- •1.1 Configuring File Management Commands
- •1.1.1 Copy
- •1.1.2 Delete
- •1.1.4 ip address
- •1.1.5 ip route
- •1.1.6 show configuration
- •1.1.7 format
- •1.1.8 more
- •1.2 BasicSystemManagementCommands
- •1.2.1 boot flash
- •1.2.3 chinese
- •1.2.4 chram
- •1.2.5 date
- •1.2.6 english
- •1.2.10 rename
- •1.2.11 reboot
- •1.2.12 alias
- •1.2.13 boot system flash
- •1.2.14 help
- •1.2.15 history
- •1.2.16 show alias
- •1.2.17 show job
- •1.2.18 show break
- •1.2.19 show memory
- •1.3 HTTP Configuration Command
- •1.3.1 ip http access-class
- •1.3.2 ip http port
- •1.3.3 ip http server
- •1.3.4 debug ip http
- •Chapter 2 Terminal Service Configuration Command
- •2.1 Telnet Configuration Command
- •2.1.1 telnet
- •2.1.2 ip telnet
- •2.1.4 where
- •2.1.5 resume
- •2.1.6 disconnect
- •2.1.7 switchkey
- •2.1.8 switchmsg
- •2.1.9 sequence-char
- •2.1.10 clear telnet
- •2.1.11 show telnet
- •2.1.12 debug telnet
- •2.2 Terminal Configuration Command
- •2.2.1 attach-port
- •2.2.2 autocommand
- •2.2.3 clear line
- •2.2.4 connect
- •2.2.5 disconnect
- •2.2.6 exec-timeout
- •2.2.7 length
- •2.2.8 line
- •2.2.9 location
- •2.2.10 login authentication
- •2.2.11 monitor
- •2.2.12 no debug all
- •2.2.13 password
- •2.2.14 resume
- •2.2.15 switchkey
- •2.2.16 sequence-char
- •2.2.17 show debug
- •2.2.18 show line
- •2.2.19 switchmsg
- •2.2.20 terminal length
- •2.2.21 terminal monitor
- •2.2.22 terminal width
- •2.2.23 terminal-type
- •2.2.24 where
- •2.2.25 width
- •3.1 SNMP Commands
- •3.1.1 snmp-server community
- •3.1.2 snmp-server contact
- •3.1.4 snmp-server location
- •3.1.5 snmp-server packetsize
- •3.1.6 snmp-server queue-length
- •3.1.7 snmp-server trap-source
- •3.1.8 snmp-server trap-timeout
- •3.1.11 snmp-server source-addr
- •3.1.12 snmp-server encryption
- •3.1.13 show snmp
- •3.1.14 debug snmp
- •3.2 Configuring RMON Commands
- •3.2.1 rmon alarm
- •3.2.2 rmon event
- •3.2.3 rmon collection stat
- •3.2.4 rmon collection history
- •3.2.5 show rmon
- •3.3 Configuring PDP Commands
- •3.3.1 pdp timer
- •3.3.2 pdp holdtime
- •3.3.3 pdp version
- •3.3.5 pdp enable
- •3.3.6 show pdp traffic
- •3.3.7 show pdp neighbour
- •4.1 Network Testing Tool Commands
- •4.1.1 ping
- •4.2 System Debugging Commands
- •4.3 Fault Diagnosis Commands
- •4.3.1 logging
- •4.3.2 logging buffered
- •4.3.3 logging console
- •4.3.4 logging facility
- •4.3.5 logging monitor
- •4.3.6 logging on
- •4.3.7 logging trap
- •4.3.8 service timestamps
- •4.3.9 clear logging
- •4.3.10 show break
- •4.3.11 show controller
- •4.3.12 show debug
- •4.3.13 show logging
- •Chapter 5 SSH Configuration Commands
- •5.1.1 ip sshd enable
- •5.1.2 ip sshd timeout
- •5.1.3 ip sshd auth-method
- •5.1.4 ip sshd access-class
- •5.1.5 ip sshd auth-retries
- •5.1.6 ip sshd clear
- •5.1.8 show ssh
- •5.1.9 show ip sshd
- •Chapter 6 Other system Command
- •6.1 The link scan command
Baisc Configuration Commands
Chapter 5 SSH Configuration Commands
5.1.1ip sshd enable
Command description
ip sshd enable
no ip sshd enable
Parameter
None
Default
1024 bits
Instruction
It is used to generate the rsa encryption key and then monitor the connection to the ssh server. The process of generating encryption key is a process of consuming the calculation time. It takes one or two minutes.
