Set Optional Parameters
- (Optional) Enter the
ip ssh authentication-retriescommand followed by a value from 1 through 5 to set the number of authentication retries.Note: Theip ssh authentication-retriescommand is applicable only to SSH clients such as PUTTY and Secure CRT. The command is not applicable on RUCKUS ICX devices acting as SSH clients. When a RUCKUS ICX device acts as an SSH client and you try to establish an SSH connection with the wrong credentials, the session is not established, and the connection is terminated. - (Optional) Update the key
exchange methods if needed. Note: By default, both the diffie-helman-group14-sha-1 and diffie-hellman-group-1-sha1 key exchange methods are available, and diffie-hellman-group14-sha-1 will be given priority. The diffie-hellman-group14-sha-1 option is non-configurable. The diffie-hellman-group1-sha-1 method is weaker and can be removed if desired.Note: High CPU usage is expected while establishing SSH sessions with the diffie-hellman-group14-sha1 key-exchange method.The following example removes the weaker of the two available key exchange methods, diffie-helman-group1-sha1.
- (Optional) Specify whether empty passwords are allowed. By default, they are not allowed.
The following example allows empty passwords.The following example disables empty password logins.
- (Optional) Assign a new port to carry SSH traffic.
The following example re-assigns port 2200 for SSH traffic.
- (Optional) Specify an SSH connection timeout value from 1 through 120 seconds. The
default is 120 seconds.
The following example configures an SSH connection timeout of 60 seconds.
- (Optional) Specify an interface type to be used for the SSH connection.
The following example sets Ethernet port 1/2/4 as the SSH source interface on the RUCKUS ICX device.
- (Optional) Set the idle time for SSH sessions. The default is 5 minutes.
The following example configures SSH sessions to never time out due to inactivity.The following example configures SSH sessions to time out after 30 minutes of inactivity.
- (Optional) Configure the interval for SSH rekey exchange.
The following example sets the rekey exchange interval to 5 minutes.