Enabling SSH Access

By default, there are no restrictions on access for management protocols, including SSH. To allow SSHv2 access to a RUCKUS ICX device, you must generate a Crypto Key. At the beginning of an SSH session, the RUCKUS ICX device negotiates the version of SSHv2 to be used. The highest version of SSHv2 supported by both the RUCKUS ICX device and the client is used for the session. Once the SSHv2 version is negotiated, the encryption algorithm with the highest security ranking is selected for the session. You can use an SSH client that is equivalent to OpenSSH v7.5 or later.

To enable SSH, generate an ECDSA or RSA host key on the device. The SSH server on the RUCKUS ICX device uses this key, along with a dynamically generated server key pair, to negotiate a session key and encryption method with the client trying to connect to it. While the SSH listener exists at all times, sessions cannot be started from clients until a host key is generated. After a host key is generated, clients can start sessions.

To enable SSH, generate a client RSA key pair with a modulus size of 2048 bits using the following command.

device# configure terminal
device(config)# crypto key generate rsa  modulus 2048 
Creating RSA key pair, please wait...
RSA Key pair is successfully created, it may take up to 5s for SSH to come up.

The previous example generates a modulus 2048-bit key. RSA Host keys with a size of 2048, 3072, or 4096 bits can be created.

Generate ECDSA key pair using the following command.

device# configure terminal
device(config)# crypto key generate ec size 384
Creating EC key pair, please wait...
Successfully generated EC key pair of size 384 label

The previous example creates an ECDSA key pair with a size of 384 bits. Valid ECDSA key sizes are 256, 384, and 521.

To confirm that SSH is enabled, use the show ip ssh command.

device# show ip ssh 
SSH-v2.0 enabled.
No SSH sessions are currently established

Note: By default, when an SSH connection is established, it opens in interactive mode.
Note: If you zeroize the RSA keys, the SSH server is disabled.

You can delete the RSA key pairs with the crypto key zeroize command, or you can specify a key pair to be deleted. When a host key is deleted, it is deleted from the flash memory of all management modules. If all key pairs are removed from the flash memory, SSH will get disabled.

Delete or zeroize the keys as shown in the following example.

device# configure terminal
device(config)# crypto key zeroize rsa 
RSA Key pair is successfully deleted

Use the show ip ssh command to confirm that SSH is disabled.

device(config)# show ip ssh 
No SSH sessions are currently established
SSH-v2.0 disabled

To establish a connection from the client side, enable a local user and set a user password.

To create a user, enter commands similar to the following.

device# configure terminal 
device(config)# user test password tesT123$$

The example enables the user "test". It then sets the user password to "tesT123$$".

Note: The user configured in the previous example, "test," is a crypto officer who will be able to modify or delete the configuration. To create a read-only user, use a command similar to the following example that includes the keywords privilege 5.
device(config)# user test privilege 5 password tesT123$$

Login

When a user tries to log in with the correct username and password, the login is successful. The following syslog message is generated for a successful login attempt:

2025-04-04T05:14:51Z:I: Test121113111aaa1 ICX7550 - General [meta sequenceId=18] BOM Security: ssh login by cli from src IP 10.246.201.17, 
src MAC c0c5.206b.5712, src PORT 48390 to dest IP 10.176.156.34, dest PORT 22 to USER EXEC mode

Logout

When the user "admin" closes the session with the RUCKUS ICX device, the session is disconnected. The following syslog message is generated for a successful logout attempt:

2025-04-04T05:15:11Z:I: Test121113111aaa1 ICX7550 - General [meta sequenceId=19] BOM Security: ssh logout by cli from src IP 10.246.201.17,
src MAC c0c5.206b.5712, src PORT 48390 to dest IP 10.176.156.34, dest PORT 22 from USER EXEC mode

Failed login attempts

By default, the user is disabled after three failed attempts to log in. Each time a user connects with a wrong password or username, a syslog message is displayed.

SYSLOG: <14>1 2025-04-04T05:15:59Z Test121113111aaa1 ICX7550 - General [meta sequenceId=21]
BOM sshd: SSH access by user cli from src IP 10.246.201.17 rejected, 1 attempt(s) 

The number of attempts and the time for which the user is disabled is configurable. Use the enable user disable-on-login-failure command with appropriate parameters to configure the number of login attempts before a user is disabled and the amount of time the system is blocked before the user is allowed to attempt login again.

The following example allows four failed login attempts before the user is disabled and the recovery time of five seconds begins.

device# configure terminal
device(config)# enable user disable-on-login-failure 4 login-recovery-time in-secs 5

Syntax:[ no ] enable user { disable-on-login-failure [ invalid-attempts login-recovery-time { in-hours | in-mins | in-secs } recovery-time ] }

Note: By default, the user is allowed three login attempts. In Korean CC mode, the default recovery time for re-enabling user accounts is three minutes.

Login attempts can be any decimal value from 1 through 10.

Login recovery time can be specified in hours (1 through 2), minutes (3 through 120), or seconds (2 through 7200).