Configuration Guide User guide

viii FastIron Configuration Guide
53-1002494-02
SSH2 authentication types. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .181
Enabling and disabling SSH by generating and
deleting host keys . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .181
Configuring DSA or RSA challenge-response authentication .183
Optional SSH parameters . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .185
Setting the number of SSH authentication retries . . . . . . . . .186
Deactivating user authentication . . . . . . . . . . . . . . . . . . . . . . .186
Enabling empty password logins. . . . . . . . . . . . . . . . . . . . . . . .186
Setting the SSH port number . . . . . . . . . . . . . . . . . . . . . . . . . .187
Setting the SSH login timeout value. . . . . . . . . . . . . . . . . . . . .187
Designating an interface as the source for all SSH packets. .187
Configuring the maximum idle time for SSH sessions . . . . . .187
Filtering SSH access using ACLs . . . . . . . . . . . . . . . . . . . . . . . . . . .188
Terminating an active SSH connection . . . . . . . . . . . . . . . . . . . . . .188
Displaying SSH information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .188
Displaying SSH connection information . . . . . . . . . . . . . . . . . .188
Displaying SSH configuration information . . . . . . . . . . . . . . . .189
Displaying additional SSH connection information . . . . . . . . .190
Secure copy with SSH2. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .191
Enabling and disabling SCP . . . . . . . . . . . . . . . . . . . . . . . . . . .191
Secure copy configuration notes . . . . . . . . . . . . . . . . . . . . . . .191
Example file transfers using SCP . . . . . . . . . . . . . . . . . . . . . . .191
SSH2 client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .195
Enabling SSH2 client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .195
Configuring SSH2 client public key authentication . . . . . . . . .195
Using SSH2 client . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .196
Displaying SSH2 client information . . . . . . . . . . . . . . . . . . . . .197
Chapter 6 Software-based Licensing
Software license terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .199
Software-based licensing overview . . . . . . . . . . . . . . . . . . . . . . . . .200
How software-based licensing works . . . . . . . . . . . . . . . . . . . .200
Seamless transition for legacy devices . . . . . . . . . . . . . . . . . .201
License types . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .201
Non-licensed features. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .202
Licensed features and part numbers . . . . . . . . . . . . . . . . . . . . . . .202
Licensing rules . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .206
General notes about licensing . . . . . . . . . . . . . . . . . . . . . . . . .206
Licensing rules for FCX and ICX 6610 devices. . . . . . . . . . . . .207
Licensing rules for FESX6, FSX 800, and
FSX 1600 devices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .208
Licensing for Ports on Demand . . . . . . . . . . . . . . . . . . . . . . . . . . . .208
Configuring PoD on an interface. . . . . . . . . . . . . . . . . . . . . . . .208
Configuring the upper PoD ports in a stack for
ICX 6610 devices only . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .209
Displaying license configuration for PoD ports after a license
upgrade . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .210