To do… | Use the command… | Remarks |
| Enter the default |
| |
| ISP domain | domain | |
| view |
| |
|
|
| |
| Apply the | authentication default | |
| { | ||
| specified AAA | ||
| |||
| scheme to the | ||
| local none | ||
Configure the | domain | ||
| |||
authentication |
|
| |
|
| ||
mode |
|
| |
| Exit to system | quit | |
| view | ||
|
|
Optional
By default, the AAA scheme is local.
If you specify the local AAA scheme, perform the configuration concerning local user as well. If you specify an existing scheme by providing the
•For RADIUS and HWTACACS configuration, see the Security Configuration Guide.
•Configure the username and password on the AAA server. (For more information, see the Security Configuration Guide.)
Create a local user and enter local | Required | ||
user view | By default, no local user exists. | ||
| |||
|
|
| |
| password { cipher simple } | Required | |
Set the local password | By default, no local password is | ||
password | |||
| set. | ||
|
| ||
|
|
| |
Specify the command level of the | Optional | ||
local user | By default, the command level is 0. | ||
| |||
|
|
| |
Specify the service type for the |
| Required | |
By default, no service type is | |||
local user | |||
| specified. | ||
|
| ||
|
|
| |
Return to system view | quit | — | |
|
|
| |
| ssh user username | Required | |
Create an SSH user, and specify | stelnet | ||
By default, no SSH user exists, and | |||
the authentication mode for the | { password { any | ||
no authentication mode is | |||
SSH user | |||
specified. | |||
| assign publickey keyname } | ||
|
| ||
|
|
| |
Configure common settings for VTY |
| Optional | |
— | See “Configuring common settings | ||
user interfaces | |||
| for VTY user interfaces (optional).” | ||
|
| ||
|
|
| |
|
|
|
NOTE:
This chapter describes how to configure an SSH client by using password authentication. For more information about SSH and how to configure an SSH client by using publickey, see the Security Configuration Guide.
After you enable command authorization or command accounting, you need to perform the following configuration to make the function take effect:
•Create a HWTACACS scheme, and specify the IP address of the authorization server and other authorization parameters.
50