Admin Guide

Table Of Contents
SSH server SSH client side SSH server side
privilege —/intflash/.ssh/id_dsa_priv
(private key), /intflash/.ssh/
id_dsa_priv.pub (public key)
Linux with Open SSH ~/.ssh/id_dsa (private key) file
permission 400
~/.ssh/id_dsa.pub (public key) file
permission 644
~/.ssh/authorized_keys (public key) file
ERS 8600/8800 /flash/.ssh/dsa_key_rwa (public key)
When you attempt to make an SSH connection from the VSP modular switch, the SSHv2 client
looks in its own internal flash for the public key pair files. If the key files exist, the SSHv2 client
prompts you for the passphrase to decrypt the key files. If the passphrase is correct, the SSHv2
client initiates the DSA key authentication to the remote SSHv2 server. The SSHv2 client looks for
the login user access level public key file on the SSHv2 server to process and validate the public
key authentication. If the DSA authentication is successful, then the SSHv2 session is established.
If no matching user key pair files exist on the client side when initiating the SSHv2 session, or if the
DSA authentication fails, you are automatically prompted for a password to attempt password
authentication.
If the remote SSHv2 server is a Linux system, the server looks for the login user public key file
~/.ssh/authorized_keys by default for DSA authentication. For Linux SSH client, the user DSA key
pair files are located in the user home directory as ~/.ssa/id_dsa and ~/.ssa/id_dsa.pub.
Block SNMP
The boot flag setting for block-snmp (boot config flags block-snmp) and the runtime
configuration of SSH secure (ssh secure) each modify the block-snmp boot flag. If you enable
SSH secure mode, the system automatically sets the block-snmp boot flag to true; the change takes
effect immediately. After enabling SSH in secure mode, you can manually change the block-snmp
flag to false to allow both SSH and SNMP access.
Important:
The block flag setting for block-snmp blocks Simple Network Management Protocol (SNMP)v1,
SNMPv2, and SNMPv3.
SCP command
Avaya recommends that you use short file names with the Secure CoPy (SCP) command. The
entire SCP command, including all options, user names, and file names must not exceed 80
characters. Avaya supports incoming SCP connections to the device but does not support outgoing
connections using an SCP client from the device
Third-party SSH and SCP client software
The following table describes the third-party SSH and SCP client software that has been tested but
is not included with this release.
Secure Shell
January 2017 Administering Avaya VSP 7200 Series and 8000 Series 154
Comments on this document? infodev@avaya.com