Ò»¡¢¹ÊÕÏÕ÷Ïó
ÖÕ¶ËÎÞ·¨Í¨¹ýSSHµÄ·½·¨µÇ¼ÉÏRSR·ÓÉÆ÷¡£
¶þ¡¢×éÍøÍØÆË
ÍØÆËÐÎò£º
ÖÕ¶Ë172.26.10.38ͨ¹ýÖÐÐÄÍøÂçÇéÐÎʹÓÃSSHÅþÁ¬µ½RSR·ÓÉÆ÷172.26.4.247
Èý¡¢¿ÉÄÜÔµ¹ÊÔÓÉ
1¡¢Ã»ÓпªÆôSSH·þÎñ
2¡¢Ã»ÓÐÌìÉú·ÓÉÆ÷¹«Ô¿vtyÏß·
3¡¢Ã»ÓзÅͨSSHµÇ¼µÄ·½·¨
4¡¢Ã»ÓÐ׼ȷÉèÖÃSSHÕ˺ÅÃÜÂëµÇÈëÁ÷Á¿
5¡¢Ã»Óе½Â·ÓÉÆ÷·ÓÉÆ÷ACL¹ýÂË·ÓÉÆ÷
6¡¢Ã»ÓлسÌ·ÓÉ·ÓÉÆ÷ÉèÖõÄvtyÏß·ÂúÁË
ËÄ¡¢ÅŲé°ì·¨
°ì·¨Ò»£º¼ì²éÊÇ·ñûÓпªÆôSSH·þÎñ
ÔÚ·ÓÉÆ÷ÉÏͨ¹ýshow serviceÏÂÁîÉó²éSSH·þÎñÊÇ·ñ¿ªÆô
Èçͼ£º
ssh-serverÊǹرÕ״̬£¬ÐèҪʹÓÃÈçÏÂÏÂÁÆô
Ruijie#conf
Ruijie(config)#enable service ssh-server
Ruijie(config)#end
Ruijie#wr
°ì·¨¶þ£º¼ì²éÊÇ·ñûÓÐÌìÉú·ÓÉÆ÷¹«Ô¿
ÔÚ·ÓÉÆ÷ÉÏʹÓÃshow crypto key mypubkey dsaºÍshow crypto key mypubkey rsaÏÂÁ¿´¿´ÊÇ·ñÌìÉúÁË·ÓÉÆ÷µÄ¹«Ô¿£¨Á½¸öÏÂÁîÖÐÓÐÒ»¸öÄÜÏÔʾ¹«Ô¿¼´¿É£©
ÈôÈçͼrsaºÍdsa¶¼Êǿյģ¬ÐèÒª½¨Éèdsa»òÕßrsaµÄ¹«Ô¿
1£©½¨Éèdsa¹«Ô¿µÄ·½·¨
2£©½¨Éèrsa¹«Ô¿µÄ·½·¨
°ì·¨Èý£º¼ì²éÊÇ·ñvtyÏß·ûÓзÅͨSSHµÇ¼µÄ·½·¨
ʹÓÃÏÂÁîshow run | be line v Éó²éÊä³öÖÐÊÇ·ñûÓзÅͨssh
Èôδ·Åͨssh£¬¿ÉÒÔ¿ªÆôvtyÏß·µÄssh£¬ÏÂÁîÈçÏÂͼ£º
¿ªÆôsshºó£¬line vty 0 4Ͻ«²»»áÓÐtransportµÄÒªº¦×ÖÏÔʾ
°ì·¨ËÄ£º¼ì²éÊÇ·ñ׼ȷÉèÖÃÁËSSHÕ˺ÅÃÜÂë
1£©ÍâµØÕ˺ÅÃÜÂë·½·¨ÈÏÖ¤
ʹÓÃÏÂÁîshow run | be line v Éó²éline vtyµÄÉèÖÃÖÐÊÇ·ñÉèÖÃlogin local£¬ÈôΪlogin local£¬ÐèҪʹÓÃshow run | in rnameºÍshow run | in enable p»®·Ö¼ì²éÕ˺ÅÃÜÂëºÍenableÃÜÂëÊÇ·ñÉèÖá£
×¢ÖØ£ºSSH²»ÍƼöÓô¿´âÃÜÂëÎÞÕ˺ŵķ½·¨µÇ¼¡£
