Users Guide

Table Of Contents
secadmin 访访AAA
netadmin ACL访访
netoperator 访 EXEC
OS10(config)# userrole default inherit sysadmin
RADIUS TACACS+
OS10(config)# userrole tacacsadmin inherit netadmin
SSH
OS10 shell SSH 访 OS10 SSH 使 RADIUS /
SSH
SSH 使 no ip ssh server enable SSH
使 ip ssh server challenge-response-authentication
使 ip ssh server hostbased-authentication
使 no ip ssh server password-authentication
使 no ip ssh server pubkey-authentication
使使 username sshkey username sshkey filename
使 ip ssh server cipher cipher-list
使 ip ssh server kex key-exchange-algorithm
使 ip ssh server mac hmac-algorithm (HMAC)
使 ip ssh server port port-number SSH
使 ip ssh server vrf SSH VRF 访
使 ip ssh server login-grace-time seconds SSH 0 300 60
SSH 使 no ip ssh server login-grace-time
使 ip ssh server max-auth-tries number 0 10 6
使 no ip ssh server max-auth-tries
max-auth-tries
max-auth-tries 1 ip
ssh server max-auth-tries 1
SSH
RivestShamir Adelman (RSA) 使 2048
线 (ECDSA) 使 256
Ed25519 使 256
: OS10 SSH RSA1 DSA
SSH OS10 SSH 使 SSH
使 Ed25519 crypto key generate sysadmin secadmin
1. EXEC SSH
crypto ssh-key generate {rsa {2048|3072|4096} | ecdsa {256|384|521} | ed25519}
2. yes
Host key already exists. Overwrite [confirm yes/no]:yes
Generated 2048-bit RSA key
908