Ò»¡¢¹ÊÕÏÏÖÏó
ÖÕ¶ËÎÞ·¨Í¨¹ýSSHµÄ·½Ê½µÇ¼ÉÏRSR·ÓÉÆ÷¡£
¶þ¡¢×éÍøÍØÆË
ÍØÆËÃèÊö£º
ÖÕ¶Ë172.26.10.38ͨ¹ýÖмäÍøÂç»·¾³Ê¹ÓÃSSHÁ¬½Óµ½RSR·ÓÉÆ÷172.26.4.247
Èý¡¢¿ÉÄÜÔÒò
1¡¢Ã»ÓпªÆôSSH·þÎñ
2¡¢Ã»ÓÐÉú³É·ÓÉÆ÷¹«Ô¿vtyÏß·
3¡¢Ã»ÓзÅͨSSHµÇ¼µÄ·½Ê½
4¡¢Ã»ÓÐÕýÈ·ÅäÖÃSSHÕ˺ÅÃÜÂëµÇÈëÁ÷Á¿
5¡¢Ã»Óе½Â·ÓÉÆ÷·ÓÉÆ÷ACL¹ýÂË·ÓÉÆ÷
6¡¢Ã»ÓлسÌ·ÓÉ·ÓÉÆ÷ÅäÖõÄvtyÏß·ÂúÁË
ËÄ¡¢ÅŲ鲽Öè
²½ÖèÒ»£º¼ì²éÊÇ·ñûÓпªÆôSSH·þÎñ
ÔÚ·ÓÉÆ÷ÉÏͨ¹ýshow serviceÃüÁî²é¿´SSH·þÎñÊÇ·ñ¿ªÆô
Èçͼ£º
ssh-serverÊǹرÕ״̬£¬ÐèҪʹÓÃÈçÏÂÃüÁÆô
Ruijie#conf
Ruijie(config)#enable service ssh-server
Ruijie(config)#end
Ruijie#wr
²½Öè¶þ£º¼ì²éÊÇ·ñûÓÐÉú³É·ÓÉÆ÷¹«Ô¿
ÔÚ·ÓÉÆ÷ÉÏʹÓÃshow crypto key mypubkey dsaºÍshow crypto key mypubkey rsaÃüÁ¿´¿´ÊÇ·ñÉú³ÉÁË·ÓÉÆ÷µÄ¹«Ô¿£¨Á½¸öÃüÁîÖÐÓÐÒ»¸öÄÜÏÔʾ¹«Ô¿¼´¿É£©
ÈôÈçͼrsaºÍdsa¶¼Êǿյģ¬ÐèÒª´´½¨dsa»òÕßrsaµÄ¹«Ô¿
1£©´´½¨dsa¹«Ô¿µÄ·½Ê½
2£©´´½¨rsa¹«Ô¿µÄ·½Ê½
²½ÖèÈý£º¼ì²éÊÇ·ñvtyÏß·ûÓзÅͨSSHµÇ¼µÄ·½Ê½
ʹÓÃÃüÁîshow run | be line v ²é¿´Êä³öÖÐÊÇ·ñûÓзÅͨssh
Èôδ·Åͨssh£¬¿ÉÒÔ¿ªÆôvtyÏß·µÄssh£¬ÃüÁîÈçÏÂͼ£º
¿ªÆôsshºó£¬line vty 0 4Ͻ«²»»áÓÐtransportµÄ¹Ø¼ü×ÖÏÔʾ
²½ÖèËÄ£º¼ì²éÊÇ·ñÕýÈ·ÅäÖÃÁËSSHÕ˺ÅÃÜÂë
1£©±¾µØÕ˺ÅÃÜÂ뷽ʽÈÏÖ¤
ʹÓÃÃüÁîshow run | be line v ²é¿´line vtyµÄÅäÖÃÖÐÊÇ·ñÅäÖÃlogin local£¬ÈôΪlogin local£¬ÐèҪʹÓÃshow run | in rnameºÍshow run | in enable p·Ö±ð¼ì²éÕ˺ÅÃÜÂëºÍenableÃÜÂëÊÇ·ñÅäÖá£
×¢Ò⣺SSH²»ÍƼöÓõ¥´¿ÃÜÂëÎÞÕ˺ŵķ½Ê½µÇ¼¡£
