Admin Guide

Table Of Contents
Variable Value
Important:
You cannot configure the TCP port 6000 as SSH connection port.
rsa-auth Enables RSA authentication. The default is enabled.
Use the no operator before this parameter, no ssh rsa-auth, to disable
RSA authentication.
rsa-host-key [<1024–2048>] Generates a new SSH RSA host key. Specify an optional key size of 1024
or 2048. The RSA host key can only be in a multiple of 1024. The default is
2048.
Use the no operator before this parameter, no ssh rsa-host-key, to
disable SSH RSA host key.
rsa-user-key WORD<1–15> Generates a new SSH RSA user key. WORD<1–15> specifies the user
access level.
You must enable SSH globally before you can generate SSH DSA user
keys.
If enhanced secure mode is disabled, the valid user access levels for the
switch are:
rwa — Specifies read-write-all.
rw — Specifies read-write.
ro — Specifies read-only.
rwl1 — Specifies read-write for Layer 1.
rwl2 — Specifies read-write for Layer 2.
rwl3 — Specifies read-write for Layer 3.
If you enable enhanced secure mode, the switch uses role-based
authentication. You associate each username with a specific role and the
appropriate authorization rights to commands based on that role.
If enhanced secure mode is enabled, the value user access levels for the
switch are:
admin—Specifies a user role with access to all of the configurations,
show commands, and the ability to view the log file and security
commands. The administrator role is the highest level of user roles.
operator—Specifies a user role with access to all of the configurations for
packet forwarding on Layer 2 and Layer 3, and has access to show
commands to view the configuration, but cannot view the audit logs and
cannot access security and password commands.
auditor—Specifies a user role that can view log files and view all
configurations, except password configuration.
security—Specifies a user role with access only to security settings and
the ability to view the configurations.
Table continues…
Secure Shell configuration using ACLI
January 2017 Administering Avaya VSP 7200 Series and 8000 Series 165
Comments on this document? infodev@avaya.com