Configuring Ssh; Configuration Guidelines; Setting Up The Ml-Series Card To Run Ssh - Cisco ONS 15454 SDH Configuration Manual

Hide thumbs Also See for ONS 15454 SDH:
Table of Contents

Advertisement

Chapter 19 Configuring Security for the ML-Series Card
The SSH server enables a connection into the ML-Series card, similar to an inbound Telnet connection,
but with stronger security. Before SSH, security was limited to the native security in Telnet. SSH
improves on this by allowing the use of Cisco IOS software authentication.
The ONS node also supports SSH. When SSH is enabled on the ONS node, you use SSH to connect to
the ML-Series card for Cisco IOS CLI sessions.
Note
Telnet access to the ML-Series card is not automatically disabled when SSH is enabled. The user can
disable Telnet access with the vty line configuration command transport input ssh.

Configuring SSH

This section has this configuration information:

Configuration Guidelines

Follow these guidelines when configuring the ML-Series card as an SSH server:

Setting Up the ML-Series Card to Run SSH

Follow these steps to set up your ML-Series card to run as an SSH server:
1.
2.
3.
Beginning in privileged EXEC mode, follow these steps to configure a hostname and an IP domain name
and to generate an RSA key pair.
Configuration Guidelines, page 19-3
Setting Up the ML-Series Card to Run SSH, page 19-3
Configuring the SSH Server, page 19-4
The new model of AAA and a AAA login method must be enabled. If not previously enabled,
complete the
"Configuring AAA Login Authentication" section on page
A Rivest, Shamir, and Adelman
SSHv2 server, and the reverse.
If you get CLI error messages after entering the crypto key generate rsa global configuration
command, an RSA key pair has not been generated. Reconfigure the hostname and domain, and then
enter the crypto key generate rsa command. For more information, see the
ML-Series Card to Run SSH" section on page
When generating the RSA key pair, the message
you must configure a hostname by using the hostname global configuration command.
When generating the RSA key pair, the message
must configure an IP domain name by using the ip domain-name global configuration command.
Configure a hostname and IP domain name for the ML-Series card.
Generate an RSA key pair for the ML-Series card, which automatically enables SSH.
Configure user authentication for local or remote access. This step is required.
Cisco ONS 15454 and Cisco ONS 15454 SDH Ethernet Card Software Feature and Configuration Guide, R8.0
(required)
(required)
(
RSA) key pair generated by a SSHv1 server can be used by an
19-3.
No host name specified
No domain specified
Configuring SSH
19-11.
"Setting Up the
might appear. If it does,
might appear. If it does, you
19-3

Advertisement

Table of Contents
loading

This manual is also suitable for:

Ons 15454

Table of Contents