2£©AAAÕ˺ÅÃÜÂë·½·¨ÈÏÖ¤
ʹÓÃÏÂÁîshow run | in aaa¼ì²éÊÇ·ñ¿ªÆôÁËAAAµÄµÇ¼ÈÏÖ¤¡£ÈôÊÇ¿ªÆôÁËAAAµÄµÇ¼ÈÏÖ¤£¬Ä¬ÈϽ«½ÓÄÉAAA·þÎñÆ÷¾ÙÐеǼÕ˺ÅÃÜÂëУÑé¡£
¢ÙÈôÏëÒªÍâµØÈÏÖ¤£¬ÐèÒª¼ì²éÊÇ·ñÉèÖÃÁËĬÈÏŲÓõÄdefaultÈÏÖ¤ÁÐ±í£¨ÈôÐè·ÇdefaultÈÏÖ¤ÁÐ±í£¬ÐèÒªline vty µ×ÏÂʹÓÃlogin authentication ÈÏÖ¤ÁбíÃû³ÆÀ´ÊµÏÖ£©£¬Ê¹ÓÃlocalÍâµØÕ˺ÅÃÜÂëÈÏÖ¤£¬²¢ÇÒÐèÒª¼ì²éÊÇ·ñ׼ȷÉèÖÃÁËÕ˺ÅÃÜÂë¡£
¢ÚÈôÏëÒªAAAÈÏÖ¤£¬ÐèʹÓÃÏÂÁîshow run | in tac¼ì²éÊÇ·ñÉèÖõǼÈÏ֤ʹÓÃtacacs+·þÎñÆ÷£¬ÇÒÊÇ·ñ½ç˵Á˸Ãtacacs+·þÎñÆ÷¡£
Èôδ½ç˵£¬ÐèÐÞÕýÉèÖÃ
°ì·¨Î壺¼ì²éÊÇ·ñSSHÁ÷Á¿Ã»Óе½Â·ÓÉÆ÷
ͨ¹ýÁ÷±íÉó²éÊÇ·ñÊÕµ½Ô¶¶ËSSH¹ýÀ´µÄÁ÷Á¿
1£©Ê×ÏÈ¿ªÆôÁ÷±í¹¦Ð§£¨í§Òâ½Ó¿Ú¿ªÆônat¼´¿É£©
R1(config)#interface loopback 0
R1(config-if-Loopback 0)#ip nat inside
R1(config-if-Loopback 0)#end
2£©Í¨¹ýÁ÷±íÉó²éSSH¶Ë¿ÚÊÇ·ñ¹ýÀ´
ÈçͼûÓп´µ½TCP 22¶Ë¿ÚµÄÁ÷Á¿µ½Â·ÓÉÆ÷£¬ÐèҪʹÓÃshow run | in ip fpmÏÂÁî¼ì²éÊÇ·ñ±£´æÁ÷¹ýÂËÉèÖá£
Èô²»±£´æ£¬Ðè¼ì²éÖÐÐÄÇéÐÎÎÊÌ⣬Á÷Á¿Ã»µ½Â·ÓÉÆ÷¡£
Èô±£´æ£¬ÐèÒª¼ìºË¶ÔÓ¦Á÷¹ýÂËACLÖÐÊÇ·ñ¹ýÂËÁË22¶Ë¿Ú»òÕßÊÇ·ñûÓзÅͨ22¶Ë¿Ú¡£
Èô¹ýÂËÁËTCP 22¶Ë¿Ú£¬ÐèÒª·Åͨ¸Ã¶Ë¿Ú£»
ÈôTCP 22¶Ë¿ÚÓб»·Åͨ£¬Ã»±»¹ýÂË£¬ÔòÐèÒª¼ì²éÖÐÐÄÇéÐÎÎÊÌâ¡£
°ì·¨Áù£º¼ì²éÊÇ·ñ·ÓÉÆ÷½Ó¿ÚACL¹ýÂË
·ÓÉÆ÷ÉÏͨ¹ýshow access-groupÏÂÁîÉó²éÊÇ·ñ±£´æ¶ÔÓ¦ssh½Ó¿ÚµÄACL¹ýÂË£¬
Èô±£´æ£¬ÔòÐèÒª¼ìºË¶ÔÓ¦½Ó¿ÚµÄACLÊÇ·ñ¹ýÂËÁËTCP22¶Ë¿Ú
ÈçÉÏͼ£¬Ã»ÓÐTCP 22Á÷Á¿±»¹ýÂË¡£
Èô±»¹ýÂË£¬ÐèÒªACLÖзÅÐÐÄ¿µÄ¶Ë¿ÚΪTCP 22µÄÁ÷Á¿¡£
