server-to-client encryption algorithm: aes128. • Preferred client-to-server HMAC algorithm: sha1. • Preferred server-to-client HMAC algorithm: sha1-96. • Preferred compression algorithm between the server and client: zlib. scp 200.1.1.1 get abc.txt prefer-kex dh-group14 prefer-stoc-cipher aes128 prefer-ctos-hmac sha1 prefer-stoc-hmac sha1-96 prefer-compress zlib publickey svkey scp ipv6 Use scp ipv6 to transfer files with an IPv6 SCP server. Syntax In non-FIPS mode: scp ipv6 server [ port-number ] [ vpn-instance vpn-instance-name ] [ -i interface-type interface-number ] { put | get } source-file-name [ destination-file-name ] [ identity-key { dsa | rsa } | prefer-compress zlib | prefer-ctos-cipher { 3des | aes128 | aes256 | des } | prefer-ctos-hmac { md5 | md5-96 | sha1 | 182

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321

182
sha1-96
: Specifies the HMAC algorithm
hmac-sha1-96
.
prefer-kex
: Specifies the preferred key exchange algorithm. The default algorithm is
dh-group-exchange
in non-FIPS mode and is
dh-group14
in FIPS mode.
Algorithm
dh-group14
features stronger security but costs more time in calculation than
dh-group1
.
dh-group-exchange
: Specifies the key exchange algorithm
diffie-hellman-group-exchange-sha1
.
dh-group1
: Specifies the key exchange algorithm
diffie-hellman-group1-sha1
.
dh-group14
: Specifies the key exchange algorithm
diffie-hellman-group14-sha1
.
prefer-stoc-cipher
: Specifies the preferred server-to-client encryption algorithm. The default is
aes128
.
prefer-stoc-hmac
: Specifies the preferred server-to-client HMAC algorithm. The default is
sha1
.
publickey
keyname
: Specifies the host public key of the sever, which is used to authenticate the server.
The
keyname
argument is a case-insensitive string of 1 to 64 characters.
source:
Specifies a source IP address or source interface to connect to the server. By default, the device
automatically selects a source IP address based on the routing entry. To avoid the communication failure
between the client and the server due to interface faults, use the specified loopback interface as the
source interface, and IP address of this interface as the source IP address.
interface
interface-type interface-number
: Specifies a source interface by its type and number. The IPv4
address of this interface is the source IP address to send packets.
ip
ip-address
: Specifies a source IPv4 address.
Usage guidelines
When the client's authentication method is publickey, the client must get the local private key for digital
signature. Because the publickey authentication uses either RSA or DSA algorithm, you must specify an
algorithm (by using the
identity-key
keyword) in order to get the correct data for the local private key.
Examples
# Connect an SCP client to the SCP server
200.1.1.1
, specify the public key of the server as
svkey
, and
download the file
abc.txt
from the server. The SCP client uses publickey authentication. Use the following
algorithms:
Preferred key exchange algorithm:
dh-group14
.
Preferred server-to-client encryption algorithm:
aes128
.
Preferred client-to-server HMAC algorithm:
sha1
.
Preferred server-to-client HMAC algorithm:
sha1-96
.
Preferred compression algorithm between the server and client:
zlib
.
<Sysname> scp 200.1.1.1 get abc.txt prefer-kex dh-group14 prefer-stoc-cipher aes128
prefer-ctos-hmac sha1 prefer-stoc-hmac sha1-96 prefer-compress zlib publickey svkey
scp ipv6
Use
scp ipv6
to transfer files with an IPv6 SCP server.
Syntax
In non-FIPS mode:
scp ipv6
server
[
port-number
] [
vpn-instance
vpn-instance-name
] [
-i
interface-type interface-number
]
{
put
|
get
}
source-file-name
[
destination-file-name
] [
identity-key
{
dsa
|
rsa
} |
prefer-compress
zlib
|
prefer-ctos-cipher
{
3des
|
aes128
|
aes256
|
des
} |
prefer-ctos-hmac
{
md5
|
md5-96
|
sha1
|