Appendix: Uploading And Downloading Files; Device Serving As The Ftp Client To Upload Or Download Files Through Ftp - Huawei USG6000 Upgrade Manual

Hide thumbs Also See for USG6000:
Table of Contents

Advertisement

HUAWEI USG6000&USG9500
Upgrade Guide
2.
----End

2.5 Appendix: Uploading and Downloading Files

About This Chapter
2.5.1 Device Serving as the FTP Client to Upload or Download
Files Through FTP
Context
As shown in Figure 1, PC2 serves as the FTP server. Log in to the FTP server from the
USG9500 and upload or download files through FTP. This method requires the third-party
FTP server software to be installed on the PC2.
Issue 01 (2018-01-16)
192.168.0.1 0
[USG9500-policy-interzone-local-trust-inbound-1] action permit
Configure SSH for login.
Set the IP address of GigabitEthernet 0/0/0 on the MPU of the USG9500 to 192.168.0.1
and subnet mask to 255.255.255.0. Set the authentication mode on the virtual type
terminal (VTY) to AAA and protocol to SSH. Create a local SSH user with the user
name user1, user level 3, password Password1.
<USG9500> system-view
[USG9500] user-interface vty 0 4
[USG9500-ui-vty0-4] authentication-mode aaa
[USG9500-ui-vty0-4] user privilege level 3
[USG9500-ui-vty0-4] quit
[USG9500] aaa
[USG9500-aaa] manager-user sshadmin
[USG9500-aaa-manager-user-sshadmin] password
Enter Password:
Confirm Password:
[USG9500-aaa-manager-user-user1] service-type ssh
[USG9500-aaa-manager-user-user1] level 3
[USG9500-aaa-manager-user-sshadmin] quit
[USG9500-aaa] bind manager-user sshadmin role system-admin
[USG9500-aaa] quit
[USG9500] stelnet server enable
[USG9500] rsa local-key-pair create
[USG9500] ssh user sshadmin
[USG9500] ssh user sshadmin authentication-type password
[USG9500] ssh user sshadmin service-type stelnet
If an interface on the interface board is used to construct the SSH environment, you need
to not only configure the previous commands, but also assign the interface to a security
zone and enable the interzone security policy between this security zone and the Local
zone. The following command output uses assigning GigabitEthernet 1/0/1 to the Trust
zone as an example. The IP address of the SSH client is 192.168.0.2.
[USG9500] firewall zone trust
[USG9500-zone-trust] add interface GigabitEthernet 1/0/1
[USG9500-zone-trust] quit
[USG9500] policy interzone local trust inbound
[USG9500-policy-interzone-local-trust-inbound] policy 1
[USG9500-policy-interzone-local-trust-inbound-1] policy source 192.168.0.2 0
[USG9500-policy-interzone-local-trust-inbound-1] policy destination
192.168.0.1 0
[USG9500-policy-interzone-local-trust-inbound-1] action permit
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
2 USG9500
180

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Usg9500

Table of Contents