show ip ssh

Displays Secure Shell (SSH) connection session details.
Syntax
show ip ssh [config]
Parameters
config
Displays the SSH configuration details.
Modes

User EXEC mode

The show ip ssh command displays the following information:

Output field Description
Inbound Connections listed under this heading are inbound.
Outbound Connections listed under this heading are outbound.
Connection The SSH connection ID.
Version The SSH version number.
Username The username for the connection.
IP Address The IP address of the SSH client.
SSH-v2.0 enabled Indicates that SSHv2 is enabled.
hostkey Indicates that at least one host key is on the device. It is followed by a list of the host key types and module sizes.

The show ip ssh config command displays the following information:

Output field Description
SSH server SSH server is enabled or disabled.
SSH port SSH port number.
Host Key Host key.
Encryption The encryption used for the SSH connection. The following values are displayed:
  • AES-256, AES-192, and AES-128 indicate the different AES methods used for encryption.
Authentication methods The authentication methods used for SSH. The authentication can have one or more of the following values:
  • Password: Indicates that you are prompted for a password when attempting to log in to the device.
  • Public-key: Indicates that DSA or RSA challenge-response authentication is enabled.
  • Interactive: Indicates the interactive authentication is enabled.
Authentication retries The number of authentication retries. This number can be from 1 through 5.
Login timeout (seconds) SSH login timeout value in seconds. This can be from 0 through 120.
Idle timeout (minutes) SSH idle timeout value in minutes. This can be from 0 through 240.
Strict management VRF Strict management VRF is enabled or disabled.
SCP SCP is enabled or disabled.
Client Rekey The SSH rekey interval configured for the client, in minutes and maximum data.
Server Rekey The SSH rekey interval configured for the server, in minutes and maximum data.
Examples

The following example displays sample output of the show ip ssh command.

device# show ip ssh
Connection  Version   Username  IP Address
Inbound:
1           SSH-2     Raymond   10.120.54.2
Outbound:
6           SSH-2     Steve     10.37.77.15
SSH-v2.0 enabled; hostkey:  RSA(2048)

The following example displays sample output of the show ip ssh config command.

device# show ip ssh config
SSH server                 : Enabled
SSH port                   : tcp\22
Host Key                   : RSA 3072, ECDSA 384
Encryption                 : chacha20-poly1305@openssh.com,aes128-gcm@openssh.com,aes256-gcm@openssh.com,
                             aes128-ctr,aes192-ctr,aes256-ctr
Authentication methods     : Password, Public-key, Interactive
Login timeout (seconds)    : 120
SCP                        : Enabled
SSH Client Keys            :
Client Rekey               : 500000K 30m (KB, Minute)
Server Rekey               : 500000K 30m (KB, Minute)
History
Release version Command history
08.0.70 This command was modified to add the rekey statistics option.
09.0.00 This command was modified to remove the rekey statistics keyword. The SSH IPv4 access-group and SSH IPv6 access-group fields were removed from the output for the show ip ssh config command. The Encryption, HMAC, and Server Hostkey fields were removed from the output for the show ip ssh command.
10.0.10h_cd1 The Encryption field is modified for the show ip ssh config command.