Command mode
Global configuration mode
Example
In the following example, the SSH service is generated.
device_config#ip sshd enable
5.1.2ip sshd timeout
Command description
ip sshd timout time-length
no ip timeout
Parameter
|
Parameter |
Description |
|
|
|
|
time-length |
Maximum time from the establishment of connection to the authentication |
|
|
approval |
|
|
Value range: 60-65535 |
|
|
|
Default |
|
180 seconds
- 84 -
Baisc Configuration Commands
Instruction
To prevent the illegal user from occupying the connection resources, the connections that are not approved will be shut down after the set duration is exceeded.
Command mode
Global configuration mode
Example
In the following example, the timeout time is set to 360 seconds:
device_config#ip sshd timeout 360
5.1.3ip sshd auth-method
Command description
ip sshd auth-method method
no sshd auth-method
Parameter
Parameter |
Description |
|
|
method |
Sets authentication method list. |
|
|
Default
The default authentication method list is used.
Instrunction
The ssh server uses the authentication method list of the login type.
Command mode
Global configuration mode
Example
In the following example, an auth-ssh authentication method list is configured and it is applied to the ssh server:
device_config#aaa authentication login auth-ssh local device_config#ip sshd auth-method auth-ssh
5.1.4ip sshd access-class
Command description
ip sshd access-class access-list no ip sshd access-class
- 85 -
Baisc Configuration Commands
Parameter
Parameter |
Description |
|
|
access-list |
Standard IP access list |
|
|
Default
No access control list
Instrunction
It is used to configure the access control list for the ssh server. Only the connections complying with the regulations in the access control list can be approved.
Command mode
Global configuration mode
Example
In the following example, an ssh-accesslist access control list is configured and applied in the ssh server:
device_config# ip access-list standard ssh-accesslist device_config_std_nacl#deny 192.168.20.40 device_config#ip sshd access-class ssh-accesslist
5.1.5ip sshd auth-retries
Command description
ip sshd auth-retries times no ip sshd auth-retries
Parameter
Parameter |
Description |
|
|
times |
Maximum re-authentication times |
|
Value range: 0-65535 |
|
|
Default
3 times
Instrunction
The connection will be shut down when the re-authentication times exceeds the set times.
Command mode
Global configuration mode
- 86 -
Baisc Configuration Commands
Example
In the following example, the maximum re-authentication times is set to five times:
device_config#ip sshd auth-retries 5
5.1.6ip sshd clear
Command description
ip sshd clear ID
Parameter
|
Parameter |
Description |
|
|
|
|
ID |
Number of the SSH connection to the local device |
|
|
Value range: 0-65535 |
|
|
|
Default |
|
N/A
Instruction
It is used to mandatorily close the incoming ssh connection with the specified number. You can run the command show ip sshd line to check the current incoming connection’s number.
Command mode
Global configuration mode
Example
In the following example, the No.0 incoming connection is mandatorily closed:
device_config#ip sshd clear 0
5.1.7ssh
Command description
ssh –l userid –d destIP [-c {des|3des|blowfish }] [-o numberofpasswdprompts] [-p port]
Parameter
Parameter |
Description |
|
|
|
|
–l userid |
User account on the server |
|
|
|
|
–d destI |
Destination IP address in the dotted decimal system |
|
|
|
|
-o |
Re-authentication times after the first authentication fails |
|
numberofpasswdpr |
Actual re-authentication times is the set value plus the smallest value set |
|
ompts |
||
|
||
|
|
- 87 -