13.07.2015 Views

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Managing login permissionsSSH ConfigurationUse <strong>the</strong> ip ssh enable command to enable SSH au<strong>the</strong>ntication and set <strong>the</strong> SSH parameters.Use <strong>the</strong> no form <strong>of</strong> this command to disable <strong>the</strong> SSH server. Disabling <strong>the</strong> server disconnectsall active SSH sessions. By default, SSH is enabled.You can set <strong>the</strong> following SSH parameters using <strong>the</strong> ssh enable command:●timeout — sets <strong>the</strong> time interval (in seconds) that <strong>the</strong> SSH server waits for <strong>the</strong> SSHclient to respond. If this time elapses with no response, <strong>the</strong> session’s SSH serverdisconnects. The timeout can be from 20 to 400 seconds. The default value is 120.Note:Note:This parameter applies to <strong>the</strong> SSH negotiation phase. Once an SSH session isestablished, <strong>the</strong> CLI timeout applies.●●●●au<strong>the</strong>ntication-retries — <strong>the</strong> number <strong>of</strong> connection attempts after which <strong>the</strong> SSHserver disconnects. This parameter can be from 1 to 5. The default value is 3.rsa-au<strong>the</strong>ntication — enables (yes) or disables (no) <strong>the</strong> public key au<strong>the</strong>nticationmethod. By default, public key au<strong>the</strong>ntication is disabled.password-au<strong>the</strong>ntication — enables (yes) or disables (no) <strong>the</strong> passwordau<strong>the</strong>ntication method. By default, password au<strong>the</strong>ntication is enabled.port — changes <strong>the</strong> default value <strong>of</strong> <strong>the</strong> SSH port. Changing <strong>the</strong> port number does notinterrupt active connections. The default value is 22.Use <strong>the</strong> ssh-client known-hosts command to clear <strong>the</strong> client’s list <strong>of</strong> server fingerprints.Each client maintains a list <strong>of</strong> server fingerprints. If a key changes, <strong>the</strong> client’s verification <strong>of</strong> <strong>the</strong>server’s fingerprint will fail, <strong>the</strong>reby preventing <strong>the</strong> client’s access to <strong>the</strong> server. If this happens,you can use <strong>the</strong> ssh-client known-hosts command to erase <strong>the</strong> client’s server fingerprintlist. This enables <strong>the</strong> client to access <strong>the</strong> server and begin to recreate its list <strong>of</strong> fingerprints with<strong>the</strong> server’s new fingerprint.Use <strong>the</strong> crypto key generate dsa command to generate an SSH host key pair.Use <strong>the</strong> disconnect ssh command to disconnect an existing SSH session.Use <strong>the</strong> show ip ssh command to display a list <strong>of</strong> active SSH sessions.SCP protocol supportIn addition to data transfer via an SSH session, <strong>the</strong> SSH protocol is also used to support SCPfor secure file transfer. When using SCP, <strong>the</strong> <strong>G350</strong> is <strong>the</strong> client, and an SCP server must beinstalled on <strong>the</strong> management station. After users are defined on <strong>the</strong> SCP server, <strong>the</strong> <strong>G350</strong> actsas an SCP client.The process <strong>of</strong> establishing an SCP session is <strong>the</strong> same process as described in SSH protocolsupport on page 38, except that <strong>the</strong> roles <strong>of</strong> <strong>the</strong> <strong>G350</strong> and <strong>the</strong> client computer are reversed.Issue 3 January 2005 39

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!