2£©AAAÕ˺ÅÃÜÂ뷽ʽÈÏÖ¤
ʹÓÃÃüÁîshow run | in aaa¼ì²éÊÇ·ñ¿ªÆôÁËAAAµÄµÇ¼ÈÏÖ¤¡£Èç¹û¿ªÆôÁËAAAµÄµÇ¼ÈÏÖ¤£¬Ä¬ÈϽ«²ÉÓÃAAA·þÎñÆ÷½øÐеǼÕ˺ÅÃÜÂëУÑé¡£
¢ÙÈôÏëÒª±¾µØÈÏÖ¤£¬ÐèÒª¼ì²éÊÇ·ñÅäÖÃÁËĬÈϵ÷ÓõÄdefaultÈÏÖ¤ÁÐ±í£¨ÈôÐè·ÇdefaultÈÏÖ¤ÁÐ±í£¬ÐèÒªline vty µ×ÏÂʹÓÃlogin authentication ÈÏÖ¤ÁбíÃû³ÆÀ´ÊµÏÖ£©£¬Ê¹ÓÃlocal±¾µØÕ˺ÅÃÜÂëÈÏÖ¤£¬²¢ÇÒÐèÒª¼ì²éÊÇ·ñÕýÈ·ÅäÖÃÁËÕ˺ÅÃÜÂë¡£
¢ÚÈôÏëÒªAAAÈÏÖ¤£¬ÐèʹÓÃÃüÁîshow run | in tac¼ì²éÊÇ·ñÅäÖõǼÈÏ֤ʹÓÃtacacs+·þÎñÆ÷£¬ÇÒÊÇ·ñ¶¨ÒåÁ˸Ãtacacs+·þÎñÆ÷¡£
Èô䶨Ò壬ÐèÐÞÕýÅäÖÃ
²½ÖèÎ壺¼ì²éÊÇ·ñSSHÁ÷Á¿Ã»Óе½Â·ÓÉÆ÷
ͨ¹ýÁ÷±í²é¿´ÊÇ·ñÊÕµ½Ô¶¶ËSSH¹ýÀ´µÄÁ÷Á¿
1£©Ê×ÏÈ¿ªÆôÁ÷±í¹¦ÄÜ£¨ÈÎÒâ½Ó¿Ú¿ªÆônat¼´¿É£©
R1(config)#interface loopback 0
R1(config-if-Loopback 0)#ip nat inside
R1(config-if-Loopback 0)#end
2£©Í¨¹ýÁ÷±í²é¿´SSH¶Ë¿ÚÊÇ·ñ¹ýÀ´
ÈçͼûÓп´µ½TCP 22¶Ë¿ÚµÄÁ÷Á¿µ½Â·ÓÉÆ÷£¬ÐèҪʹÓÃshow run | in ip fpmÃüÁî¼ì²éÊÇ·ñ´æÔÚÁ÷¹ýÂËÅäÖá£
Èô²»´æÔÚ£¬Ðè¼ì²éÖм价¾³ÎÊÌ⣬Á÷Á¿Ã»µ½Â·ÓÉÆ÷¡£
Èô´æÔÚ£¬ÐèÒª¼ì²é¶ÔÓ¦Á÷¹ýÂËACLÖÐÊÇ·ñ¹ýÂËÁË22¶Ë¿Ú»òÕßÊÇ·ñûÓзÅͨ22¶Ë¿Ú¡£
Èô¹ýÂËÁËTCP 22¶Ë¿Ú£¬ÐèÒª·Åͨ¸Ã¶Ë¿Ú£»
ÈôTCP 22¶Ë¿ÚÓб»·Åͨ£¬Ã»±»¹ýÂË£¬ÔòÐèÒª¼ì²éÖм价¾³ÎÊÌâ¡£
²½ÖèÁù£º¼ì²éÊÇ·ñ·ÓÉÆ÷½Ó¿ÚACL¹ýÂË
·ÓÉÆ÷ÉÏͨ¹ýshow access-groupÃüÁî²é¿´ÊÇ·ñ´æÔÚ¶ÔÓ¦ssh½Ó¿ÚµÄACL¹ýÂË£¬
Èô´æÔÚ£¬ÔòÐèÒª¼ì²é¶ÔÓ¦½Ó¿ÚµÄACLÊÇ·ñ¹ýÂËÁËTCP22¶Ë¿Ú
ÈçÉÏͼ£¬Ã»ÓÐTCP 22Á÷Á¿±»¹ýÂË¡£
Èô±»¹ýÂË£¬ÐèÒªACLÖзÅÐÐÄ¿µÄ¶Ë¿ÚΪTCP 22µÄÁ÷Á¿¡£
