{"id":494,"date":"2018-12-08T16:20:00","date_gmt":"2018-12-08T07:20:00","guid":{"rendered":""},"modified":"2020-10-02T22:28:00","modified_gmt":"2020-10-02T13:28:00","slug":"nw%e6%a9%9f%e5%99%a8%e3%82%82%e5%85%ac%e9%96%8b%e9%8d%b5%e8%aa%8d%e8%a8%bc%e3%81%a7ssh","status":"publish","type":"post","link":"https:\/\/wp.zassoul.com\/?p=494","title":{"rendered":"NW\u6a5f\u5668\u3082\u516c\u958b\u9375\u8a8d\u8a3c\u3067SSH"},"content":{"rendered":"<p>NW\u6a5f\u5668\u3082\u305d\u308d\u305d\u308dSSH\u3067\u30a2\u30af\u30bb\u30b9\u3059\u308b\u3068\u304d\u306f\u516c\u958b\u9375\u8a8d\u8a3c\u3067\u3084\u308b\u3079\u304d\u304b\u3068\u601d\u3044, \u4e3b\u306b\u89e6\u308b\u3067\u3042\u308d\u3046NW\u6a5f\u5668\u306e\u8a2d\u5b9a\u3092\u307e\u3068\u3081\u305f\u3002<\/p>\n<h3><u>&#8211; \u9375\u6e96\u5099<\/u><\/h3>\n<h4>SSH\u3067\u5fc5\u8981\u3068\u306a\u308b\u516c\u958b\u9375\u3092\u6e96\u5099\u3059\u308b\u3002<\/h4>\n<pre>$ ssh-keygen -t rsa -C user01 -f .\/rsa_id<br \/>$ ls rsa* <br \/>rsa_id.pub  #\u516c\u958b\u9375<br \/>rsa_id      #\u79d8\u5bc6\u9375<br \/><\/pre>\n<p><\/p>\n<h3><u>&#8211; Cisco IOS<\/u><\/h3>\n<p>\u53c2\u8003\uff1a&nbsp;<a href=\"https:\/\/community.cisco.com\/t5\/security-documents\/ssh-using-public-key-authentication-to-ios-and-big-outputs\/ta-p\/3122001\" target=\"_blank\" rel=\"noopener noreferrer\">SSH using public key authentication to IOS and big outputs.<\/a><\/p>\n<h4>1. SSH\u8a2d\u5b9a<\/h4>\n<pre># conf t<br \/>(config)# ip ssh version 2<br \/>(config)# line vty 0 4<br \/>(config-line)# login local<br \/>(config-line)# transport input ssh<br \/>(config-line)# hostname R1<br \/>(config)# ip domain name test.local<br \/>(config)# crypto key gen rsa<br \/><\/pre>\n<p><\/p>\n<h4>2. \u30e6\u30fc\u30b6\u3068\u516c\u958b\u9375\u7d10\u4ed8\u3051<\/h4>\n<pre>(config)# ip ssh pubkey-chain<br \/>(conf-ssh-pubkey)# username cisco<br \/>(conf-ssh-pubkey-user)# key-string<br \/>(conf-ssh-pubkey-data)# <br \/>\u203b \u6700\u5927\u3067\u8cbc\u308a\u4ed8\u3051\u3089\u308c\u308b\u6587\u5b57\u6570\u304c256\u5b57\u3068\u3044\u3046\u3053\u3068\u3067\u8907\u6570\u884c\u306b\u5206\u3051\u3066\u30da\u30fc\u30b9\u30c8\u3059\u308b\u3002<br \/>(conf-ssh-pubkey-data)# exit<br \/>(conf-ssh-pubkey-user)# end<br \/>#<\/pre>\n<p><\/p>\n<h4>\u30c6\u30b9\u30c8  <\/h4>\n<pre>$ ssh -l cisco -i .\/rsa.id 172.16.1.1<br \/>R1&gt;<br \/><\/pre>\n<p><u><br \/><\/u><\/p>\n<h3><u>&#8211; VyOS<\/u><\/h3>\n<p>\u53c2\u8003\uff1a<a href=\"https:\/\/wiki.vyos.net\/wiki\/Remote_access\" target=\"_blank\" rel=\"noopener noreferrer\">Remote access<\/a><\/p>\n<h4>1. SSH\u8a2d\u5b9a<\/h4>\n<pre>set service ssh port '22'<\/pre>\n<div>\n<h4>2. \u30e6\u30fc\u30b6\u3068\u516c\u958b\u9375\u306e\u7d10\u4ed8\u3051\u8a8d\u8a3c\u8a2d\u5b9a<\/h4>\n<\/div>\n<pre>set system login user user1 authentication public-keys '\u9375\u306e\u8b58\u5225\u5b50' key 'public key\u5185\u306e\u6587\u5b57\u5217\u306e\u307f\u5165\u529b'&nbsp; #ssh-rsa \u3068 \u30e6\u30fc\u30b6\u306f\u629c\u304f<\/pre>\n<div>\n<h4>3. \u30d1\u30b9\u30ef\u30fc\u30c9\u8a8d\u8a3c\u7121\u52b9\u5316<\/h4>\n<\/div>\n<pre>set service ssh disable-password-authentication<\/pre>\n<div>\n<h4>4. \u30db\u30b9\u30c8\u30d0\u30ea\u30c7\u30fc\u30b7\u30e7\u30f3\u7121\u52b9\u5316(\u30aa\u30d7\u30b7\u30e7\u30f3)<\/h4>\n<\/div>\n<pre>set service ssh disable-host-validation<br \/><\/pre>\n<div>\n<div><\/p>\n<h4>\u30c6\u30b9\u30c8<\/h4>\n<\/div>\n<div>\n<pre>$ ssh -l user1 -i .