Enabling SSH Access
By default, there are no restrictions on access for management protocols, including SSH. To allow SSHv2 access to a RUCKUS ICX device, you must generate a Crypto Key. At the beginning of an SSH session, the RUCKUS ICX device negotiates the version of SSHv2 to be used. The highest version of SSHv2 supported by both the RUCKUS ICX device and the client is used for the session. Once the SSHv2 version is negotiated, the encryption algorithm with the highest security ranking is selected for the session. You can use an SSH client that is equivalent to OpenSSH v7.5 or later.
To enable SSH, generate an ECDSA or RSA host key on the device. The SSH server on the RUCKUS ICX device uses this key, along with a dynamically generated server key pair, to negotiate a session key and encryption method with the client trying to connect to it. While the SSH listener exists at all times, sessions cannot be started from clients until a host key is generated. After a host key is generated, clients can start sessions.
To enable SSH, generate a client RSA key pair with a modulus size of 2048 bits using the following command.
device# configure terminal device(config)# crypto key generate rsa modulus 2048 Creating RSA key pair, please wait... RSA Key pair is successfully created, it may take up to 5s for SSH to come up.
The previous example generates a modulus 2048-bit key. RSA Host keys with a size of 2048, 3072, or 4096 bits can be created.
Generate ECDSA key pair using the following command.
device# configure terminal device(config)# crypto key generate ec size 384 Creating EC key pair, please wait... Successfully generated EC key pair of size 384 label
The previous example creates an ECDSA key pair with a size of 384 bits. Valid ECDSA key sizes are 256, 384, and 521.
To confirm that SSH is enabled, use the
show ip ssh
command.
device# show ip ssh SSH-v2.0 enabled. No SSH sessions are currently established
You can delete the RSA key pairs with the
crypto key zeroize
command, or you can specify a key pair to be deleted. When a host key is deleted,
it is
deleted from the flash memory of all management modules. If all key pairs are removed
from the flash memory, SSH will get disabled.
Delete or zeroize the keys as shown in the following example.
device# configure terminal device(config)# crypto key zeroize rsa RSA Key pair is successfully deleted
Use the show ip ssh command to
confirm that SSH is disabled.
device(config)# show ip ssh No SSH sessions are currently established SSH-v2.0 disabled
To establish a connection from the client side, enable a local user and set a user password.
To create a user, enter commands similar to the following.
device# configure terminal device(config)# user test password tesT123$$
The example enables the user "test". It then sets the user password to "tesT123$$".
device(config)# user test privilege 5 password tesT123$$
When a user tries to log in with the correct username and password, the login is successful. The following syslog message is generated for a successful login attempt:
2025-04-04T05:14:51Z:I: Test121113111aaa1 ICX7550 - General [meta sequenceId=18] BOM Security: ssh login by cli from src IP 10.246.201.17, src MAC c0c5.206b.5712, src PORT 48390 to dest IP 10.176.156.34, dest PORT 22 to USER EXEC mode
When the user "admin" closes the session with the RUCKUS ICX device, the session is disconnected. The following syslog message is generated for a successful logout attempt:
2025-04-04T05:15:11Z:I: Test121113111aaa1 ICX7550 - General [meta sequenceId=19] BOM Security: ssh logout by cli from src IP 10.246.201.17, src MAC c0c5.206b.5712, src PORT 48390 to dest IP 10.176.156.34, dest PORT 22 from USER EXEC mode
By default, the user is disabled after three failed attempts to log in. Each time a user connects with a wrong password or username, a syslog message is displayed.
SYSLOG: <14>1 2025-04-04T05:15:59Z Test121113111aaa1 ICX7550 - General [meta sequenceId=21] BOM sshd: SSH access by user cli from src IP 10.246.201.17 rejected, 1 attempt(s)
The number of attempts and the time for
which the user is disabled is configurable. Use the enable user
disable-on-login-failure command with appropriate parameters to configure
the number of login attempts before a user is disabled and the amount of time the
system
is blocked before the user is allowed to attempt login again.
The following example allows four failed login attempts before the user is disabled and the recovery time of five seconds begins.
device# configure terminal device(config)# enable user disable-on-login-failure 4 login-recovery-time in-secs 5
Syntax:[ no
]
enable user
{
disable-on-login-failure
[
invalid-attempts
login-recovery-time
{
in-hours
|
in-mins
|
in-secs
}
recovery-time
]
}
Login attempts can be any decimal value from 1 through 10.
Login recovery time can be specified in hours (1 through 2), minutes (3 through 120), or seconds (2 through 7200).