EasyManuals Logo

HPE FlexNetwork 5510 HI Series Security Configuration Guide

HPE FlexNetwork 5510 HI Series
551 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #351 background imageLoading...
Page #351 background image
338
The PKI domain specified for the SSH server has the following functions:
• The SSH server uses the PKI domain to send its certificate to the client in the key exchange
stage.
• The SSH server uses the PKI domain to authenticate the client's certificate if no PKI domain is
specified for the client authentication by using the ssh user command.
To specify a PKI domain for the SSH server:
Step
Command
Remarks
1. Enter system view.
system-view
N/A
2. Specify a PKI domain for the
SSH server.
ssh server pki-domain
domain-name
By default, no PKI domain is
specified for the SSH server.
Configuring the device as an Stelnet client
Stelnet client configuration task list
Tasks at a glance
(Optional.) Specifying the source IP address for SSH packets
(Required.) Establishing a connection to an Stelnet server
(Optional.) Establishing a connection to an Stelnet server based on Suite B
Specifying the source IP address for SSH packets
As a best practice, specify the IP address of the loopback interface as the source interface for SSH
packets for the following purposes:
• Ensuring the communication between the Stelnet client and the Stelnet server.
• Improving the manageability of Stelnet clients in authentication service.
To specify the source IP address for SSH packets:
Step
Command
Remarks
1. Enter system view.
system-view
N/A
2. Specify the source
address for SSH packets.
• Specify the source IPv4 address for
SSH packets:
ssh client source
{
interface
interface-type interface-number |
ip
ip-address }
• Specify the source IPv6 address for
SSH packets:
ssh client ipv6 source { interface
interface-type interface-number |
ipv6 ipv6-address }
By default, the
source IP
address for SSH packets is not
configured. For IPv4 SSH
packets, the device uses the
primary IPv4 address
of the
output interface specified in
the routing entry as the source
address of the packets. For
IPv6 SSH packets, the device
automatically selects an IPv6
address as the source address
of the packets in compliance
with RFC 3484.

Table of Contents

Other manuals for HPE FlexNetwork 5510 HI Series

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the HPE FlexNetwork 5510 HI Series and is the answer not in the manual?

HPE FlexNetwork 5510 HI Series Specifications

General IconGeneral
BrandHPE
ModelFlexNetwork 5510 HI Series
CategorySwitch
LanguageEnglish

Related product manuals