\/rsa_id 172.16.1.2<br \/>Welcome to VyOS<br \/><br \/>The programs included with the Debian GNU\/Linux system are free software;<br \/>the exact distribution terms for each program are described in the<br \/>individual files in \/usr\/share\/doc\/*\/copyright.<br \/><br \/>Debian GNU\/Linux comes with ABSOLUTELY NO WARRANTY, to the extent<br \/>permitted by applicable law.<br \/>Last login: <br \/>user1@vyos:~$<br \/><\/pre>\n<h3><u>&#8211; Cisco ASA(9.x)<\/u><\/h3>\n<p>\u53c2\u8003\uff1a<a href=\"https:\/\/www.cisco.com\/c\/en\/us\/td\/docs\/security\/asa\/asa93\/configuration\/general\/asa-general-cli\/aaa-local.html#43678\" target=\"_blank\" rel=\"noopener noreferrer\">Cisco ASA \u30b7\u30ea\u30fc\u30ba 9.8 CLI \u30b3\u30f3\u30d5\u30a3\u30ae\u30e5\u30ec\u30fc\u30b7\u30e7\u30f3 \u30ac\u30a4\u30c9\uff08\u4e00\u822c\u7684\u306a\u64cd\u4f5c\uff09<\/a><\/p>\n<h4>1. SSH\u8a2d\u5b9a<\/h4>\n<p>\u3072\u3068\u307e\u305aOutside\u304b\u3089\u5168\u8a31\u53ef\u3002<\/p>\n<pre>(config)# ssh 0.0.0.0 0.0.0.0 outside<br \/><\/pre>\n<div><\/div>\n<div>\n<h4>2. \u516c\u958b\u9375\u306e\u30d5\u30a9\u30fc\u30de\u30c3\u30c8\u5909\u66f4<\/h4>\n<p>\u516c\u958b\u9375\u3092RFC4716\u5f62\u5f0f\u3067\u51fa\u529b\u3002<\/p><\/div>\n<pre>$ ssh-keygen&nbsp; -e -m rfc4716 -f .\/rsa_id.pub  # \u3053\u306e\u51fa\u529b\u7d50\u679c\u3092\u63a7\u3048\u3066\u304a\u304f<br \/><\/pre>\n<h4>3. \u30e6\u30fc\u30b6\u3068\u516c\u958b\u9375\u306e\u7d10\u4ed8\u3051<\/h4>\n<pre>(config)# aaa authentication ssh console LOCAL<br \/>(config)# username user1 attributes<br \/>(config-username)#&nbsp;service-type admin<br \/>(config-username)&nbsp;ssh authentication pkf<br \/><br \/>Enter an SSH public key formatted file.<br \/>End with the word \"quit\" on a line by itself:<br \/>###  2\u3067\u5909\u63db\u3057\u305fPublic Key\u3092\u8cbc\u308a\u4ed8\u3051\u308b ###<br \/>---- BEGIN SSH2 PUBLIC KEY ----<br \/>Comment: \"2048-bit RSA, converted by ubuntu@HOST from OpenSSH\"<br \/>\uff5e\uff5e\uff5e<br \/>---- END SSH2 PUBLIC KEY ----<br \/>quit<br \/><\/pre>\n<div><\/p>\n<h4>\u30c6\u30b9\u30c8<\/h4>\n<pre>$ ssh -l user1 -i .\/rsa_id 172.16.1.3<br \/>User user1 logged in to ASA<br \/>Logins over the last 1 days: 2.  Last login: 06:54:33 UTC Dec 8 2018 from 192.168.1.10<br \/>Failed logins since the last login: 0.<br \/>Type help or '?' for a list of available commands.<br \/>ASA&gt;<br \/><\/pre>\n<p><\/div>\n<h3><u>&#8211; Cumulus linux<\/u><\/h3>\n<div>\n<h4>0. NCLU(Network Command Line Utility)\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb<\/h4>\n<\/div>\n<div>\u53c2\u8003\uff1a<a href=\"https:\/\/docs.cumulusnetworks.com\/display\/DOCS\/Network+Command+Line+Utility+-+NCLU\" target=\"_blank\" rel=\"noopener noreferrer\">Network Command Line Utility &#8211; NCLU<\/a><br \/>\u203b \u3053\u3053\u306f\u7701\u7565<\/div>\n<div>\n<h4>1. Linux\u306eSSH\u516c\u958b\u9375\u8a8d\u8a3c\u8a2d\u5b9a<\/h4>\n<p>\u30db\u30fc\u30e0\u306e.ssh\u914d\u4e0b\u306eauthorized_keys\u306b\u516c\u958b\u9375\u3092\u767b\u9332\u3002<\/p>\n<h4>\u30c6\u30b9\u30c8<\/h4>\n<pre>$ ssh -l cumulus -i .