Set Optional Parameters

Perform any of the following steps if necessary to change optional SSH parameters.
  1. (Optional) Enter the ip ssh authentication-retries command followed by a value from 1 through 5 to set the number of authentication retries.
    Note: The ip ssh authentication-retries command is applicable only to SSH clients such as PUTTY and Secure CRT. The command is not applicable on RUCKUS ICX devices acting as SSH clients. When a RUCKUS ICX device acts as an SSH client and you try to establish an SSH connection with the wrong credentials, the session is not established, and the connection is terminated.
    device# configure terminal
    device(config)# ip ssh authentication-retries 5
    
  2. (Optional) Update the key exchange methods if needed.
    Note: By default, both the diffie-helman-group14-sha-1 and diffie-hellman-group-1-sha1 key exchange methods are available, and diffie-hellman-group14-sha-1 will be given priority. The diffie-hellman-group14-sha-1 option is non-configurable. The diffie-hellman-group1-sha-1 method is weaker and can be removed if desired.
    Note: High CPU usage is expected while establishing SSH sessions with the diffie-hellman-group14-sha1 key-exchange method.
    The following example removes the weaker of the two available key exchange methods, diffie-helman-group1-sha1.
    device(config)# no ip ssh key-exchange-method dh-group1-sha1
    
  3. (Optional) Specify whether empty passwords are allowed. By default, they are not allowed.
    The following example allows empty passwords.
    device(config)# ip ssh permit-empty-passwd yes
    
    The following example disables empty password logins.
    device(config)# ip ssh permit-empty-passwd no
    
  4. (Optional) Assign a new port to carry SSH traffic.
    The following example re-assigns port 2200 for SSH traffic.
    Note: If you change the SSH port number, RUCKUS recommends that you change it to a port number greater than 1024.
    device(config)# ip ssh port 2200
    
  5. (Optional) Specify an SSH connection timeout value from 1 through 120 seconds. The default is 120 seconds.
    The following example configures an SSH connection timeout of 60 seconds.
    device(config)# ip ssh timeout 60
    
  6. (Optional) Specify an interface type to be used for the SSH connection.
    The following example sets Ethernet port 1/2/4 as the SSH source interface on the RUCKUS ICX device.
    device(config)# ip ssh source interface ethernet 1/2/4
  7. (Optional) Set the idle time for SSH sessions. The default is 5 minutes.
    The following example configures SSH sessions to never time out due to inactivity.
    device(config)# ip ssh idle-time 0
    
    The following example configures SSH sessions to time out after 30 minutes of inactivity.
    device(config)# ip ssh idle-time 30
    
  8. (Optional) Configure the interval for SSH rekey exchange.
    The following example sets the rekey exchange interval to 5 minutes.
    device(config)# ip ssh rekey time 5