Explains the overall SSH authentication-attempt limit and the separate fixed limit for password authentication on Cisco IOS XR SSH servers.
The SSH authentication-attempt limit is a server-wide control that
-
counts attempts across public-key, certificate-based, keyboard-interactive, and password authentication
-
denies the connection when the overall limit is reached, and
-
applies the same configured value to every user.
The configurable range is 3 through 20, with a default of 20. Before Release 7.3.2, the range was 4 through 20. Password authentication retains a separate maximum of three attempts regardless of the overall setting.
|
Feature Name |
Release Information |
Feature Description |
|---|---|---|
|
User Configurable Maximum Authentication Attempts for SSH |
Release 25.4.1 |
Introduced in this release on: Fixed Systems (8010 [ASIC: A100]) (select variants only*) *This feature is supported on:
|
|
User Configurable Maximum Authentication Attempts for SSH |
Release 25.1.1 |
Introduced in this release on: Fixed Systems (8700 [ASIC: K100], 8010 [ASIC: A100]) (select variants only*) *This feature is supported on:
|
|
User Configurable Maximum Authentication Attempts for SSH |
Release 24.4.1 |
Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100]) (select variants only*); Modular Systems (8800 [LC ASIC: P100]) (select variants only*) *This feature is supported on:
|
|
User Configurable Maximum Authentication Attempts for SSH |
Release 7.3.1 |
This feature allows you to set a limit on the number of user authentication attempts allowed for SSH connection, using the three authentication methods that are supported by Cisco IOS XR. The limit that you set is an overall limit that covers all the authentication methods together. If the user fails to enter the correct login credentials within the configured number of attempts, the connection is denied and the session is terminated. This command is introduced for this feature: ssh server max-auth-limit |