\/rsa_id 172.16.1.4<br \/><br \/>Welcome to Cumulus VX (TM)<br \/><br \/>Cumulus VX (TM) is a community supported virtual appliance designed for<br \/>experiencing, testing and prototyping Cumulus Networks' latest technology.<br \/>For any questions or technical support, visit our community site at:<br \/>http:\/\/community.cumulusnetworks.com<br \/><br \/>The registered trademark Linux (R) is used pursuant to a sublicense from LMI,<br \/>the exclusive licensee of Linus Torvalds, owner of the mark on a world-wide<br \/>basis.<br \/>Last login: Sat Dec  8 04:45:53 2018 from 192.168.1.10<br \/>cumulus@cumulus:~$<br \/><\/pre>\n<p><\/div>\n<div>\n<h3><u>&#8211; JUNOS<\/u><\/h3>\n<p>\u53c2\u8003\uff1a<a href=\"https:\/\/www.juniper.net\/documentation\/en_US\/junos\/topics\/reference\/configuration-statement\/authentication-edit-system-login-qfx-series.html\" target=\"_blank\" rel=\"noopener noreferrer\">authentication (Login)<\/a><\/p>\n<h4>1. SSH\u8a2d\u5b9a<\/h4>\n<pre> set system services ssh protocol-version v2<br \/><\/pre>\n<div><\/p>\n<h4>2. \u30e6\u30fc\u30b6\u3068\u516c\u958b\u9375\u7d10\u4ed8\u3051 <\/h4>\n<pre>set system login user admin authentication ssh-rsa \"ssh-rsa \u7701\u7565 user01\"<br \/><\/pre>\n<div><\/p>\n<h4>\u30c6\u30b9\u30c8 <\/h4>\n<pre>$ ssh -l admin -i .\/user2_rsa 172.16.1.5<br \/>Last login: Thu Dec  6 18:07:53 2018 from 192.168.1.10<br \/>--- JUNOS 15.1X49-D140.2 built 2018-05-25 18:23:50 UTC<br \/>admin&gt;<br \/><\/pre>\n<div><\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>NW\u6a5f\u5668\u3082\u305d\u308d\u305d\u308dSSH\u3067\u30a2\u30af\u30bb\u30b9\u3059\u308b\u3068\u304d\u306f\u516c\u958b\u9375\u8a8d\u8a3c\u3067\u3084\u308b\u3079\u304d\u304b\u3068\u601d\u3044, \u4e3b\u306b\u89e6\u308b\u3067\u3042\u308d\u3046NW\u6a5f\u5668\u306e\u8a2d\u5b9a\u3092\u307e\u3068\u3081\u305f\u3002 &#8211; \u9375\u6e96\u5099 SSH\u3067\u5fc5\u8981\u3068\u306a\u308b\u516c\u958b\u9375\u3092\u6e96\u5099\u3059\u308b\u3002 $ ssh-keygen -t rsa\u2026 <span class=\"read-more\"><a href=\"https:\/\/wp.zassoul.com\/?p=494\">\u7d9a\u304d\u3092\u8aad\u3080 &raquo;<\/a><\/span><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[11,40,43,42,41,8],"tags":[],"class_list":["post-494","post","type-post","status-publish","format-standard","hentry","category-cisco","category-cumuluslinux","category-junos","category-nat","category-vyos","category-8"],"_links":{"self":[{"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=\/wp\/v2\/posts\/494","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=494"}],"version-history":[{"count":1,"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=\/wp\/v2\/posts\/494\/revisions"}],"predecessor-version":[{"id":631,"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=\/wp\/v2\/posts\/494\/revisions\/631"}],"wp:attachment":[{"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=494"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=494"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/wp.zassoul.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=494"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}