²½ÖèÆß£º¼ì²éÊÇ·ñ·ÓÉÆ÷ûÓлسÌ·ÓÉ
·ÓÉÆ÷ÉÏͨ¹ýshow ip routeÃüÁî¼ì²éÊÇ·ñÓÐÈ¥Íù¶ÔÓ¦SSH·¢ÆðÕßIPµÄ·ÓÉ
Èç±¾ÀýÖÐSSH·¢ÆðÕßµÄIPÊÇ172.26.10.38£¬Â·ÓÉÆ÷ÓÐĬÈÏ·Óɻذü¡£
ÈôûÓлذü·ÓÉ£¬ÐèÒª¼ÓÉÏÏàÓ¦µÄ·ÓÉ¡£
²½Öè°Ë£º¼ì²éÊÇ·ñvtyÏß·ÂúÁË
Line vty 0 4´ú±íÓÐ0-4Ò²¾ÍÊÇ5¸össhÏß·¿ÉÒԵǼÉ豸£¬ÈôÕâЩÏß·ÂúÁË»á³öÏÖÎÞ¿ÕÏÐÏß·¿ÉµÇ¼·ÓÉÆ÷µÄÇé¿ö¡£Í¨¹ýshow usersÃüÁî¿ÉÒԲ鿴Óм¸¸öÏß·±»Õ¼ÓÃ
Èô·¢ÏÖÏß·±»Õ¼Âú£¬ÐèÒªÌßÓû§ÏÂÏߣ¬¿ÉÒÔclear line vty [Óû§±àºÅ]£¬±¾ÀýÖÐΪclear line vty 0
Èô·¢ÏÖÏß·²»×ãÈÕ³£Ê¹Ó㬿ÉÒÔ¸ÄΪline vty 0 32£¬Ôö¼ÓvtyÏß·¡£
Îå¡¢ÐÅÏ¢ÊÕ¼¯
ÐÅÏ¢ÊÕ¼¯ÃüÁî²Î¿¼
ter len 0
show ver
show slot
show ver slot
show run
show log
show cpu
show memory
show ip fpm count
show ip fpm st
show ip route
show ip ref route
show ip ref adj
show ip route summary
show arp
show ip int brief
show interface
show service
show crypto key mypubkey dsa
show crypto key mypubkey rsa
show run | be line v
show run | in rname
show run | in enable p
show run | in aaa
show run | in tac
show run | in ip fpm
show access-group
show ssh
show users
ter no len
Áù¡¢×ܽáÓ뽨Òé
SSHµÇ¼²»ÉϵÄÎÊÌ⣬Ðè×¢ÒâÒÔϼ¸µã£º
- ûÓпªÆôSSH·þÎñ£»
- ûÓÐÉú³É·ÓÉÆ÷¹«Ô¿£»
- vtyÏß·ûÓзÅͨSSHµÇ¼µÄ·½Ê½£»
- ûÓÐÕýÈ·ÅäÖÃSSHÕ˺ÅÃÜÂë
- Á÷Á¿Ã»Óе½Â·ÓÉÆ÷£»
- ·ÓÉÆ÷ACL¹ýÂË
- ·ÓÉÆ÷ûÓлسÌ·ÓÉ
- vtyÏß·Âú
ÈçÓöµ½¹ÊÕÏÇéÐÎÒÔÉÏ·½Ê½ÎÞ·¨½â¾ö¿Éµã»÷Á´½Ó´¦Àí£ºÊÛºóÉÁµçÍÃ