R3166-R3206-HP High-End Firewalls System Management and Maintenance Configuration Guide-6PW101

v
Configuring RSH ·························································································································································· 128
Configuration prerequisites ································································································································ 128
Configuration procedure ···································································································································· 128
RSH configuration example ········································································································································ 129
SSH2.0 configuration ············································································································································· 132
SSH2.0 overview ························································································································································· 132
Introduction to SSH2.0 ······································································································································· 132
Operation of SSH ················································································································································ 132
Configuring the firewall as an SSH server ················································································································ 135
SSH server configuration task list ······················································································································ 135
Generating a DSA or RSA key pair ·················································································································· 135
Enabling SSH server ··········································································································································· 136
Configuring the user interfaces for SSH clients ································································································ 136
Configuring a client public key ·························································································································· 136
Configuring an SSH user ···································································································································· 137
Setting the SSH management parameters ········································································································ 138
Configuring the firewall as an SSH client ················································································································· 139
SSH client configuration task list ························································································································ 139
Specifying a source IP address/interface for the SSH client ·········································································· 139
Configuring whether first-time authentication is supported ············································································· 140
Establishing a connection between the SSH client and the server ································································· 140
Displaying and maintaining SSH ······························································································································· 141
SSH server configuration examples ··························································································································· 141
When the firewall acts as a server for password authentication ··································································· 141
When the firewall acts as a server for publickey authentication ··································································· 143
SSH client configuration examples ····························································································································· 148
When the firewall acts as a client for password authentication ···································································· 148
When the firewall acts as a client for publickey authentication ····································································· 151
SFTP service ····························································································································································· 153
SFTP overview ······························································································································································· 153
Configuring an SFTP server ········································································································································· 153
Configuration prerequisites ································································································································ 153
Enabling the SFTP server ···································································································································· 153
Configuring the SFTP connection idle timeout period ····················································································· 154
Configuring an SFTP client ·········································································································································· 154
Specifying a source IP address or interface for the SFTP client ······································································ 154
Establishing a connection to the SFTP server ···································································································· 154
Working with the SFTP directories ···················································································································· 155
Working with SFTP files ······································································································································ 156
Displaying help information ······························································································································· 156
Terminating the connection to the remote SFTP server ···················································································· 157
SFTP client configuration example ····························································································································· 157
SFTP server configuration example ···························································································································· 160
Virtual device management ···································································································································· 163
Virtual device management overview ························································································································ 163
Configuring a virtual device ······································································································································· 164
Configuration task list ········································································································································· 164
Creating a virtual device ···································································································································· 164
Adding an interface to a virtual device ············································································································ 165
Adding VLANs to a virtual device ····················································································································· 165
Selecting a virtual device ··································································································································· 166
Virtual device configuration example ························································································································ 167