ƵµÀÖ±´ï - רÌâ - ÐÂÎÅ - ¼¼ÇÉ - ×éÍø - ¿ª·¢ - °²È« - web±à³Ì - ͼÏñ - ²Ù×÷ϵͳ - Êý¾Ý¿â - ½ÌÓý - ÂÃÓÎ - ½¡¿µ - ʱÉÐ - Çý¶¯ - Èí¼þ - ÓÎÏ· - ¶àýÌå - ERP - ÌÖÂÛ×é

SSH ʵս

À´Ô´£ºChinaITLab ×÷Õߣº ³ö´¦£ºÇÉÇɶÁÊé 2006-04-09 ½øÈëÌÖÂÛ×é

¡¡¡¡Ê¹ÓÃtelnet½øÐÐÔ¶³ÌÉ豸ά»¤µÄʱºò£¬ÓÉÓÚÃÜÂëºÍͨѶ¶¼ÊÇÃ÷Îĵģ¬Ò×ÊÜsnifferÕìÌý£¬ËùÒÔÓ¦²ÉÓÃSSHÌæ´útelnet¡£SSH (Secure Shell)·þÎñʹÓÃtcp 22 ¶Ë¿Ú£¬¿Í»§¶ËÈí¼þ·¢ÆðÁ¬½ÓÇëÇóºó´Ó·þÎñÆ÷½ÓÊܹ«Ô¿£¬Ð­É̼ÓÃÜ·½·¨£¬³É¹¦ºóËùÓеÄͨѶ¶¼ÊǼÓÃܵġ£
Cisco É豸Ŀǰֻ֧³ÖSSH v1£¬²»Ö§³Öv2¡£CiscoʵÏÖ SSHµÄÄ¿µÄÔÚÓÚÌṩ½Ï°²È«µÄÉ豸¹ÜÀíÁ¬½Ó£¬²»ÊÊÓÃÓÚÖ÷»úµ½Ö÷»úµÄͨѶ¼ÓÃÜ¡£CiscoÍÆ¼öʹÓÃIPSEC×÷Ϊ¶Ë¶Ô¶ËµÄͨѶ¼ÓÃܽâ¾ö·½°¸¡£

1.IOSÉ豸(Èç6500 MSFC¡¢8500¡¢7500)µÄÅäÖãº

a) Èí¼þÐèÇó

IOS°æ±¾12.0.(10)S ÒÔÉÏ º¬IPSEC 56 Feature

ÍÆ¼öʹÓà IOS 12.2 IP PLUS IPSEC 56CÒÔÉϰ汾

»ù±¾ÉÏCiscoȫϵÁзÓÉÆ÷¶¼ÒÑÖ§³Ö£¬µ«ÎªÔËÐÐÖ¸¶¨°æ±¾µÄÈí¼þÄú¿ÉÄÜÐèÒªÏàÓ¦µØ½øÐÐÓ²¼þÉý¼¶

b) ¶¨ÒåÓû§

user mize pass nnwh@163.net

d) ¶¨ÒåÓòÃû

ip domain-name mize.myrice.com //ÅäÖÃSSH±ØÐè

e) Éú³ÉÃÜÔ¿

crypto key generate rsa modulus 2048

Ö´Ðнá¹û£º

The name for the keys will be: 6509-mize.myrice.com

% The key modulus size is 2048 bits

Generating RSA keys ...

[OK]

f)Ö¸¶¨¿ÉÒÔÓÃSSHµÇ¼ϵͳµÄÖ÷»úµÄÔ´IPµØÖ·

access-list 90 remark Hosts allowed to SSH in //µÍ°æ±¾¿ÉÄܲ»Ö§³Öremark¹Ø¼ü×Ö

access-list 90 permit 10.10.1.100

access-list 90 permit 10.10.1.101

g) ÏÞÖÆµÇ¼

line con 0

login local

line vty 0 4

login local //ʹÓñ¾µØ¶¨ÒåµÄÓû§ÃûºÍÃÜÂëµÇ¼

transport input SSH //Ö»ÔÊÐíÓÃSSHµÇ¼(×¢Ò⣺½ûÖ¹telnetºÍ´Ó½»»»ÒýÇæsession!)

