R211x-HP Flexfabric 11900 Security Command Reference

Table Of Contents
284
Usage guidelines
When the server adopts publickey authentication to authenticate a client, the client must get the local
private key for digital signature. Because publickey authentication uses either RSA or DSA algorithm, you
must specify a public key algorithm (by using the identity-key keyword) in order to get the correct data
for the local private key.
Examples
# Connect an SFTP client to the IPv6 SFTP server 2000::1 and specify the public key of the server as svkey.
The SFTP client uses publickey authentication. Use the following algorithms:
Preferred key exchange algorithm is dh-group14.
Preferred server-to-client encryption algorithm is aes128.
Preferred client-to-server HMAC algorithm is sha1.
Preferred server-to-client HMAC algorithm is sha1-96.
Preferred compression algorithm between the server and client is zlib.
<Sysname> sftp ipv6 2000::1 prefer-kex dh-group14 prefer-stoc-cipher aes128
prefer-ctos-hmac sha1 prefer-stoc-hmac sha1-96 prefer-compress zlib publickey svkey
Username:
ssh client ipv6 source
Use ssh client ipv6 source to specify the source IPv6 address or source interface for the Stelnet client.
Use undo ssh client ipv6 source to remove the configuration.
Syntax
ssh client ipv6 source { interface interface-type interface-number | ipv6 ipv6-address }
undo ssh client ipv6 source
Default
The Stelnet client uses the IPv6 address of the interface specified by the route of the device to access the
Stelnet server.
Views
System view
Predefined user roles
network-admin
mdc-admin
Parameters
interface interface-type interface-number: Specifies the IPv6 address of the interface which matches the
destination address of the outbound packets using the longest match criteria as the source IPv6 address.
The interface-type interface-number argument specifies a source interface by its type and number.
ipv6 ipv6-address: Specifies a source IPv6 address.
Usage guidelines
The Stelnet client uses the specified source address to communicate with the server.
If you execute the ssh client ipv6 source command multiple times, the most recent configuration takes
effect.