交换机开启了SSH服务,登录账户也打开了SSH登录权限。但是在登陆时被拒绝
(0)
1、查看一下 用户是否有service-type ssh
2、查看ssh server acl xxxx 是否有限制;
3、查看是否配置line vty 会话
dis cur conf line
line vty 0 4
authentication-mode scheme
(0)
我现在只能访问web界面,我发一下web相关配置的截图
# version 7.1.070, Release 6318P01 # sysname YG-R2_Line-1#SW # clock timezone Beijing add 08:00:00 clock protocol ntp # irf mac-address persistent timer irf auto-update enable undo irf link-delay irf member 1 priority 1 # lldp global enable # password-recovery enable # vlan 1 # vlan 100 # stp global enable # interface NULL0 # interface Vlan-interface1 ip address dhcp-alloc dhcp client identifier ascii 6ce5f789c56f-VLAN0001 # interface Vlan-interface100 ip address xxxxxxxxx 255.255.255.0 # interface GigabitEthernet1/0/1 # interface GigabitEthernet1/0/2 port link-type trunk port trunk permit vlan 1 100 # interface GigabitEthernet1/0/3 # interface GigabitEthernet1/0/4 # interface GigabitEthernet1/0/5 # interface GigabitEthernet1/0/6 # interface GigabitEthernet1/0/7 # interface GigabitEthernet1/0/8 # interface GigabitEthernet1/0/9 # interface GigabitEthernet1/0/10 # interface GigabitEthernet1/0/11 # interface GigabitEthernet1/0/12 # interface GigabitEthernet1/0/13 # interface GigabitEthernet1/0/14 # interface GigabitEthernet1/0/15 # interface GigabitEthernet1/0/16 port link-type trunk port trunk permit vlan 1 100 # interface GigabitEthernet1/0/17 # interface GigabitEthernet1/0/18 # interface GigabitEthernet1/0/19 # interface GigabitEthernet1/0/20 # interface GigabitEthernet1/0/21 # interface GigabitEthernet1/0/22 # interface GigabitEthernet1/0/23 # interface GigabitEthernet1/0/24 # interface GigabitEthernet1/0/25 # interface GigabitEthernet1/0/26 # interface GigabitEthernet1/0/27 # interface GigabitEthernet1/0/28 # scheduler logfile size 16 # line class aux user-role network-admin # line class vty user-role network-operator # line aux 0 user-role network-admin # line vty 0 63 user-role network-operator # snmp-agent snmp-agent local-engineid xxxxxxxx snmp-agent community read xxxxxxx snmp-agent sys-info version v2c v3 # ssh server enable # ntp-service enable ntp-service source Vlan-interface1 ntp-service unicast-server xxxxxxxxx # radius scheme system user-name-format without-domain # domain system # domain default enable system # role name level-0 description Predefined level-0 role # role name level-1 description Predefined level-1 role # role name level-2 description Predefined level-2 role # role name level-3 description Predefined level-3 role # role name level-4 description Predefined level-4 role # role name level-5 description Predefined level-5 role # role name level-6 description Predefined level-6 role # role name level-7 description Predefined level-7 role # role name level-8 description Predefined level-8 role # role name level-9 description Predefined level-9 role # role name level-10 description Predefined level-10 role # role name level-11 description Predefined level-11 role # role name level-12 description Predefined level-12 role # role name level-13 description Predefined level-13 role # role name level-14 description Predefined level-14 role # user-group system # local-user admin class manage password hash xxxxxxx service-type https ssh terminal authorization-attribute user-role network-admin authorization-attribute user-role network-operator # local-user test class manage password hash xxxxxx service-type https ssh terminal authorization-attribute user-role network-admin authorization-attribute user-role network-operator # ip https enable # cloud-management server domain oasis.h3c.com # return
检查下ssh相关的配置,配置没问题的话 检查下是否有设备做了限制
(0)
# version 7.1.070, Release 6318P01 # sysname YG-R2_Line-1#SW # clock timezone Beijing add 08:00:00 clock protocol ntp # irf mac-address persistent timer irf auto-update enable undo irf link-delay irf member 1 priority 1 # lldp global enable # password-recovery enable # vlan 1 # vlan 100 # stp global enable # interface NULL0 # interface Vlan-interface1 ip address dhcp-alloc dhcp client identifier ascii 6ce5f789c56f-VLAN0001 # interface Vlan-interface100 ip address xxxxxxxxx 255.255.255.0 # interface GigabitEthernet1/0/1 # interface GigabitEthernet1/0/2 port link-type trunk port trunk permit vlan 1 100 # interface GigabitEthernet1/0/3 # interface GigabitEthernet1/0/4 # interface GigabitEthernet1/0/5 # interface GigabitEthernet1/0/6 # interface GigabitEthernet1/0/7 # interface GigabitEthernet1/0/8 # interface GigabitEthernet1/0/9 # interface GigabitEthernet1/0/10 # interface GigabitEthernet1/0/11 # interface GigabitEthernet1/0/12 # interface GigabitEthernet1/0/13 # interface GigabitEthernet1/0/14 # interface GigabitEthernet1/0/15 # interface GigabitEthernet1/0/16 port link-type trunk port trunk permit vlan 1 100 # interface GigabitEthernet1/0/17 # interface GigabitEthernet1/0/18 # interface GigabitEthernet1/0/19 # interface GigabitEthernet1/0/20 # interface GigabitEthernet1/0/21 # interface GigabitEthernet1/0/22 # interface GigabitEthernet1/0/23 # interface GigabitEthernet1/0/24 # interface GigabitEthernet1/0/25 # interface GigabitEthernet1/0/26 # interface GigabitEthernet1/0/27 # interface GigabitEthernet1/0/28 # scheduler logfile size 16 # line class aux user-role network-admin # line class vty user-role network-operator # line aux 0 user-role network-admin # line vty 0 63 user-role network-operator # snmp-agent snmp-agent local-engineid xxxxxxxx snmp-agent community read xxxxxxx snmp-agent sys-info version v2c v3 # ssh server enable # ntp-service enable ntp-service source Vlan-interface1 ntp-service unicast-server xxxxxxxxx # radius scheme system user-name-format without-domain # domain system # domain default enable system # role name level-0 description Predefined level-0 role # role name level-1 description Predefined level-1 role # role name level-2 description Predefined level-2 role # role name level-3 description Predefined level-3 role # role name level-4 description Predefined level-4 role # role name level-5 description Predefined level-5 role # role name level-6 description Predefined level-6 role # role name level-7 description Predefined level-7 role # role name level-8 description Predefined level-8 role # role name level-9 description Predefined level-9 role # role name level-10 description Predefined level-10 role # role name level-11 description Predefined level-11 role # role name level-12 description Predefined level-12 role # role name level-13 description Predefined level-13 role # role name level-14 description Predefined level-14 role # user-group system # local-user admin class manage password hash xxxxxxx service-type https ssh terminal authorization-attribute user-role network-admin authorization-attribute user-role network-operator # local-user test class manage password hash xxxxxx service-type https ssh terminal authorization-attribute user-role network-admin authorization-attribute user-role network-operator # ip https enable # cloud-management server domain oasis.h3c.com # return
我现在只能通过web界面登录,SSH并没有做相关限制。我本身对配置这块不太懂,但是对照着同型号可登录的设备配置,没有区别
相关配置发来看下
命令行的配置上来看下吧
我用我号在评论区发了配置截图。现在设备不在我身边没办法console
# version 7.1.070, Release 6318P01 # sysname YG-R2_Line-1#SW # clock timezone Beijing add 08:00:00 clock protocol ntp # irf mac-address persistent timer irf auto-update enable undo irf link-delay irf member 1 priority 1 # lldp global enable # password-recovery enable # vlan 1 # vlan 100 # stp global enable # interface NULL0 # interface Vlan-interface1 ip address dhcp-alloc dhcp client identifier ascii 6ce5f789c56f-VLAN0001 # interface Vlan-interface100 ip address xxxxxxxxx 255.255.255.0 # interface GigabitEthernet1/0/1 # interface GigabitEthernet1/0/2 port link-type trunk port trunk permit vlan 1 100 # interface GigabitEthernet1/0/3 # interface GigabitEthernet1/0/4 # interface GigabitEthernet1/0/5 # interface GigabitEthernet1/0/6 # interface GigabitEthernet1/0/7 # interface GigabitEthernet1/0/8 # interface GigabitEthernet1/0/9 # interface GigabitEthernet1/0/10 # interface GigabitEthernet1/0/11 # interface GigabitEthernet1/0/12 # interface GigabitEthernet1/0/13 # interface GigabitEthernet1/0/14 # interface GigabitEthernet1/0/15 # interface GigabitEthernet1/0/16 port link-type trunk port trunk permit vlan 1 100 # interface GigabitEthernet1/0/17 # interface GigabitEthernet1/0/18 # interface GigabitEthernet1/0/19 # interface GigabitEthernet1/0/20 # interface GigabitEthernet1/0/21 # interface GigabitEthernet1/0/22 # interface GigabitEthernet1/0/23 # interface GigabitEthernet1/0/24 # interface GigabitEthernet1/0/25 # interface GigabitEthernet1/0/26 # interface GigabitEthernet1/0/27 # interface GigabitEthernet1/0/28 # scheduler logfile size 16 # line class aux user-role network-admin # line class vty user-role network-operator # line aux 0 user-role network-admin # line vty 0 63 user-role network-operator # snmp-agent snmp-agent local-engineid xxxxxxxx snmp-agent community read xxxxxxx snmp-agent sys-info version v2c v3 # ssh server enable # ntp-service enable ntp-service source Vlan-interface1 ntp-service unicast-server xxxxxxxxx # radius scheme system user-name-format without-domain # domain system # domain default enable system # role name level-0 description Predefined level-0 role # role name level-1 description Predefined