Comware

 View Only
  • 1.  How to enable SSH on Comware

    Posted Feb 15, 2016 10:40 AM
     
    Boot ROM:
    142

    Software:
    V300R001B01D023SP25
     
     
     Trying to enable SSH by following different guides on the net. I.e. this:
     
    But it seams not to work. I can use http and https - but port 22 is not open on the switch for SSH. Where do I go wrong?
     
    Regards, Lars.

     


    #ssh


  • 2.  RE: How to enable SSH on Comware

    Posted Feb 15, 2016 01:35 PM

    What's your current config?



  • 3.  RE: How to enable SSH on Comware

    Posted Feb 16, 2016 05:59 AM

    #
    version 7.1.045, Release 3111P02
    #
    sysname SrvRack01
    #
    irf mac-address persistent timer
    irf auto-update enable
    undo irf link-delay
    irf member 1 priority 1
    #
    lldp global enable
    #
    password-recovery enable
    #
    vlan 1
    #
    vlan 203
    name SwitchMgmt
    #
    vlan 207
    description Mgmt
    #
    vlan 209
    #
    stp global enable
    #
    interface Bridge-Aggregation1
    description QNAP
    port access vlan 209
    link-aggregation mode dynamic
    #
    interface Bridge-Aggregation3
    description ESX03 iSCSI-backup
    port link-type trunk
    undo port trunk permit vlan 1
    port trunk permit vlan 209
    link-aggregation mode dynamic
    #
    interface Bridge-Aggregation4
    description ESX03 iSCSI-backup
    port link-type trunk
    undo port trunk permit vlan 1
    port trunk permit vlan 209
    port trunk pvid vlan 209
    link-aggregation mode dynamic
    #
    interface NULL0
    #
    interface Vlan-interface1
    #
    interface Vlan-interface203
    ip address 192.168.202.2 255.255.255.192
    #
    interface GigabitEthernet1/0/1
    port access vlan 209
    port link-aggregation group 1
    #
    interface GigabitEthernet1/0/2
    port access vlan 209
    port link-aggregation group 1
    #
    interface GigabitEthernet1/0/3
    #
    interface GigabitEthernet1/0/4
    #
    interface GigabitEthernet1/0/5
    port link-type trunk
    undo port trunk permit vlan 1
    port trunk permit vlan 209
    port link-aggregation group 3
    #
    interface GigabitEthernet1/0/6
    port link-type trunk
    undo port trunk permit vlan 1
    port trunk permit vlan 209
    port link-aggregation group 3
    #
    interface GigabitEthernet1/0/7
    port link-type trunk
    undo port trunk permit vlan 1
    port trunk permit vlan 209
    port trunk pvid vlan 209
    port link-aggregation group 4
    #
    interface GigabitEthernet1/0/8
    port link-type trunk
    undo port trunk permit vlan 1
    port trunk permit vlan 209
    port trunk pvid vlan 209
    port link-aggregation group 4
    #
    interface GigabitEthernet1/0/9
    #
    interface GigabitEthernet1/0/10
    #
    interface GigabitEthernet1/0/11
    #
    interface GigabitEthernet1/0/12
    #
    interface GigabitEthernet1/0/13
    #
    interface GigabitEthernet1/0/14
    #
    interface GigabitEthernet1/0/15
    port link-type trunk
    undo port trunk permit vlan 1
    port trunk permit vlan 209
    #
    interface GigabitEthernet1/0/16
    #
    interface GigabitEthernet1/0/17
    port access vlan 207
    #
    interface GigabitEthernet1/0/18
    port link-type trunk
    undo port trunk permit vlan 1
    port trunk permit vlan 209
    #
    interface GigabitEthernet1/0/19
    #
    interface GigabitEthernet1/0/20
    #
    interface GigabitEthernet1/0/21
    #
    interface GigabitEthernet1/0/22
    #
    interface GigabitEthernet1/0/23
    #
    interface GigabitEthernet1/0/24
    #
    interface GigabitEthernet1/0/25
    #
    interface GigabitEthernet1/0/26
    #
    interface GigabitEthernet1/0/27
    #
    interface GigabitEthernet1/0/28
    #
    interface GigabitEthernet1/0/29
