System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

Requirements for Secure Shell

Want to summarize with AI?

Log in

Provides user access-control, VRF, AAA, host-key, and SFTP requirements that must be satisfied before configuring or using secure SSH services.


Satisfy the access, routing, authentication, and key requirements before you enable SSH services.

  • Use a user group whose task group includes the task IDs required by each command.

  • Provide the default VRF or a specific VRF for an SSHv2 server.

  • Configure local or remote user authentication through AAA.

  • Configure AAA authentication and authorization for SFTP.

  • Keep at least one default host key on a router that accepts incoming SSH sessions. FIPS mode requires a default RSA or ECDSA key.