Use this information to identify and resolve common SSH connection problems.
Connection and key-generation problems
Table 1. SSH connection troubleshooting
| Symptom or message |
Possible cause |
Resolution |
|
An SSHv1 connection is rejected.
|
|
Confirm that the remote server accepts SSHv1. On the server, configure a hostname and domain, generate an RSA key pair with the crypto key generate rsa command in EXEC mode, and enable the SSH server.
|
|
An SSHv2 connection is rejected.
|
The DSA, RSA, or ECDSA key pair required for the connection was zeroized.
|
Configure a hostname and domain, generate the required key pair with the applicable crypto key generate command in EXEC mode, and enable the SSH server.
|
|
No hostname specified
|
The router does not have a configured hostname.
|
Configure the router hostname with the hostname command.
|
|
No domain specified
|
The router does not have a configured domain name.
|
Configure the router domain with the domain name command.
|
SSH connection capacity
Each SSH connection consumes one virtual terminal (VTY) resource. The number of concurrent SSH connections cannot exceed the number of VTY lines configured in the VTY pool.
Configure enough VTY lines in the VTY pool for the required number of concurrent SSH connections.
FIPS cipher requirements
In FIPS mode, use an AES-CTR cipher. FIPS mode does not support weaker ciphers such as 3DES or AES-CBC.
AAA authentication considerations
SSH uses local authentication or remote authentication configured through authentication, authorization, and accounting (AAA). When configuring AAA, apply the global configuration keyword that disables AAA on the console so that the console does not operate under AAA.
PuTTY interoperability
When using PuTTY 0.63 or later, go to SSH > Bugs and set Chokes on PuTTY's SSH2 winadj request to On. This setting helps prevent the session from breaking down when Cisco IOS XR sends lengthy output to the PuTTY client.