EasyManuals Logo

HPE FlexNetwork 5510 HI Series Security Configuration Guide

HPE FlexNetwork 5510 HI Series
551 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #350 background imageLoading...
Page #350 background image
337
Step
Command
Remarks
2.
Enable the SSH server to
support SSH1 clients.
ssh server compatible-ssh1x
enable
By default, the SSH server
supports SSH1 clients.
This command is not available in
FIPS mode.
3. Set the RSA server key pair
update interval.
ssh server rekey-interval
hours
By default, the
device does not
update the RSA server key pair.
This command takes effect only
on SSH1 users.
This command is not available in
FIPS mode.
4.
Set the SSH user
authentication timeout timer.
ssh server
authentication-timeout
time-out-value
The default setting is 60 seconds.
If a user does not finish the
authentication when the timeout
timer
expires, the connection
cannot be established.
5. Set the maximum number of
SSH authentication
attempts.
ssh server
authentication-retries
times
The default setting is 3.
If a user does not finish the
authentication when the timeout
timer
expires, the connection
cannot be established.
6.
Specify an ACL to control
SSH user connections.
•
Control IPv4 SSH user
connections:
ssh server acl acl-number
• Control IPv6
SSH user
connections:
ssh server ipv6 acl [ ipv6 ]
acl-number
By default, no ACLs are specified
and all
SSH users can initiate
connections to the server.
7. Set the DSCP value in the
packets that the SSH server
sends to the SSH clients.
• Set the DSCP value in IPv4
packets:
ssh server dscp dscp-value
• Set the DSCP value in IPv6
packets:
ssh server ipv6 dscp
dscp-value
The default setting is 48.
The DSCP value of a packet
defines the priority of the packet
and affects the transmission
priority of the packet. A bigger
DSCP value represents a higher
priority.
8.
Configure the SFTP
connection idle timeout
timer.
sftp server idle-timeout
time-out-value
The default setting is 10 minutes.
When the idle timeout timer
expires, the system automatically
terminates the connection.
9.
Specify the maximum
number of concurrent online
SSH users.
aaa session-limit ssh
max-sessions
The default setting is 32.
When the number of online SSH
users reaches the upper limit, the
system denies
new SSH
connection requests.
Changing the upper limit does not
affect online SSH users.
Specifying a PKI domain for the SSH server
IMPORTANT:
This feature is available in Release 1121 and later.

Table of Contents

Other manuals for HPE FlexNetwork 5510 HI Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HPE FlexNetwork 5510 HI Series and is the answer not in the manual?

HPE FlexNetwork 5510 HI Series Specifications

General IconGeneral
BrandHPE
ModelFlexNetwork 5510 HI Series
CategorySwitch
LanguageEnglish

Related product manuals