資源描述:
《華為交換機vty用戶界面屬性配置教程》由會員上傳分享,免費在線閱讀,更多相關(guān)內(nèi)容在行業(yè)資料-天天文庫。
1、華為交換機VTY用戶界面屬性配置教程用戶通過Telnet或SSH方式登錄設(shè)備實現(xiàn)本地或遠程維護時,可以根據(jù)用戶使用需求以及對設(shè)備安全的考慮來配置VTY,除對VTY類型用戶界面呼入呼出進行限制的ACL號、用戶名和口令及用戶界面的驗證方式外其他參數(shù)設(shè)備均有缺省值,用戶可以結(jié)合實際需求和安全性考慮選擇配置。1、設(shè)置通過賬號和密碼登陸VTY界面1.1、進入VTY用戶界面視圖[Huawei]user-interfacevty??INTEGER<0-4,16-20>?Thefirstuserterminalinterfacetobeconfigured?[Huawei]user-inter
2、facevty04[Huawei-ui-vty0-4]?1.2、設(shè)置用戶驗證方式為AAA驗證(即通過賬號和密碼登陸)[Huawei-ui-vty0-4]authentication-mode??aaa??????AAAauthentication?none?????Loginwithoutchecking?password?Authenticationthroughthepasswordofauserterminalinterface?[Huawei-ui-vty0-4]authentication-modeaaa?1.3、設(shè)置登陸的賬號和密碼[Huawei-ui-vty0-4
3、]q[Huawei]aaa[Huawei-aaa]local-user??STRING<1-64>??Username,informof'user@domain'.Canusewildcard'*',????????????????whiledisplayingandmodifying,suchas*@isp,user@*,*@*.Can????????????????notincludeinvalidcharacter/:*?"<>
4、@'?[Huawei-aaa]local-user023wg.com??access-limit??Setaccesslimitofuser(
5、s)?ftp-directory?Setuser(s)FTPdirectorypermitted?idle-timeout??Setthetimeoutperiodforterminaluser(s)?password??????Setpassword?privilege?????Setadminuser(s)level?service-type??Servicetypesforauthorizeduser(s)?state?????????Activate/Blocktheuser(s)?user-group????Usergroup?[Huawei-aaa]local-us
6、er023wg.compassword??cipher?Userpasswordwithciphertext?[Huawei-aaa]local-user023wg.compasswordcipherwww.023wg.com?1.4、設(shè)置賬號的使用類型為Telnet或SSH[Huawei-aaa]local-user023wg.comservice-typetelnet或[Huawei-aaa]local-user023wg.comservice-typessh?2、設(shè)置只通過密碼登陸VTY2.1、置用戶驗證方式為密碼驗證[Huawei-ui-vty0-4]authentic
7、ation-modepassword?2.2、設(shè)置登陸密碼[Huawei-ui-vty0-4]setauthenticationpasswordcipher??STRING<1-16>/<24>?Plaintext/ciphertextpassword?[Huawei-ui-vty0-4]setauthenticationpasswordcipherwww.023wg.com?3、設(shè)置直接登陸VTY(此模式不安全)[Huawei-ui-vty0-4]authentication-modenone?4、配置VTY用戶界面的用戶優(yōu)先級缺省情況下,VTY用戶界面對應(yīng)的默認命令訪問級別
8、是0,實際工作如果對權(quán)限要求不是特別嚴格,一本設(shè)置為15級。[Huawei-ui-vty0-4]userprivilegelevel??INTEGER<0-15>?Setapriority?[Huawei-ui-vty0-4]userprivilegelevel15?5、啟用VTY終端服務(wù)[Huawei-ui-vty0-4]shell?6、設(shè)置用戶超時斷連時間[Huawei-ui-vty0-4]idle-timeout??INTEGER<0-35791>?Setthenumberofminu