System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

PDF

System Security Configuration Guide for Cisco 8000 Series Routers, IOS XR Releases

SSH authentication attempt limits

Want to summarize with AI?

Log in

Explains the overall SSH authentication-attempt limit and the separate fixed limit for password authentication on Cisco IOS XR SSH servers.


The SSH authentication-attempt limit is a server-wide control that

  • counts attempts across public-key, certificate-based, keyboard-interactive, and password authentication

  • denies the connection when the overall limit is reached, and

  • applies the same configured value to every user.

The configurable range is 3 through 20, with a default of 20. Before Release 7.3.2, the range was 4 through 20. Password authentication retains a separate maximum of three attempts regardless of the overall setting.

Table 1. Feature History Table

Feature Name

Release Information

Feature Description

User Configurable Maximum Authentication Attempts for SSH

Release 25.4.1

Introduced in this release on: Fixed Systems (8010 [ASIC: A100]) (select variants only*)

*This feature is supported on:

  • 8011-32Y8L2H2FH

  • 8011-12G12X4Y-A/D

User Configurable Maximum Authentication Attempts for SSH

Release 25.1.1

Introduced in this release on: Fixed Systems (8700 [ASIC: K100], 8010 [ASIC: A100]) (select variants only*)

*This feature is supported on:

  • 8712-MOD-M

  • 8011-4G24Y4H-I

User Configurable Maximum Authentication Attempts for SSH

Release 24.4.1

Introduced in this release on: Fixed Systems (8200 [ASIC: P100], 8700 [ASIC: P100]) (select variants only*); Modular Systems (8800 [LC ASIC: P100]) (select variants only*)

*This feature is supported on:

  • 8212-48FH-M

  • 8711-32FH-M

  • 88-LC1-36EH

  • 88-LC1-12TH24FH-E

  • 88-LC1-52Y8H-EM

User Configurable Maximum Authentication Attempts for SSH

Release 7.3.1

This feature allows you to set a limit on the number of user authentication attempts allowed for SSH connection, using the three authentication methods that are supported by Cisco IOS XR. The limit that you set is an overall limit that covers all the authentication methods together. If the user fails to enter the correct login credentials within the configured number of attempts, the connection is denied and the session is terminated.

This command is introduced for this feature:

ssh server max-auth-limit

SSH authentication attempt restrictions

Review these restrictions before configuring the maximum number of SSH authentication attempts.

Maximum SSH authentication attempts have these restrictions:

  • The feature is available only when the Cisco IOS XR router functions as an SSH server. It does not apply when the router functions as an SSH client.

  • The configuration is not user-specific. The configured limit is the same for all users.

  • For security reasons, the SSH server permits a maximum of three authentication attempts that explicitly use password authentication. Configuring the maximum SSH authentication-attempt limit does not change this password-specific limit.

Password authentication example

If you configure the overall maximum authentication-attempt limit as five by using ssh server max-auth-limit 5 , the SSH server still permits only three attempts that explicitly use password authentication.


Set the maximum SSH authentication attempts

Terminate SSH connections whose authentication failures reach the configured overall limit.

The setting applies only when the router acts as an SSH server and uses the same limit for all users. Password authentication remains limited to three attempts.

Procedure

  1. Set the maximum authentication attempts and commit the configuration.

    Example:

    Router# configure
    Router(config)# ssh server max-auth-limit 5
    Router(config)# commit
  2. Verify the configured value.

    Example:

    Router# show running-configuration ssh
    ssh server max-auth-limit 5
    ssh server v2

When the overall limit is reached, the router terminates the session and reports Max authentication tries reached-exiting in a SECURITY-SSHD-3-ERR_GENERAL Syslog message.