<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Disable SSHv1 2960 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/disable-sshv1-2960/m-p/2727199#M917296</link>
    <description>&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;I've got a 2960-x running SSHv1.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;1) I need to disable SSHv1 and only run V2. Will the line listed below run ONLY SSHv2 and disable V1?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;2) I need a cisco document that says SSHv1 can&amp;nbsp; be completely disabled and only V2 runs on a 2960x.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;&lt;SPAN style="font-size: 14px;"&gt;I know that I need to add the following line:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;&lt;SPAN style="font-size: 14px;"&gt;#IP SSH version 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 115%; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-CA; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;FONT color="#000000"&gt;Cisco IOS Software, C2960X Software (C2960X-UNIVERSALK9-M), Version 15.0(2)EX5, RELEASE &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;2960x-Switch#sho ip ssh&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;SSH Enabled - version 1.99&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;Authentication timeout: 120 secs; Authentication retries: 3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;Minimum expected Diffie Hellman key size : 1024 bits&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;IOS Keys in SECSH format(ssh-rsa, base64 encoded):&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;Krista&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 13:33:32 GMT</pubDate>
    <dc:creator>Krista Bowman</dc:creator>
    <dc:date>2020-02-21T13:33:32Z</dc:date>
    <item>
      <title>Disable SSHv1 2960</title>
      <link>https://community.cisco.com/t5/network-security/disable-sshv1-2960/m-p/2727199#M917296</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;Hi,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;I've got a 2960-x running SSHv1.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;1) I need to disable SSHv1 and only run V2. Will the line listed below run ONLY SSHv2 and disable V1?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px;"&gt;2) I need a cisco document that says SSHv1 can&amp;nbsp; be completely disabled and only V2 runs on a 2960x.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;&lt;SPAN style="font-size: 14px;"&gt;I know that I need to add the following line:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-left: 40px;"&gt;&lt;SPAN style="font-size: 14px;"&gt;#IP SSH version 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="line-height: 115%; font-family: &amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;; font-size: 11pt; mso-ascii-theme-font: minor-latin; mso-fareast-font-family: Calibri; mso-fareast-theme-font: minor-latin; mso-hansi-theme-font: minor-latin; mso-bidi-font-family: &amp;quot;Times New Roman&amp;quot;; mso-bidi-theme-font: minor-bidi; mso-ansi-language: EN-CA; mso-fareast-language: EN-US; mso-bidi-language: AR-SA;"&gt;&lt;FONT color="#000000"&gt;Cisco IOS Software, C2960X Software (C2960X-UNIVERSALK9-M), Version 15.0(2)EX5, RELEASE &lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;2960x-Switch#sho ip ssh&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;SSH Enabled - version 1.99&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;Authentication timeout: 120 secs; Authentication retries: 3&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;Minimum expected Diffie Hellman key size : 1024 bits&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;IOS Keys in SECSH format(ssh-rsa, base64 encoded):&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;Thanks!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 12px;"&gt;Krista&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:33:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-sshv1-2960/m-p/2727199#M917296</guid>
      <dc:creator>Krista Bowman</dc:creator>
      <dc:date>2020-02-21T13:33:32Z</dc:date>
    </item>
    <item>
      <title>hi when you see 1.99 it's</title>
      <link>https://community.cisco.com/t5/network-security/disable-sshv1-2960/m-p/2727200#M917297</link>
      <description>&lt;P&gt;hi when you see 1.99 it's still backward compatabile to 1 so yes use that command and run show ip ssh again you want to see 2 only , your keys are long enough for v2 theyneed to be at least 1024 for v2 to work&lt;/P&gt;</description>
