Enabling and Disabling SSH by Generating and Deleting Host Keys

To enable SSH, generate a DSA or RSA host key on the device. The SSH server on the RUCKUS ICX device uses this host DSA or RSA key, along with a dynamically generated server DSA or RSA key pair, to negotiate a session key and encryption method with the client trying to connect to it.

While the SSH listener exists at all times, sessions cannot be started from clients until a host key is generated. After a host key is generated, clients can start sessions.

Note: DSA encryption is deprecated in OpenSSH client versions 7.0. Password authentication may be required.

To disable SSH, delete all of the host keys from the device.

Note: In FastIron release 08.0.95h, the ip ssh disable command can be used to disable SSH and close port 22 (the default port for SSH) or the port where SSH has been configured. The no ip ssh disable command re-enables SSH on default port 22.

When a host key is generated, it is saved to the flash memory of all management modules. When a host key is deleted, it is deleted from the flash memory of all management modules.

The time required to initially generate SSH keys varies depending on the configuration and can be from a under a minute to several minutes.