Ò»¡¢¹ÊÕϾ°Ïó
ÖÕ¶ËÎÞ·¨Í¨¹ýSSHµÄ·½Ê½µÇ¼ÉÏRSR·ÓÉÆ÷¡£
¶þ¡¢×éÍøÍØÆË
ÍØÆËÃèÊö£º
ÖÕ¶Ë172.26.10.38ͨ¹ýÖÐÑëÍøÂç»·¾³Ê¹ÓÃSSHÏνӵ½RSR·ÓÉÆ÷172.26.4.247
Èý¡¢¿ÉÄÜÔÒò
1¡¢Ã»ÓпªÆôSSH·þÎñ
2¡¢Ã»ÓÐÌìÉú·ÓÉÆ÷¹«Ô¿vtyÏß·
3¡¢Ã»ÓзÅͨSSHµÇ¼µÄ·½Ê½
4¡¢Ã»ÓÐÕýÈ·ÅäÖÃSSHÕ˺ÅÃÜÂëµÇÈëÁ÷Á¿
5¡¢Ã»Óе½Â·ÓÉÆ÷·ÓÉÆ÷ACL¹ýÂË·ÓÉÆ÷
6¡¢Ã»ÓлسÌ·ÓÉ·ÓÉÆ÷ÅäÖõÄvtyÏß·ÂúÁË
ËÄ¡¢ÅŲ鲽Öè
²½ÖèÒ»£º²é³ÊÇ·ñûÓпªÆôSSH·þÎñ
ÔÚ·ÓÉÆ÷ÉÏͨ¹ýshow serviceºÅÁî²é¿´SSH·þÎñÊÇ·ñ¿ªÆô
Èçͼ£º
ssh-serverÊǹعØ×´Ì¬£¬±ØÒªÊ¹ÓÃÈçϺÅÁÆô
Ruijie#conf
Ruijie(config)#enable service ssh-server
Ruijie(config)#end
Ruijie#wr
²½Öè¶þ£º²é³ÊÇ·ñûÓÐÌìÉú·ÓÉÆ÷¹«Ô¿
ÔÚ·ÓÉÆ÷ÉÏʹÓÃshow crypto key mypubkey dsaºÍshow crypto key mypubkey rsaºÅÁ¿´¿´ÊÇ·ñÌìÉúÁË·ÓÉÆ÷µÄ¹«Ô¿£¨Á½¸öºÅÁîÖÐÓÐÒ»¸öÄÜÏÔʾ¹«Ô¿¼´¿É£©
ÈôÈçͼrsaºÍdsa¶¼Êǿյ쬱ØÒª´´½¨dsa»òÕßrsaµÄ¹«Ô¿
1£©´´½¨dsa¹«Ô¿µÄ·½Ê½
2£©´´½¨rsa¹«Ô¿µÄ·½Ê½
²½ÖèÈý£º²é³ÊÇ·ñvtyÏß·ûÓзÅͨSSHµÇ¼µÄ·½Ê½
ʹÓúÅÁîshow run | be line v ²é¿´Êä³öÖÐÊÇ·ñûÓзÅͨssh
Èôδ·Åͨssh£¬Äܹ»¿ªÆôvtyÏß·µÄssh£¬ºÅÁîÈçÏÂͼ£º
¿ªÆôsshºó£¬line vty 0 4Ͻ«²»»áÓÐtransportµÄ¹Ø¼ü×ÖÏÔʾ
²½ÖèËÄ£º²é³ÊÇ·ñÕýÈ·ÅäÖÃÁËSSHÕ˺ÅÃÜÂë
1£©±¾µØÕ˺ÅÃÜÂ뷽ʽÈÏÖ¤
ʹÓúÅÁîshow run | be line v ²é¿´line vtyµÄÅäÖÃÖÐÊÇ·ñÅäÖÃlogin local£¬ÈôΪlogin local£¬±ØÒªÊ¹ÓÃshow run | in rnameºÍshow run | in enable p±ðÀë²é³Õ˺ÅÃÜÂëºÍenableÃÜÂëÊÇ·ñÅäÖá£
°ÑÎÈ£ºSSH²»ÍƼöÓõ¥´¿ÃÜÂëÎÞÕ˺ŵķ½Ê½µÇ¼¡£
