Updated on 2026-07-30 GMT+08:00

Enabling or Disabling an Insecure Protocol

Scenarios

You can disable or enable an insecure protocol used by your bastion host system. If an insecure protocol is disabled, the bastion host cannot use the insecure protocol to transmit data. The common insecure protocols include FTP, Telnet, and Rlogin.

By default, insecure protocols are disabled on a bastion host. However, you may need to enable insecure protocols in some special scenarios, for example:

  • Interconnection with third-party systems: If your bastion host needs to interconnect with third-party systems or devices that support only insecure protocols such as FTP, Telnet, and Rlogin, insecure protocols must be enabled to ensure normal service transfer.
  • Compatibility with old devices: If you need to manage systems or devices that use insecure protocols through a bastion host, insecure protocols must be enabled to ensure backward compatibility and continuity of O&M management.
  • Smooth transition: During the transition phase of protocol upgrade and reconstruction, some old systems may not support secure protocols. In this case, insecure protocols must be temporarily enabled to ensure smooth service migration.

Precautions

Protocols such as FTP, Telnet, and Rlogin have security risks, such as plaintext transmission. You are advised to disable these insecure protocols in a timely manner and prevent sensitive information from being transmitted while they remain enabled.

Prerequisites

The role you belong to has the management permission for the System module. For details about how to check the permissions of each role, see Role.

Enabling or Disabling an Insecure Protocol

  1. Log in to your bastion host system.
  2. In the navigation pane on the left, choose System > System Config > Security.
  3. On the right of the Protocol Config area, click Edit.

    Figure 1 Protocol configuration

  4. After enabling or disabling an insecure protocol, click OK.

    Figure 2 Enabling or disabling an insecure protocol