Configuring ssh, Feature and hardware compatibility, Overview – H3C Technologies H3C SecPath F1000-E User Manual
Page 161: Ssh operation
150
Configuring SSH
Feature and hardware compatibility
Feature F1000-A-EI/E-SI/S-AI
F1000-E
F5000-A5 Firewall
module
FIPS
No No
No
Yes
Overview
Secure Shell (SSH) offers an approach to logging in to a remote device securely. By encryption and
strong authentication, it protects devices against attacks such as IP spoofing and plain text password
interception.
The device can not only work as an SSH server to support connections with SSH clients, but also work as
an SSH client to allow users to establish SSH connections with a remote device acting as the SSH server.
When acting as an SSH server, the device supports SSH2 and SSH1. In FIPS mode, the device supports
SSH2 only. When acting as an SSH client, the device supports SSH2 only.
Unless otherwise noted, SSH in this document refers to SSH2.
The term "router" in this document refers to both routers and Layer 3 firewalls.
NOTE:
The SSH2 configuration is available only at the CLI.
SSH operation
To establish an SSH connection and communicate with each other through the connection, an SSH client
and the SSH server go through the stages listed in
Table 27 Stages in session establishment and interaction between an SSH client and the server
Stages Description
SSH1 and SSH2 are supported. The two parties negotiate a version to
use.
SSH supports multiple algorithms. The two parties negotiate algorithms
for communication, and use the DH key exchange algorithm to generate
the same session key and session ID.
The SSH server authenticates the client in response to the client's
authentication request.
After passing authentication, the client sends a session request to the
server.
- H3C SecPath F5000-A5 Firewall H3C SecPath F1000-A-EI H3C SecPath F1000-E-SI H3C SecPath F1000-S-AI H3C SecPath F5000-S Firewall H3C SecPath F5000-C Firewall H3C SecPath F100-C-SI H3C SecPath F1000-C-SI H3C SecPath F100-A-SI H3C SecBlade FW Cards H3C SecBlade FW Enhanced Cards H3C SecPath U200-A U200-M U200-S H3C SecPath U200-CA U200-CM U200-CS