2£©AAAÕ˺ÅÃÜÂ뷽ʽÈÏÖ¤
ʹÓúÅÁîshow run | in aaa²é³ÊÇ·ñ¿ªÆôÁËAAAµÄµÇ¼ÈÏÖ¤¡£ÈôÊÇ¿ªÆôÁËAAAµÄµÇ¼ÈÏÖ¤£¬Ä¬ÈϽ«Ñ¡È¡AAA·þÎñÆ÷½øÐеǼÕ˺ÅÃÜÂëУÑé¡£
¢ÙÈôÏëÒª±¾µØÈÏÖ¤£¬±ØÒª²é³ÊÇ·ñÅäÖÃÁËĬÈÏŲÓõÄdefaultÈÏÖ¤ÁÐ±í£¨ÈôÐè·ÇdefaultÈÏÖ¤ÁÐ±í£¬±ØÒªline vty µ×ÏÂʹÓÃlogin authentication ÈÏÖ¤ÁбíÃû³ÆÀ´ÊµÏÖ£©£¬Ê¹ÓÃlocal±¾µØÕ˺ÅÃÜÂëÈÏÖ¤£¬²¢ÇÒ±ØÒª²é³ÊÇ·ñÕýÈ·ÅäÖÃÁËÕ˺ÅÃÜÂë¡£
¢ÚÈôÏëÒªAAAÈÏÖ¤£¬ÐèʹÓúÅÁîshow run | in tac²é³ÊÇ·ñÅäÖõǼÈÏ֤ʹÓÃtacacs+·þÎñÆ÷£¬ÇÒÊÇ·ñ½ç˵Á˸Ãtacacs+·þÎñÆ÷¡£
Èôδ½ç˵£¬Ð轨¸ÄÅäÖÃ
²½ÖèÎ壺²é³ÊÇ·ñSSHÁ÷Á¿Ã»Óе½Â·ÓÉÆ÷
ͨ¹ýÁ÷±í²é¿´ÊÇ·ñÊÕµ½Ô¶¶ËSSH¹ýÀ´µÄÁ÷Á¿
1£©Ê×ÏÈ¿ªÆôÁ÷±íÖ°ÄÜ£¨ËÁÒâ½Ó¿Ú¿ªÆônat¼´¿É£©
R1(config)#interface loopback 0
R1(config-if-Loopback 0)#ip nat inside
R1(config-if-Loopback 0)#end
2£©Í¨¹ýÁ÷±í²é¿´SSH¶Ë¿ÚÊÇ·ñ¹ýÀ´
ÈçͼûÓп´µ½TCP 22¶Ë¿ÚµÄÁ÷Á¿µ½Â·ÓÉÆ÷£¬±ØÒªÊ¹ÓÃshow run | in ip fpmºÅÁî²é³ÊÇ·ñ´æÔÚÁ÷¹ýÂËÅäÖá£
Èô²»´æÔÚ£¬Ðè²é³ÖÐÑë»·¾³ÎÊÌ⣬Á÷Á¿Ã»µ½Â·ÓÉÆ÷¡£
Èô´æÔÚ£¬±ØÒª²é³¶ÔÓ¦Á÷¹ýÂËACLÖÐÊÇ·ñ¹ýÂËÁË22¶Ë¿Ú»òÕßÊÇ·ñûÓзÅͨ22¶Ë¿Ú¡£
Èô¹ýÂËÁËTCP 22¶Ë¿Ú£¬±ØÒª·Åͨ¸Ã¶Ë¿Ú£»
ÈôTCP 22¶Ë¿ÚÓб»·Åͨ£¬Ã»±»¹ýÂË£¬Ôò±ØÒª²é³ÖÐÑë»·¾³ÎÊÌâ¡£
²½ÖèÁù£º²é³ÊÇ·ñ·ÓÉÆ÷½Ó¿ÚACL¹ýÂË
·ÓÉÆ÷ÉÏͨ¹ýshow access-groupºÅÁî²é¿´ÊÇ·ñ´æÔÚ¶ÔÓ¦ssh½Ó¿ÚµÄACL¹ýÂË£¬
Èô´æÔÚ£¬Ôò±ØÒª²é³¶ÔÓ¦½Ó¿ÚµÄACLÊÇ·ñ¹ýÂËÁËTCP22¶Ë¿Ú
ÈçÉÏͼ£¬Ã»ÓÐTCP 22Á÷Á¿±»¹ýÂË¡£
Èô±»¹ýÂË£¬±ØÒªACLÖзÅÐÐÖ÷ÕŶ˿ÚΪTCP 22µÄÁ÷Á¿¡£
