F3726, F3211, F3174, R5135, R3816-HP Firewalls and UTM Devices System Management and Maintenance Configuration Guide-6PW100

187
# Export the DSA public key to file key.pub.
[Firewall] public-key local export dsa ssh2 key.pub
[Firewall] quit
Then, you transmit the public key file to the server through FTP or TFTP. (Details not shown.)
2. Configure the Stelnet server:
# Generate the RSA key pairs.
<Router> system-view
[Router] public-key local create rsa
The range of public key size is (512 ~ 2048).
NOTES: If the key modulus is greater than 512,
It will take a few minutes.
Press CTRL+C to abort.
Input the bits of the modulus[default = 1024]:
Generating Keys...
++++++++
++++++++++++++
+++++
++++++++
# Generate a DSA key pair.
[Router] public-key local create dsa
The range of public key size is (512 ~ 2048).
NOTES: If the key modulus is greater than 512,
It will take a few minutes.
Press CTRL+C to abort.
Input the bits of the modulus[default = 1024]:
Generating Keys...
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+++++++++++++++++++++++++++++++++++
# Enable SSH server function.
[Router] ssh server enable
# Configure an IP address for interface GigabitEthernet 0/1, which the Stelnet client will use as the
destination address of the SSH connection.
[Router] interface gigabitethernet 0/1
[Router-GigabitEthernet0/1] ip address 192.168.1.40 255.255.255.0
[Router-GigabitEthernet0/1] quit
# Set the authentication mode for the user interface to AAA.
[Router] user-interface vty 0 4
[Router-ui-vty0-4] authentication-mode scheme
# Enable the user interface to support SSH.
[Router-ui-vty0-4] protocol inbound ssh
# Set the user command privilege level to 3.
[Router-ui-vty0-4] user privilege level 3
[Router-ui-vty0-4] quit
# Import the peer public key from the file key.pub, and name it ClientKey.
[Router] public-key peer ClientKey import sshkey key.pub