      <pubDate>Tue, 18 Aug 2015 20:56:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-sshv1-2960/m-p/2727200#M917297</guid>
      <dc:creator>Mark Malone</dc:creator>
      <dc:date>2015-08-18T20:56:29Z</dc:date>
    </item>
    <item>
      <title>Hi Mark,Thanks very much.</title>
      <link>https://community.cisco.com/t5/network-security/disable-sshv1-2960/m-p/2727201#M917298</link>
      <description>&lt;P&gt;Hi Mark,&lt;/P&gt;&lt;P&gt;Thanks very much. However, I still need a document that says that SSHv1 is Disabled from running by doing so for that switch model and/or IOS. That I have not been able to find.&lt;/P&gt;&lt;P&gt;Would you know where that might be?&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Krista&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Aug 2015 15:59:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-sshv1-2960/m-p/2727201#M917298</guid>
      <dc:creator>Krista Bowman</dc:creator>
      <dc:date>2015-08-21T15:59:55Z</dc:date>
    </item>
    <item>
      <title>When you fully enable ssh</title>
      <link>https://community.cisco.com/t5/network-security/disable-sshv1-2960/m-p/2727202#M917299</link>
      <description>&lt;P&gt;When you fully enable ssh version 2 it disables version 1 by default, as 1 cannot work with 2 as per the wiki doc , if you see 2 only in show ip ssh output 1 is not supported , that's the onloy diocs I have below its just know not to have 1 or 1.99 enabled and to specifically set 2 to disable 1&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;SSH-2&lt;/STRONG&gt;, was adopted as a standard. This version is incompatible with SSH-1. SSH-2 features both security and feature improvements over SSH-1. Better security, for example, comes through &lt;A href="https://en.wikipedia.org/wiki/Diffie%E2%80%93Hellman_key_exchange" title="Diffie–Hellman key exchange"&gt;&lt;U&gt;&lt;FONT color="#0066cc"&gt;Diffie–Hellman key exchange&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt; and strong &lt;A href="https://en.wikipedia.org/wiki/Integrity" title="Integrity"&gt;&lt;U&gt;&lt;FONT color="#0066cc"&gt;integrity&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt; checking via &lt;A href="https://en.wikipedia.org/wiki/Message_authentication_code" title="Message authentication code"&gt;&lt;U&gt;&lt;FONT color="#0066cc"&gt;message authentication codes&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;. New features of SSH-2 include the ability to run any number of &lt;A href="https://en.wikipedia.org/wiki/Unix_shell" title="Unix shell"&gt;&lt;U&gt;&lt;FONT color="#0066cc"&gt;shell&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt; sessions over a single SSH connection.&lt;SUP class="reference" id="cite_ref-19"&gt;&lt;A href="https://en.wikipedia.org/wiki/Secure_Shell#cite_note-19"&gt;&lt;U&gt;&lt;FONT color="#0066cc" size="2"&gt;[19]&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/SUP&gt; Due to SSH-2's superiority and popularity over SSH-1, some implementations such as &lt;A href="https://en.wikipedia.org/wiki/Lsh" title="Lsh"&gt;&lt;U&gt;&lt;FONT color="#0066cc"&gt;Lsh&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;SUP class="reference" id="cite_ref-20"&gt;&lt;A href="https://en.wikipedia.org/wiki/Secure_Shell#cite_note-20"&gt;&lt;U&gt;&lt;FONT color="#0066cc" size="2"&gt;[20]&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/SUP&gt; and &lt;A href="https://en.wikipedia.org/wiki/Dropbear_(software)" title="Dropbear (software)"&gt;&lt;U&gt;&lt;FONT color="#0066cc"&gt;Dropbear&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;SUP class="reference" id="cite_ref-21"&gt;&lt;A href="https://en.wikipedia.org/wiki/Secure_Shell#cite_note-21"&gt;&lt;U&gt;&lt;FONT color="#0066cc" size="2"&gt;[21]&lt;/FONT&gt;&lt;/U&gt;&lt;/A&gt;&lt;/SUP&gt; support only the SSH-2 protocol.&lt;/P&gt;&lt;P&gt;ip ssh version 2&lt;/P&gt;&lt;P&gt;CORE#sh ip ssh&lt;BR /&gt;SSH Enabled - version 2.0&lt;BR /&gt;Authentication timeout: 60 secs; Authentication retries: 2&lt;/P&gt;&lt;P&gt;&lt;A href="https://en.wikipedia.org/wiki/Secure_Shell"&gt;https://en.wikipedia.org/wiki/Secure_Shell&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco-faq.com/178/disable_ssh_v1_ssh_version_2.html"&gt;http://www.cisco-faq.com/178/disable_ssh_v1_ssh_version_2.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Aug 2015 08:03:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/disable-sshv1-2960/m-p/2727202#M917299</guid>
      <dc:creator>Mark Malone</dc:creator>
      <dc:date>2015-08-24T08:03:45Z</dc:date>
    </item>
  </channel>
</rss>

