System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

Configure an SSH client

Want to summarize with AI?

Log in

Configures server host-key validation and starts an authenticated outbound SSH connection from a Cisco IOS XR router to a remote server.


Connect securely from the router to a remote SSH server.

Before you begin

  • Configure local or remote AAA authentication.

  • Configure enough VTY lines for the required concurrent connections. The default VTY count is 5, and the source states a default maximum of 64 SSH sessions.

  • Use AES-CTR in FIPS mode; 3DES and AES-CBC are not supported in that mode.

Procedure

  1. Optionally configure the complete path to a known-host public-key file and commit the configuration.

    Example:

    Router# configure
    Router(config)# ssh client knownhost harddisk:/server_pubkey
    Router(config)# commit

    Include both the colon and slash in the device path.

  2. Optionally set the DSCP value for packets sent by the SSH client.

    Example:

    Router# configure
    Router(config)# ssh client dscp 63
    Router(config)# commit

    Use a value from 0 through 63. If you do not configure a value, the client and server use 16.

  3. Start an outbound SSH connection.

    Example:

    Router# ssh 192.0.2.1 username sample-user1
    • The client first attempts SSHv2. The remote peer can select SSHv1 only when it supports the legacy server.

    • The DES option applies only to an SSHv1 client.

    • When a hostname resolves to IPv4 and IPv6 addresses, the client uses IPv6.

  4. Optionally execute a command on the remote router through the SSH session.

    Example:

    Router# ssh 192.0.2.1 username admin command "show redundancy sum"
    Password:
    
        Active Node    Standby Node
        -----------    ------------
           0/4/CPU0        0/5/CPU0 (Node Ready, NSR: Not Configured)
    Router#

    The remote router returns the command output through the encrypted SSH session.

The router authenticates the remote server when a known-host file is configured, applies the optional packet marking, and opens the outbound SSH session.


Troubleshoot SSH client connections

Use this information to identify and resolve common SSH connection problems.

Connection and key-generation problems

Table 1. SSH connection troubleshooting
Symptom or message Possible cause Resolution

An SSHv1 connection is rejected.

  • The RSA key pair was zeroized.

  • The remote SSH server does not accept SSHv1 connections.

Confirm that the remote server accepts SSHv1. On the server, configure a hostname and domain, generate an RSA key pair with the crypto key generate rsa command in EXEC mode, and enable the SSH server.

An SSHv2 connection is rejected.

The DSA, RSA, or ECDSA key pair required for the connection was zeroized.

Configure a hostname and domain, generate the required key pair with the applicable crypto key generate command in EXEC mode, and enable the SSH server.

No hostname specified

The router does not have a configured hostname.

Configure the router hostname with the hostname command.

No domain specified

The router does not have a configured domain name.

Configure the router domain with the domain name command.

SSH connection capacity

Each SSH connection consumes one virtual terminal (VTY) resource. The number of concurrent SSH connections cannot exceed the number of VTY lines configured in the VTY pool.

  • The default number of VTY lines is 5.

  • The default maximum number of SSH sessions is 64.

Configure enough VTY lines in the VTY pool for the required number of concurrent SSH connections.

FIPS cipher requirements

In FIPS mode, use an AES-CTR cipher. FIPS mode does not support weaker ciphers such as 3DES or AES-CBC.

AAA authentication considerations

SSH uses local authentication or remote authentication configured through authentication, authorization, and accounting (AAA). When configuring AAA, apply the global configuration keyword that disables AAA on the console so that the console does not operate under AAA.

PuTTY interoperability

When using PuTTY 0.63 or later, go to SSH > Bugs and set Chokes on PuTTY's SSH2 winadj request to On. This setting helps prevent the session from breaking down when Cisco IOS XR sends lengthy output to the PuTTY client.