beautypg.com

H3C Technologies H3C S6300 Series Switches User Manual

Page 294

background image

279

In an insecure network, H3C recommends that you configure the server's host public key on the device.
After the connection is established, you can directly enter SFTP client view on the server to perform
operations, such as working with directories or files.
To establish a connection to an SFTP server:

Task Command

Remarks

Establish a
connection to an

SFTP server.

In non-FIPS mode, establish a connection to an IPv4 SFTP
server:

sftp server [ port-number ] [ identity-key { dsa | ecdsa |

rsa } | prefer-compress zlib | prefer-ctos-cipher { 3des |
aes128 | aes256 | des } | prefer-ctos-hmac { md5 |

md5-96 | sha1 | sha1-96 } | prefer-kex

{ dh-group-exchange | dh-group1 | dh-group14 } |
prefer-stoc-cipher { 3des | aes128 | aes256 | des } |

prefer-stoc-hmac { md5 | md5-96 | sha1 | sha1-96 } ] *

[ dscp dscp-value | publickey keyname | source
{ interface interface-type interface-number | ip

ip-address } ] *

In FIPS mode, establish a connection to an IPv4 SFTP
server:

sftp server [ port-number ] [ identity-key { ecdsa | rsa } |

prefer-compress zlib | prefer-ctos-cipher { aes128 |

aes256 } | prefer-ctos-hmac { sha1 | sha1-96 } |
prefer-kex dh-group14 | prefer-stoc-cipher { aes128 |

aes256 } | prefer-stoc-hmac { sha1 | sha1-96 } ] *

[ publickey keyname | source { interface interface-type
interface-number
| ip ip-address } ] *

In non-FIPS mode, establish a connection to an IPv6 SFTP

server:
sftp ipv6 server [ port-number ] [ -i interface-type

interface-number ] [ identity-key { dsa | ecdsa | rsa } |

prefer-compress zlib | prefer-ctos-cipher { 3des |
aes128 | aes256 | des } | prefer-ctos-hmac { md5 |

md5-96 | sha1 | sha1-96 } | prefer-kex

{ dh-group-exchange | dh-group1 | dh-group14 } |
prefer-stoc-cipher { 3des | aes128 | aes256 | des } |

prefer-stoc-hmac { md5 | md5-96 | sha1 | sha1-96 } ] *

[ dscp dscp-value | publickey keyname | source
{ interface interface-type interface-number | ipv6

ipv6-address } ] *

In FIPS mode, establish a connection to an IPv6 SFTP

server:

sftp ipv6 server [ port-number ] [ -i interface-type

interface-number ] [ identity-key { ecdsa | rsa } |
prefer-compress zlib | prefer-ctos-cipher { aes128 |

aes256 } | prefer-ctos-hmac { sha1 | sha1-96 } |

prefer-kex dh-group14 | prefer-stoc-cipher { aes128 |
aes256 } | prefer-stoc-hmac { sha1 | sha1-96 } ] *

[ publickey keyname | source { interface interface-type

interface-number | ipv6 ipv6-address } ] *

Available in user view.
The ecdsa keyword is

available in Release
2311P04 and later

versions.