²½ÖèÆß£º²é³ÊÇ·ñ·ÓÉÆ÷ûÓлسÌ·ÓÉ
·ÓÉÆ÷ÉÏͨ¹ýshow ip routeºÅÁî²é³ÊÇ·ñÓÐÈ¥Íù¶ÔÓ¦SSHÌáÒéÕßIPµÄ·ÓÉ
Èç±¾ÀýÖÐSSHÌáÒéÕßµÄIPÊÇ172.26.10.38£¬Â·ÓÉÆ÷ÓÐĬÈÏ·Óɻذü¡£
ÈôûÓлذü·ÓÉ£¬±ØÒª¼ÓÉÏÏàÓ¦µÄ·ÓÉ¡£
²½Öè°Ë£º²é³ÊÇ·ñvtyÏß·ÂúÁË
Line vty 0 4´ú±íÓÐ0-4Ò²¾ÍÊÇ5¸össhÏß·Äܹ»µÇ¼É豸£¬ÈôÕâЩÏß·ÂúÁË»á³öÏÖÎÞ¿ÕÏÐÏß·¿ÉµÇ¼·ÓÉÆ÷µÄÇé¿ö¡£Í¨¹ýshow usersºÅÁîÄܹ»²é¿´Óм¸¸öÏß·±»Õ¼ÓÃ
Èô·¢ÏÖÏß·±»Õ¼Âú£¬±ØÒªÌßÓû§ÏÂÏߣ¬Äܹ»clear line vty [Óû§±àºÅ]£¬±¾ÀýÖÐΪclear line vty 0
Èô·¢ÏÖÏß·²»¼°ÈÕ³£Ê¹Óã¬Äܹ»¸ÄΪline vty 0 32£¬Ôö³¤vtyÏß·¡£
Îå¡¢ÐÅÏ¢ÍøÂç
ÐÅÏ¢ÍøÂçºÅÁî²Î¿¼
ter len 0
show ver
show slot
show ver slot
show run
show log
show cpu
show memory
show ip fpm count
show ip fpm st
show ip route
show ip ref route
show ip ref adj
show ip route summary
show arp
show ip int brief
show interface
show service
show crypto key mypubkey dsa
show crypto key mypubkey rsa
show run | be line v
show run | in rname
show run | in enable p
show run | in aaa
show run | in tac
show run | in ip fpm
show access-group
show ssh
show users
ter no len
Áù¡¢×ܽáÓ뽨Òé
SSHµÇ¼²»ÉϵÄÎÊÌ⣬Ðè°ÑÎÈÒÔϼ¸µã£º
- ûÓпªÆôSSH·þÎñ£»
- ûÓÐÌìÉú·ÓÉÆ÷¹«Ô¿£»
- vtyÏß·ûÓзÅͨSSHµÇ¼µÄ·½Ê½£»
- ûÓÐÕýÈ·ÅäÖÃSSHÕ˺ÅÃÜÂë
- Á÷Á¿Ã»Óе½Â·ÓÉÆ÷£»
- ·ÓÉÆ÷ACL¹ýÂË
- ·ÓÉÆ÷ûÓлسÌ·ÓÉ
- vtyÏß·Âú
ÈçÓöµ½¹ÊÕÏÇé¾°ÒÔÉÏ·½Ê½ÎÞ·¨½â¾ö¿Éµã»÷Á´½Ó´¦ÖãºÊÛºóÉÁµçÍÃ