SSH

To enable SSH, you must generate RSA encryption keys using the following command.

device(config)# crypto key generate rsa  modulus 2048 
device(config)#
Creating RSA key pair, please wait...
RSA Key pair is successfully created

To confirm that SSH is enabled, use the show ip ssh command.

device# show ip ssh 
No SSH sessions are currently established
SSH-v2.0 enabled; hostkey: RSA(2048)

Note: By default, when an SSH connection is established, it opens in interactive mode in FastIron 10.0.10d release.
Note: If you zeroize the RSA keys, the SSH server is disabled.

Zeroize the keys as shown in the following example.

device(config)# crypto key zeroize  rsa 
RSA Key pair is successfully deleted

Use the show ip ssh command to confirm that SSH is disabled.

device(config)# show ip ssh 
No SSH sessions are currently established
SSH-v2.0 disabled

To establish a connection from the client side, enable a local user and set a user password. The following rules apply to passwords:

  1. Passwords must be at least eight characters long.
    Note: The password can be from 8 through 60 characters in length.
    Note: You can configure the device to require passwords be at least a specified length with the enable password-min-length command.
  2. Passwords must consist of characters from all four character classes: uppercase, lowercase, numeric, and ASCII non-alphanumeric characters.
    Note: ASCII non-alphanumeric characters include the following characters:

    '!', '@', '#', '$', '%', '^', '&', '(', ')'

Note: In FIPS and CC modes, after three incorrect attempts to enter the password, user access is disabled until login recovery time is reached. The default recovery time is three minutes. The recovery time is configurable using the enable user disable-on-login-failure command.

To enable a user, enter commands similar to the following.

device# configure terminal 
device(config)# user test password tesT123$$

The example enables the user "test". It then sets the user password to "tesT123$$".

Note: The user configured in the previous example, "test," is a crypto officer who will be able to modify or delete the configuration. To create a read-only user, use a command similar to the following example thta includes the keywords privilege 5.
device(config)# user test privilege 5 password tesT123$$

Login

When a user tries to log in with correct username and password, the login is successful. The following syslog message is generated for a successful login attempt:

SYSLOG: <14> Dec 18 09:03:26 Device Security: SSH login by admin from src IP 15.15.15.1 from src MAC 0200.8801.8132 to USER EXEC mode using RSA as Server Host Key.

Logout

When the user "admin" closes the session from the TOE, the session is disconnected. The following syslog message is generated for a successful logout attempt:

SYSLOG: <14> Dec 18 09:09:11 Device Security: SSH logout by admin from src IP 15.15.15.1 from src MAC 0200.8801.8132 from USER EXEC mode using RSA as Server Host Key.

Failed login attempts

By default, the user is disabled after three failed attempts to login. Each time a user connects with a wrong password, a syslog message is displayed. The following example indicates three unsuccessful login attempts.

SYSLOG: <14> Dec 18 09:18:14 Device Security: SSH access by user admin from src IP 15.15.15.1 rejected, 1 attempt(s)

SYSLOG: <14> Dec 18 09:18:15 Device Security: SSH access by user admin from src IP 15.15.15.1 rejected, 2 attempt(s)

SYSLOG: <14> Dec 18 09:18:16 Device Security: SSH access by user admin from src IP 15.15.15.1 rejected, 3 attempt(s) 

The number of attempts and the time for which the user is disabled is configurable. Use the enable user disable-on-login-failure command with appropriate parameters to configure the number of login attempts before a user is disabled and the amount of time the system is blocked before the user is allowed to attempt login again.

Note: To prevent all admin accounts from being locked out entirely, the disable-on-logon-failure feature applies only to SSH and does not apply to the local console.

The following example allows four failed login attempts before the user is disabled and the recovery time of five seconds begins.

device# configure terminal
device(config)# enable user disable-on-login-failure 4 login-recovery-time in-secs 5

Syntax:[ no ] enable user { disable-on-login-failure [ invalid-attempts login-recovery-time { in-hours | in-mins | in-secs } recovery-time ] }

Note: By default, the user is allowed three login attempts. In CC mode, the default recovery time for re-enabling user accounts is three minutes.

Login attempts can be any decimal value from 1 through 10.

Login recovery time can be specified in hours, minutes, or seconds.

Note: You must configure users before enabling the aaa console; otherwise, you may be logged off and locked out of the system.