Remote Access Configuration Using SSH
If there is no startup configuration file in the flash memory on the device, SSH access is automatically enabled. No manual intervention is required to generate SSH keys, configure a local user, and enable AAA configurations that are required for SSH access. The following configuration is added to the device during bootup:
aaa authentication web-server default local aaa authentication login default local no telnet server username super password sp-admin
This configuration automatically generates an RSA-2048 key during bootup if an RSA key does not exist. On initial access the default username of super and default password of sp-admin are used. You are immediately prompted to modify the password as shown in the following example:
User Access Verification Please Enter Login Name:super Please Enter Password:sp-admin User login successful. User ‘super’ login successful with default password. Please change the password. Enter new password for user ‘super’: Reconfirm new password for user ‘super’: Password modified successfully for user ‘super’. Authentication is enabled in the device for Console/WEB/SSH
The new password is not automatically saved, you must use the
write memory command to save it to the startup configuration file.
Restrictions on Automatic Enabling of SSH and Disabling Telnet
The added configurations are removed automatically from the device if the running configuration file is downloaded by way of DHCP auto-provisioning before being accessed by SSH.
The added configurations are removed automatically from the device if the device connects to SmartZone (SZ) before being accessed by way of the SSH.
- In FIPS or FIPS-CC mode, the automatic enabling of SSH configuration is not applicable.