show ip ssh

Displays Secure Shell (SSH) connection session details.
Syntax
show ip ssh [ config | rekey statistics ]
Parameters
config
Displays the SSH configuration details.
rekey statistics
Displays the SSH rekey statistics information.
Modes

User EXEC mode

The show ip ssh command displays the following information:

Output field Description
Inbound Connections listed under this heading are inbound.
Outbound Connections listed under this heading are outbound.
Connection The SSH connection ID.
Version The SSH version number.
Encryption The encryption method used for the connection.
Username The username for the connection.
HMAC The HMAC version.
Server Hostkey The type of server host key. This can be DSA or RSA.
IP Address The IP address of the SSH client.
SSH-v2.0 enabled Indicates that SSHv2 is enabled.
hostkey Indicates that at least one host key is on the device. It is followed by a list of the host key types and module sizes.

The show ip ssh config command displays the following information:

Output field Description
SSH server SSH server is enabled or disabled.
SSH port SSH port number.
Host Key Host key.
Encryption The encryption used for the SSH connection. The following values are displayed when AES only is enabled:
  • AES-256, AES-192, and AES-128 indicate the different AES methods used for encryption.
  • 3-DES indicates 3-DES algorithm is used for encryption
Permit empty password Empty password login is allowed or not allowed.
Authentication methods The authentication methods used for SSH. The authentication can have one or more of the following values:
  • Password: Indicates that you are prompted for a password when attempting to log in to the device.
  • Public-key: Indicates that DSA or RSA challenge-response authentication is enabled.
  • Interactive: Indicates the interactive authentication is enabled.
Authentication retries The number of authentication retries. This number can be from 1 through 5.
Login timeout (seconds) SSH login timeout value in seconds. This can be from 0 through 120.
Idle timeout (minutes) SSH idle timeout value in minutes. This can be from 0 through 240.
Strict management VRF Strict management VRF is enabled or disabled.
SCP SCP is enabled or disabled.
SSH IPv4 clients The list of IPv4 addresses to which SSH access is allowed. The default is "All".
SSH IPv6 clients The list of IPv6 addresses to which SSH access is allowed. The default is "All".
SSH IPv4 access-group The IPv4 ACL used to permit or deny access using SSH.
SSH IPv6 access-group The IPv6 ACL used to permit or deny access using SSH.
Client Rekey The SSH rekey interval configured for the client, in minutes and maximum data.
Server Rekey The SSH rekey interval configured for the server, in minutes and maximum data.
Examples

The following example displays sample output of the show ip ssh command.

device# show ip ssh
Connection  Version  Encryption  Username  HMAC       Server Hostkey  IP Address
Inbound:
1           SSH-2    3des-cbc    Raymond   hmac-sha1  ssh-dss         10.120.54.2
Outbound:
6           SSH-2    aes256-cbc  Steve     hmac-sha1  ssh-dss         10.37.77.15
SSH-v2.0 enabled; hostkey: DSA(1024), RSA(2048)

The following example displays sample output of the show ip ssh config command.

device# show ip ssh config
SSH server                 : Disabled
SSH port                   : tcp\22
Host Key                   :
Encryption                 : aes256-cbc, aes192-cbc, aes128-cbc, aes256-ctr, aes
192-ctr, aes128-ctr, 3des-cbc
Permit empty password      : No
Authentication methods     : Password, Public-key, Interactive
Authentication retries     : 3
Login timeout (seconds)    : 120
Idle timeout (minutes)     : 0
Strict management VRF      : Disabled
SCP                        : Enabled
SSH IPv4 clients           : All
SSH IPv6 clients           : All
SSH IPv4 access-group      :
SSH IPv6 access-group      :
SSH Client Keys            : RSA(0)
Client Rekey               : 200 Minute, 0 KB
Server Rekey               : 250 Minute, 0 KB

The following example displays sample output of the show ip ssh rekey statistics command.

device# show ip ssh rekey statistics 
SSH Server Rekey Statistics:
1     Time :   24 Sec,   Data :     996632 Bytes
2     closed
3     closed
4     closed
5     closed
SSH Client Rekey Statistics:
6     Time :  596 Sec, Data :    2999556 Bytes
7     closed
8     closed
9     closed
10    closed
11    closed
12    closed
13    closed
14    closed
15    closed
16    closed
17    closed
18    closed
History
Release version Command history
08.0.70 This command was modified to add the rekey statistics option.