SSH
To enable SSH, you must generate RSA encryption keys using the following command.
device(config)# crypto key generate rsa modulus 2048 device(config)# Creating RSA key pair, please wait... RSA Key pair is successfully created
To confirm that SSH is enabled, use the
show ip ssh command.
device# show ip ssh No SSH sessions are currently established SSH-v2.0 enabled; hostkey: RSA(2048)
Zeroize the keys as shown in the following example.
device(config)# crypto key zeroize rsa RSA Key pair is successfully deleted
Use the
show ip ssh command to confirm that SSH is disabled.
device(config)# show ip ssh No SSH sessions are currently established SSH-v2.0 disabled
To establish a connection from the client side, enable a local user and set a user password. The following rules apply to passwords:
- Passwords must be at least eight characters long.
- Passwords must consist of characters from three or more of these character classes: uppercase, lowercase, numerical, ASCII non-alphanumeric.
- The password must not end with the only numeric character in the password.
To enable a user, enter commands similar to the following.
device# configure terminal device(config)# enable password-min-length 9 device(config)# user test password tesT123$$
The example enables the user "test" and defines the minimum password length as 9 characters. It then sets the user password to "tesT123$$".
device(config)# user test privilege 5 password tesT123$$
When a user tries to log in with correct username and password, the login is successful. The following syslog message is generated for a successful login attempt:
SYSLOG: <14> Dec 18 09:03:26 Device Security: SSH login by admin from src IP 15.15.15.1 from src MAC 0200.8801.8132 to USER EXEC mode using RSA as Server Host Key.
When the user "admin" closes the session from the TOE, the session is disconnected. The following syslog message is generated for a successful logout attempt:
SYSLOG: <14> Dec 18 09:09:11 Device Security: SSH logout by admin from src IP 15.15.15.1 from src MAC 0200.8801.8132 from USER EXEC mode using RSA as Server Host Key.
By default, the user is disabled after three failed attempts to login. Each time a user connects with a wrong password, a syslog message is displayed. The following example indicates three unsuccessful login attempts.
SYSLOG: <14> Dec 18 09:18:14 Device Security: SSH access by user admin from src IP 15.15.15.1 rejected, 1 attempt(s) SYSLOG: <14> Dec 18 09:18:15 Device Security: SSH access by user admin from src IP 15.15.15.1 rejected, 2 attempt(s) SYSLOG: <14> Dec 18 09:18:16 Device Security: SSH access by user admin from src IP 15.15.15.1 rejected, 3 attempt(s)
The number of attempts and the time for which the user is disabled is configurable.
Use the
enable user disable-on-login-failure command with appropriate parameters to configure the number of login attempts before
a user is disabled and the amount of time the system is blocked before the user is
allowed to attempt login again.
The following example allows four failed login attempts before the user is disabled and the recovery time of five seconds begins.
device# configure terminal device(config)# enable user disable-on-login-failure 4 login-recovery-time in-secs 5
Syntax:
[ no ]
enable user
{
disable-on-login-failure
[
invalid-attempts
login-recovery-time
{
in-hours
|
in-mins
|
in-secs
}
recovery-time
]
}
Login attempts can be any decimal value from 1 through 10.
Login recovery time can be specified in hours, minutes, or seconds.