    #
    interface GigabitEthernet1/0/30
    #
    interface GigabitEthernet1/0/31
    #
    interface GigabitEthernet1/0/32
    #
    interface GigabitEthernet1/0/33
    #
    interface GigabitEthernet1/0/34
    #
    interface GigabitEthernet1/0/35
    #
    interface GigabitEthernet1/0/36
    #
    interface GigabitEthernet1/0/37
    #
    interface GigabitEthernet1/0/38
    #
    interface GigabitEthernet1/0/39
    #
    interface GigabitEthernet1/0/40
    #
    interface GigabitEthernet1/0/41
    #
    interface GigabitEthernet1/0/42
    #
    interface GigabitEthernet1/0/43
    #
    interface GigabitEthernet1/0/44
    #
    interface GigabitEthernet1/0/45
    #
    interface GigabitEthernet1/0/46
    port link-type trunk
    port trunk permit vlan 1 203 207
    #
    interface GigabitEthernet1/0/47
    #
    interface GigabitEthernet1/0/48
    #
    interface Ten-GigabitEthernet1/0/49
    #
    interface Ten-GigabitEthernet1/0/50
    #
    interface Ten-GigabitEthernet1/0/51
    #
    interface Ten-GigabitEthernet1/0/52
    #
    scheduler logfile size 16
    #
    line class aux
    user-role network-admin
    #
    line class vty
    user-role network-operator
    #
    line aux 0
    user-role network-admin
    #
    line vty 0 15
    authentication-mode scheme
    user-role network-operator
    protocol inbound ssh
    #
    line vty 16 63
    user-role network-operator
    #
    ip route-static 0.0.0.0 0 192.168.202.1
    ip route-static 0.0.0.0 1 192.168.202.1
    #
    ssh server enable
    #
    radius scheme system
    user-name-format without-domain
    #
    domain system
    #
    domain default enable system
    #
    role name level-0
    description Predefined level-0 role
    #
    role name level-1
    description Predefined level-1 role
    #
    role name level-2
    description Predefined level-2 role
    #
    role name level-3
    description Predefined level-3 role
    #
    role name level-4
    description Predefined level-4 role
    #
    role name level-5
    description Predefined level-5 role
    #
    role name level-6
    description Predefined level-6 role
    #
    role name level-7
    description Predefined level-7 role
    #
    role name level-8
    description Predefined level-8 role
    #
    role name level-9
    description Predefined level-9 role
    #
    role name level-10
    description Predefined level-10 role
    #
    role name level-11
    description Predefined level-11 role
    #
    role name level-12
    description Predefined level-12 role
    #
    role name level-13
    description Predefined level-13 role
    #
    role name level-14
    description Predefined level-14 role
    #
    role name enable
    #
    role name enablefwf
    #
    user-group system
    #
    local-user admin class manage
    password hash *
    service-type ssh
    authorization-attribute user-role network-admin
    authorization-attribute user-role network-operator
    #
    local-user swadmin class manage
    password hash *
    service-type ssh telnet http https
    authorization-attribute vlan 203
    authorization-attribute user-role network-admin
    authorization-attribute user-role network-operator
    #
    ip http enable
    ip https enable
    #
    return



  • 4.  RE: How to enable SSH on Comware

    Posted Nov 08, 2019 09:02 PM
    Did you ever get it working I enabled the ash server on my MSR2003ac router and it lets you connect and passes the public key properly but as soon as the under name authenticates properly it drops the freaking connection it’s so weird


  • 5.  RE: How to enable SSH on Comware

    Posted Nov 24, 2019 05:41 AM

    Hi,

    Have you generated an ssl key? 

    ]public-key local create rsa

     

    Regards