access-class 90 in //Ö»ÔÊÐíÖ¸¶¨Ô´Ö÷»úµÇ¼

2.CatOS(Èç6500/4000½»»»ÒýÇæ)µÄÅäÖãº

a) Èí¼þÐèÇó

ÔËÐÐCatOSµÄ6500/4000½»»»ÒýÇæÌṩSSH·þÎñÐèÒªÒ»¸ö6.1ÒÔÉÏ¡°k9¡±°æ±¾µÄÈí¼þ£¬Èç: cat6000-sup2cvk9.7-4-3.bin ºÍ cat4000-k9.6-3-3a.bin.

8540/8510½»»»»úÖ§³ÖSSHÐèÒªÒÔÉÏ12.1(12c)EY°æ±¾Èí¼þ¡£

3550½»»»»úÖ§³ÖSSHÐèÒª12.1(11)EA1ÒÔÉϰ汾Èí¼þ¡£

ÆäËû½»»»»ú¿ÉÄܲ»Ö§³ÖSSH¡£

b) Éú³ÉÃÜÔ¿

set crypto key rsa 2048

ÃÜÔ¿µÄÉú³ÉÐèÒª1-2·ÖÖÓ£¬Ö´ÐÐÍê±Ïºó¿ÉÓÃÃüÁîshow crypto key²é¿´Éú³ÉµÄÃÜÔ¿¡£

c) ÏÞÖÆ¹ÜÀí¹¤×÷Õ¾µØÖ·

set ip permit 10.10.1.100 ssh //Ö»ÔÊÐíʹÓÃSSHµÇ¼µÄ¹¤×÷Õ¾

set ip permit 10.10.1.101 ssh

set ip permit enable ssh //¼ì²éSSHÁ¬½ÓµÄÔ´µØÖ·

set ip permit enable telnet //¼ì²ételnetÁ¬½ÓµÄÔ´µØÖ·

set ip permit enable snmp //¼ì²ésnmpÇëÇóµÄÔ´µØÖ·

Èç¹û·þÎñµÄip permit ´¦ÓÚdisable״̬£¬ËùÓеÄÁ¬½Ó½«±»ÔÊÐí£¨µ±È»·þÎñÈçtelnet±¾Éí¿ÉÄܰüº¬Óû§ÈÏÖ¤»úÖÆ£©¡£Èç¹ûÖ¸¶¨·þÎñµÄip permit ´¦ÓÚenable״̬£¬Ôò¹ÜÀí¹¤×÷Õ¾µÄµØÖ·±ØÐëÊÂÏÈÓÃset ip permit <¹ÜÀí¹¤×÷Õ¾IPµØÖ·> [¿ÉÑ¡µÄ×ÓÍøÑÚÂë] [ÔÊÐíʹÓõķþÎñÀàÐÍ(ssh/telnet/snmp)]À´¶¨Òå

¿ÉÓÃÃüÁî show ip permit À´¼ì²éip permit µÄÅäÖÃ

ijЩ·þÎñ¿ÉÄÜ´æÔÚ°²È«Â©¶´£¨Èçhttp£©»òЭÒé±¾ÉíÉè¼Æ¾ÍÊDZȽϲ»°²È«µÄ£¨Èçsnmp¡¢telnet£©¡£Èç¹û·þÎñ²»ÊDZØÒªµÄ£¬¿ÉÒÔ½«Ö®¹Ø±Õ£»Èç¹û·þÎñÊDZØÐëµÄ£¬Ó¦²ÉÈ¡´ëÊ©±£Ö¤ÕâЩ·þÎñ½öÏòºÏ·¨Óû§Ìṩ:

6500/4000½»»»ÒýÇæ£º

set ip http server disable //¹Ø±Õhttp·þÎñ

set ip permit enable snmp //ÏÞÖÆSNMPÔ´µØÖ·

set snmp comm. read-only //Çå¿ÕÔ¤ÉèµÄSNMP COMM×Ö

set snmp comm. read-write

set snmp comm. read-write-all

8500¡¢7500¡¢MSFCµÈIOSÉ豸£º

no ip http server //¹Ø±Õhttp·þÎñ

no snmp //¹Ø±Õsnmp·þÎñ

no service dhcp //¹Ø±Õ dhcp ·þÎñ

no ip finger //¹Ø±Õ finger ·þÎñ

no service tcp-small-server //¹Ø±Õtcp»ù±¾·þÎñ

no service udp-small-server //¹Ø±Õ udp»ù±¾·þÎñ

service password-encryption //ÆôÓÃÃ÷ÎÄÃÜÂë¼ÓÃÜ·þÎñ

3.SSH ¿Í»§¶Ë

a) ´Ó¹ÜÀí¹¤×÷Õ¾µÇ¼

±ØÐëʹÓÃÖ§³ÖSSH v1ЭÒéµÄÖÕ¶Ë·ÂÕæ³ÌÐò²ÅÄÜʹÓÃSSHЭÒé¹ÜÀíÉ豸£¬ÍƼöʹÓÃSecure CRT 3.3, Ò²¿ÉÒÔʹÓÃÃâ·ÑÈí¼þputty.ÏÂÃæ½éÉÜʹÓÃSecure CRTµÇ¼SSHÉ豸µÄ·½·¨£º

ÔËÐÐSecure CRT³ÌÐò£¬Ñ¡Ôñ²Ëµ¥File ¨C Quick Connect¡­ÉèÖÃÒÔϲÎÊý£ºProtocol(ЭÒé): ssh1 Hostname(Ö÷»úÃû): 10.10.1.1 Port(¶Ë¿Ú): 22 Username(Óû§Ãû): mize Ciper(¼ÓÃÜ·½·¨): 3DES Authentication(ÈÏÖ¤·½Ê½)assword µã»÷Connect£¬Õâʱ¿ÉÄÜ»áÌáʾÄú½ÓÊÜÀ´×ÔÉ豸µÄ¼ÓÃܹ«Ô¿£¬Ñ¡ÔñAccept once(Ö»ÓÃÒ»´Î)»òAccept & Save (±£´æÃÜÔ¿ÒÔ±ãÏ´ÎʹÓÃ)¡£ÓÉÓÚЭÒéʵÏÖµÄÎÊÌ⣬¿ÉÄÜ»áÅöµ½SSH Buffer OverflowµÄÎÊÌ⣬Èç¹û³öÏÖ¡°ÊÕµ½´óÓÚ16kµÄÃÜÔ¿¡±µÄÌáʾ£¬ÇëÖØÐÂÁ¬½Ó¡£Á¬½ÓÕý³££¬ÊäÈëÃÜÂë¼´¿ÉµÇ¼µ½ÏµÍ³¡£

µÚ¶þ´ÎµÇ¼µã»÷File ¨C Connect µã»÷Á¬½Ó10.10.1.1¼´¿É¡£

b) ´ÓIOSÉ豸ÓÃSSHЭÒéµÇ¼ÆäËûÉ豸

IOSÉ豸Ҳ¿ÉÒÔ·¢ÆðSSHÁ¬½ÓÇëÇó(×÷ΪSSH Client)£¬´ÓIOSÉ豸µÇ¼֧³Ö3DESµÄIOSÉ豸£¬Ê¹ÓÃÒÔÏÂÃüÁî(-l Ö¸¶¨Óû§Ãû)£º

