设为首页收藏本站language→→ 语言切换

鸿鹄论坛

 找回密码
 论坛注册

QQ登录

先注册再绑定QQ

查看: 1049|回复: 0
收起左侧

Configuring Secure Shell on Cisco IOS Routers

[复制链接]
发表于 2010-8-27 09:40:17 | 显示全部楼层 |阅读模式
 Hardware and Software Versions
  The information in this document is based on the software version below.
  
  Cisco IOS 3600 Software (C3640-IK9S-M), Version 12.2(2)T1
  
  SSH was introduced into IOS platforms/images as shown below.
  
  SSH Version 1.0 (SSHv1) server was introduced in some IOS platforms/images starting in 12.0.5.S.
  SSH client was introduced in some IOS platforms/images starting in 12.1.3.T.
  SSH terminal-line access (also known as reverse-telnet) was introduced in some IOS platforms/images starting in 12.2.2.T.
  [[The No.1 Picture.]]
  Testing Authentication Without SSH:
  !--- aaa new-model causes the local username/password on the router
  !--- to be used in the absence of other aaa statements.
  aaa new-model
  username cisco password 0 cisco
  line vty 0 4
  !--- Instead of aaa new-model, the login local command may be used.ip domain-name rtp.cisco.com
  !--- Generate an SSH key to be used with SSH.
  
  Testing Authentication With SSH:
  cry key generate rsa
  ip ssh time-out 60
  ip ssh authentication-retries 2
  
  ip domain-name rtp.cisco.com
  !--- Generate an SSH key to be used with SSH.
  cry key generate rsa
  ip ssh time-out 60
  ip ssh authentication-retries 2
  
  line vty 0 4
  !--- Prevent non-SSH telnets.
  transport input ssh
  ssh
  !--- Step 1: Configure hostname if you have not previously done so.
  hostname carter
  !--- aaa new-model causes the local username/password on the router
  !--- to be used in the absence of other AAA statements.
  aaa new-model
  username cisco password 0 cisco
  !--- Step 2: Configure the router's DNS domain.
  ip domain-name rtp.cisco.com
  !--- Step 3: Generate an SSH key to be used with SSH.
  cry key generate rsa
  ip ssh time-out 60
  ip ssh authentication-retries 2
  !--- Step 4: By default the vtys' transport is Telnet. In this case,
  !--- Telnet has been disabled and only SSH is supported.
  line vty 0 4
  transport input SSH
  !--- Instead of aaa new-model, the login local command may be used.
  测试ssh
  ssh -l cisco -c 3des 10.13.1.99
  Adding SSH Terminal-Line Access
  ip ssh port 2001 rotary 1
  line 1 16
  no exec
  rotary 1
  transport input ssh
  exec-timeout 0 0
  modem In Out
  Stopbits 1
您需要登录后才可以回帖 登录 | 论坛注册

本版积分规则

QQ|Archiver|手机版|小黑屋|sitemap|鸿鹄论坛 ( 京ICP备14027439号 )  

GMT+8, 2024-5-19 18:17 , Processed in 0.055988 second(s), 9 queries , Redis On.  

  Powered by Discuz!

  © 2001-2024 HH010.COM

快速回复 返回顶部 返回列表