F3726, F3211, F3174, R5135, R3816-HP Firewalls and UTM Devices System Management and Maintenance Configuration Guide-6PW100
181
c. Likewise, to save the private key, click Save private key.
A warning window pops up to prompt you whether to save the private key without any
protection.
d. Click Yes and enter the name of the file for saving the key (private.ppk in this case).
e. Transmit the public key file to the server through FTP or TFTP. (Details not shown.)
2. Configure the Stelnet server:
# Generate the RSA key pairs.
<Firewall> system-view
[Firewall] public-key local create rsa
The range of public key size is (512 ~ 2048).
NOTES: If the key modulus is greater than 512,
It will take a few minutes.
Press CTRL+C to abort.
Input the bits of the modulus[default = 1024]:
Generating Keys...
++++++++
++++++++++++++
+++++
++++++++
# Generate a DSA key pair.
[Firewall] public-key local create dsa
The range of public key size is (512 ~ 2048).
NOTES: If the key modulus is greater than 512,
It will take a few minutes.
Press CTRL+C to abort.
Input the bits of the modulus[default = 1024]:
Generating Keys...
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+++++++++++++++++++++++++++++++++++
# Enable the SSH server function.
[Firewall] ssh server enable
# Configure an IP address for interface GigabitEthernet 0/1, which the Stelnet client will use as the
destination for SSH connection.
[Firewall] interface gigabitethernet 0/1
[Firewall-GigabitEthernet0/1] ip address 192.168.1.40 255.255.255.0
[Firewall-GigabitEthernet0/1] quit
# Set the authentication mode for the user interface to AAA.
[Firewall] user-interface vty 0 4
[Firewall-ui-vty0-4] authentication-mode scheme
# Enable the user interface to support SSH.
[Firewall-ui-vty0-4] protocol inbound ssh
[Firewall-ui-vty0-4] quit
# Import the client's public key from file key.pub and name it ClientKey.
[Firewall] public-key peer ClientKey import sshkey key.pub
# Specify the authentication method for user client002 as publickey, and assign the public key
ClientKey to the user.