ssh ¨Cl mize 10.10.3.3

´ÓIOSÉ豸µÇ¼֧³Ö DES(56λ)µÄIOS£¬Ê¹ÓÃÒÔÏÂÃüÁî(-c desÖ¸¶¨1 des¼ÓÃÜ·½Ê½)£º

ssh ¨Cc des ¨Cl mize 10.10.5.5

´ÓIOSÉ豸µÇ¼֧³Ö 3DESµÄCatOS, Èç6509/4006µÄ½»»»ÒýÇæ£¬Ê¹ÓÃÈçÏÂÃüÁî(ÎÞÐèÖ¸¶¨Óû§Ãû)£º

ssh 10.10.6.6

4.ÏÞÖÆtelnetÔ´µØÖ·

¶ÔÓÚδ֧³ÖSSH µÄÉ豸£¬¿É²ÉÈ¡ÏÞÖÆtelnetÔ´µØÖ·µÄ·½·¨À´¼ÓÇ¿°²È«ÐÔ¡£ÎªÁ˲»ÖÂÓÚÔö¼ÓÒ»¸ö¹ÜÀíÔ±µØÖ·¾ÍÒª°ÑËùÓеÄÉ豸ÅäÖÃÐÞ¸ÄÒ»±é£¬¿ÉÒÔ²ÉÓÃÖмÌÉ豸µÄ·½·¨£¬¼´ÊÜ¿ØÉ豸ֻÔÊÐíÖмÌÉ豸µÄtelnet·ÃÎÊ£¬ÖмÌÉ豸ÔòÔÊÐí¶à¸ö¹ÜÀíÔ±ÒԽϰ²È«µÄ·½·¨£¨ÈçSSH£©µÇ¼¡£

ÉèÖÃÖмÌÉ豸:

inter lo 0

ip address 10.10.1.100 255.255.255.255

ip telnet source-interface Loopback0 //·¢ÆðtelnetµÄÔ´µØÖ·

ÉèÖÃÊÜ¿ØÉ豸£º

access-list 91 remark Hosts allowed to TELNET in

access-list 91 permit 10.10.1.100

access-list 91 permit 10.10.1.101

line con 0

password xxxxxxxx

line vty 0 4

password xxxxxxxx

access-class 91 inÕýÎÄ£ºhttp://www.qqread.com/net-saft/f111994508.html ¸ü¶àÎÄÕ ¸ü¶àÄÚÈÝÇë¿´SSH¼¼ÊõÊֲᡢSSH°²È«¼¼Êõ¡¢SSHÏà¹ØÎÄÕÂרÌ⣬»ò½øÈëÌÖÂÛ×éÌÖÂÛ¡£
¡¾ÊղشËÎÄ¡¿¡¾´ó ÖРС¡¿¡¾´òÓ¡¡¿¡¾¹Ø±Õ¡¿
½ÏÔçµÄÎÄÕ£ºSSLÓëTLS

½ÏеÄÎÄÕ£ºÈçºÎ²âÊÔSSHÊÇ·ñÕý³£¹¤×÷£¿
Ïà¹ØÍ¼ÎÄÔĶÁ
ƵµÀͼÎÄÍÆ¼ö
½¡ ¿µ ×É Ñ¯
ʱ ÉÐ ×É Ñ¯
ÇÉÇɶÁÊé×ÚÖ¼
Ïà¹Ø×¨Ìâ
ÌÖÂÛ×éÎÊÌâÍÆ¼ö
Õ¾ÄÚ¸÷ƵµÀ×îиüÐÂÎĵµ
Õ¾ÄÚ×îÐÂÖÆ×÷רÌâ
ÈÈÃŹؼü×Öµ¼¶Á
Photoshop½Ì ³Ì£ºÕÕÆ¬´¦Àí ÕÕÆ¬ÖÆ×÷ PS¿ì½Ý¼ü ¿Ùͼ
¼Æ Ëã »ú ¹Ê ÕÏ£ºXPϵͳÐÞ¸´
ÒÕ Êõ Óë Éè ¼Æ£ºÉè¼Æ Á÷ýÌå Éè¼ÆÐÀÉÍ ±ß¿ò
¼Æ Ëã »ú °² È«£ºARP
Õ¾ÄÚÆµµÀÎÄÕ¾«Ñ¡
ÇÉÇɵçÄÔÆµµÀ±à¼­ÐÅÏä  ¸æËßÎÒÃÇÄúÏë¿´µÄרÌâ»òÎÄÕÂ