level-1 role # role name level-2 description Predefined level-2 role # role name level-3 description Predefined level-3 role # role name level-4 description Predefined level-4 role # role name level-5 description Predefined level-5 role # role name level-6 description Predefined level-6 role # role name level-7 description Predefined level-7 role # role name level-8 description Predefined level-8 role # role name level-9 description Predefined level-9 role # role name level-10 description Predefined level-10 role # role name level-11 description Predefined level-11 role # role name level-12 description Predefined level-12 role # role name level-13 description Predefined level-13 role # role name level-14 description Predefined level-14 role # user-group system # local-user admin class manage password hash xxxxxxx service-type https ssh terminal authorization-attribute user-role network-admin authorization-attribute user-role network-operator # local-user test class manage password hash xxxxxx service-type https ssh terminal authorization-attribute user-role network-admin authorization-attribute user-role network-operator # ip https enable # cloud-management server domain oasis.h3c.com # return
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
# version 7.1.070, Release 6318P01 # sysname YG-R2_Line-1#SW # clock timezone Beijing add 08:00:00 clock protocol ntp # irf mac-address persistent timer irf auto-update enable undo irf link-delay irf member 1 priority 1 # lldp global enable # password-recovery enable # vlan 1 # vlan 100 # stp global enable # interface NULL0 # interface Vlan-interface1 ip address dhcp-alloc dhcp client identifier ascii 6ce5f789c56f-VLAN0001 # interface Vlan-interface100 ip address xxxxxxxxx 255.255.255.0 # interface GigabitEthernet1/0/1 # interface GigabitEthernet1/0/2 port link-type trunk port trunk permit vlan 1 100 # interface GigabitEthernet1/0/3 # interface GigabitEthernet1/0/4 # interface GigabitEthernet1/0/5 # interface GigabitEthernet1/0/6 # interface GigabitEthernet1/0/7 # interface GigabitEthernet1/0/8 # interface GigabitEthernet1/0/9 # interface GigabitEthernet1/0/10 # interface GigabitEthernet1/0/11 # interface GigabitEthernet1/0/12 # interface GigabitEthernet1/0/13 # interface GigabitEthernet1/0/14 # interface GigabitEthernet1/0/15 # interface GigabitEthernet1/0/16 port link-type trunk port trunk permit vlan 1 100 # interface GigabitEthernet1/0/17 # interface GigabitEthernet1/0/18 # interface GigabitEthernet1/0/19 # interface GigabitEthernet1/0/20 # interface GigabitEthernet1/0/21 # interface GigabitEthernet1/0/22 # interface GigabitEthernet1/0/23 # interface GigabitEthernet1/0/24 # interface GigabitEthernet1/0/25 # interface GigabitEthernet1/0/26 # interface GigabitEthernet1/0/27 # interface GigabitEthernet1/0/28 # scheduler logfile size 16 # line class aux user-role network-admin # line class vty user-role network-operator # line aux 0 user-role network-admin # line vty 0 63 user-role network-operator # snmp-agent snmp-agent local-engineid xxxxxxxx snmp-agent community read xxxxxxx snmp-agent sys-info version v2c v3 # ssh server enable # ntp-service enable ntp-service source Vlan-interface1 ntp-service unicast-server xxxxxxxxx # radius scheme system user-name-format without-domain # domain system # domain default enable system # role name level-0 description Predefined level-0 role # role name level-1 description Predefined level-1 role # role name level-2 description Predefined level-2 role # role name level-3 description Predefined level-3 role # role name level-4 description Predefined level-4 role # role name level-5 description Predefined level-5 role # role name level-6 description Predefined level-6 role # role name level-7 description Predefined level-7 role # role name level-8 description Predefined level-8 role # role name level-9 description Predefined level-9 role # role name level-10 description Predefined level-10 role # role name level-11 description Predefined level-11 role # role name level-12 description Predefined level-12 role # role name level-13 description Predefined level-13 role # role name level-14 description Predefined level-14 role # user-group system # local-user admin class manage password hash xxxxxxx service-type https ssh terminal authorization-attribute user-role network-admin authorization-attribute user-role network-operator # local-user test class manage password hash xxxxxx service-type https ssh terminal authorization-attribute user-role network-admin authorization-attribute user-role network-operator # ip https enable # cloud-management server domain oasis.h3c.com # return