°ì·¨Æß£º¼ì²éÊÇ·ñ·ÓÉÆ÷ûÓлسÌ·ÓÉ
·ÓÉÆ÷ÉÏͨ¹ýshow ip routeÏÂÁî¼ì²éÊÇ·ñÓÐÈ¥Íù¶ÔÓ¦SSHÌᳫÕßIPµÄ·ÓÉ
Èç±¾ÀýÖÐSSHÌᳫÕßµÄIPÊÇ172.26.10.38£¬Â·ÓÉÆ÷ÓÐĬÈÏ·Óɻذü¡£
ÈôûÓлذü·ÓÉ£¬ÐèÒª¼ÓÉÏÏìÓ¦µÄ·ÓÉ¡£
°ì·¨°Ë£º¼ì²éÊÇ·ñvtyÏß·ÂúÁË
Line vty 0 4´ú±íÓÐ0-4Ò²¾ÍÊÇ5¸össhÏß·¿ÉÒԵǼװ±¸£¬ÈôÕâЩÏß·ÂúÁ˻᷺ÆðÎÞ¿ÕÏÐÏß·¿ÉµÇ¼·ÓÉÆ÷µÄÇéÐΡ£Í¨¹ýshow usersÏÂÁî¿ÉÒÔÉó²éÓм¸¸öÏß·±»Õ¼ÓÃ
Èô·¢Ã÷Ïß·±»Õ¼Âú£¬ÐèÒªÌßÓû§ÏÂÏߣ¬¿ÉÒÔclear line vty [Óû§±àºÅ]£¬±¾ÀýÖÐΪclear line vty 0
Èô·¢Ã÷Ïß·ȱ·¦Ò»Ñùƽ³£Ê¹Ó㬿ÉÒÔ¸ÄΪline vty 0 32£¬ÔöÌívtyÏß·¡£
Îå¡¢ÐÅÏ¢ÍøÂç
ÐÅÏ¢ÍøÂçÏÂÁî²Î¿¼
ter len 0
show ver
show slot
show ver slot
show run
show log
show cpu
show memory
show ip fpm count
show ip fpm st
show ip route
show ip ref route
show ip ref adj
show ip route summary
show arp
show ip int brief
show interface
show service
show crypto key mypubkey dsa
show crypto key mypubkey rsa
show run | be line v
show run | in rname
show run | in enable p
show run | in aaa
show run | in tac
show run | in ip fpm
show access-group
show ssh
show users
ter no len
Áù¡¢×ܽáÓ뽨Òé
SSHµÇ¼²»ÉϵÄÎÊÌ⣬Ðè×¢ÖØÒÔϼ¸µã£º
- ûÓпªÆôSSH·þÎñ£»
- ûÓÐÌìÉú·ÓÉÆ÷¹«Ô¿£»
- vtyÏß·ûÓзÅͨSSHµÇ¼µÄ·½·¨£»
- ûÓÐ׼ȷÉèÖÃSSHÕ˺ÅÃÜÂë
- Á÷Á¿Ã»Óе½Â·ÓÉÆ÷£»
- ·ÓÉÆ÷ACL¹ýÂË
- ·ÓÉÆ÷ûÓлسÌ·ÓÉ
- vtyÏß·Âú
ÈçÓöµ½¹ÊÕÏÇéÐÎÒÔÉÏ·½·¨ÎÞ·¨½â¾ö¿Éµã»÷Á´½Ó´¦Öóͷ££ºÊÛºóÉÁµçÍÃ