Got it

Configuring Logging In to the CLI Using SSH Using the CLI - In Practice

Latest reply: Dec 3, 2021 16:56:59 367 12 18 0 0

Configuring Logging In to the CLI Using SSH Using the CLI - In Practice


Hello everyone,


Today, I would like to introduce in practice a method of configuring the SSH protocol and login via CLI.


The local administrator has some administrator permissions and can use SSH to login to the CLI only from a local PC for FW management and maintenance. FW implements local authentication on administrators.


Procedure:


To complete our example, we need to follow these steps:


Enable the SSH service in FW:


Enable SSH for IPv4 or IPv6. IPv4 is used as an example

1a


i_f42.gifIn the example the configured IP address has been set to 172.16.100.2, the interface has been added to the trust zone and the administrator has permission to log into the device using SSH.


Configure the administrator login interface: 


Configure the interface IP address and interface-based access control and enable the administrator to log in to the device through SSH.


2A


Add an interface to the security zone.

3a


Configure the VTY administrator interface: 


Set the VTY administrator interface authentication mode to AAA and the idle disconnect duration to 5 minutes (default value is 10 minutes).


4a


i_f42.gifThe default number of VTY administrator interfaces is five. To add more interfaces, run the maximum-vty number UI command.

Configure the administrator: 


Configure the SSH administrator.


Create an administrator and bind a role to the administrator.


5a

In the example the username is sshuser and the password Huawei@123


Configure the SSH user.

10


Generate a local key pair.

7


Configure the IP address of the administrator PC and use Telnet software to log into the VTY interface: 


Set the IP address and subnet mask of the administrator PC to 172.16.100.1 and 255.255.255.0.

The terminal used in the example is SecureCRT. Choose 
SSH2 as protocol and hostaname 172.16.100.2 as port 22 and click Connect.

6


Enter the configured information in the vty user section.


In the example the user is "sshuser" and the password is "Huawei@123"

06

8


Now let's validate user access.


9

Through the command "displays users" we have the information of the users connected to the equipment.


With that our practical example was completed.


Cheers,


zaheernew
MVE Author Created Nov 29, 2021 16:07:40

cool
View more
  • x
  • convention:

great
View more
  • x
  • convention:

Well done post, thanks q
View more
  • x
  • convention:

Vlada85
MVE Author Created Nov 29, 2021 17:18:05

Very good! Configuring Logging In to the CLI Using SSH Using the CLI - In Practice-4415309-1
View more
  • x
  • convention:

Thanks for sharing
View more
  • x
  • convention:

bruno.guedes
HCIE MVE Author Created Nov 29, 2021 20:36:51

Very clear!
View more
  • x
  • convention:

Thank you for such an useful post! Keep up the good work!
View more
  • x
  • convention:

Important sharing
View more
  • x
  • convention:

Great content.
View more
  • x
  • convention:

12
Back to list

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.