cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
536
Views
0
Helpful
9
Replies

Received empty VPN credentials

fandre207
Community Member

I'm getting empty VPN credentials by email: 

Screenshot From 2026-07-30 16-40-38.png

I tried with 'sandbox-iosxr-1.cisco.com', as I see in the I/O tab (image attached) but the authentication is failing.
This is happening with the IOS XR Always-on Sandbox. 

9 Replies 9

Jesus Illescas
Cisco Employee
Cisco Employee

@fandre207 I confirm the credentials are not on the mail, I'll share this with the sandbox team. However as you noted the credentials can be found in the I/O tab. 

I can see the ssh connection to the sandbox is not working as you commented, I'll the sandbox team to reset it.

fandre207
Community Member

@Jesus Illescas Should I use the ssh connection to establish the lab's private VPN?

I understand that these are different URLs but please correct me if I'm wrong. 

I tried re-launching and Lab Network Address is missing on the email.  

Jesus Illescas
Cisco Employee
Cisco Employee

@fandre207 the Always On sandboxes don't require VPN, you can ssh directly. However, I can see the sandbox is not working at the moment. It can take a moment for the sandbox team to see my request. 

The mail needs some rework, I can see is confusing, but the credentials that don't appear on the mail are the same as the ones in the I/O tab in the environment page.

fandre207
Community Member

Hello @Jesus Illescas , 

Do you have any news from the sandbox team on the IOS XR Always? I see is still down.

I also see this ones are down: 
- Catalyst 8000 Always-On Sandbox
- Nexus 9000 AlwaysOn Sandbox

I understand is best effort to fix it but could ask the team? 

Jesus Illescas
Cisco Employee
Cisco Employee

Hi @fandre207 I see the sandboxes XR and C8k Always On are not working correctly, I will ping again the sandbox team. Thanks for sharing.

I tested the N9k always on too, but this one is working for me right now. If you have an active reservation, please end it and start a new one.

Hi @Jesus Illescas , I started a fresh new reservation for N9k always-on but is not working right now: 

labs
labs ping sbx-nxos-mgmt.cisco.com
PING sandbox-nxos-1.cisco.com (131.226.217.151) 56(84) bytes of data.
^C
--- sandbox-nxos-1.cisco.com ping statistics ---
16 packets transmitted, 0 received, 100% packet loss, time 15367ms

labs ssh [email protected]
User Access Verification
Received disconnect from 131.226.217.151 port 22:2: Too many authentication failures
Disconnected from 131.226.217.151 port 22
labs
labs

The error message indicates that my user had too many authentication failures. Could you ask the team if the problem is with my particular username "felix.andre86" ? 

Anyway ping is not responding... so I assume is down again. 

Jesus Illescas
Cisco Employee
Cisco Employee

@fandre207 I tested the nexus always on and worked for me.

Is felix.andre86 the user that appears on the environment page? a screenshot helps. Sometimes the credentials might fail at the first attempt, if that happens end and start a new reservation.

Also, please share the output of your ssh command using the -v flag (assuming openSSH) or equivalent.

ssh <YOUR_USER>@sbx-nxos-mgmt.cisco.com -v

It would be strange that the issue might be only for your username.

About ping, as far as I know is disabled for all always on sandboxes.

fandre207
Community Member

Hello @Jesus Illescas , 

felix.andre86 is the username as in the I/O page and I'm trying the SSH credentials at least twice. 

The Nexus 9000 and Catalyst 8000 Always, are working now 😀

Just the IOS XR Always-on is failing. 

Did the sandbox team reply with their fix? Could you let me know to test it afterwards? 

Below the full SSH logs: 

 ~ ssh [email protected] -v
debug1: OpenSSH_10.0p2 Debian-7+deb13u4, OpenSSL 3.5.6 7 Apr 2026
debug1: Reading configuration data /home/fandre/.ssh/config
debug1: /home/fandre/.ssh/config line 2: include ~/.ssh/config.d/clab_nodes matched no files
debug1: Reading configuration data /etc/ssh/ssh_config
debug1: Reading configuration data /etc/ssh/ssh_config.d/20-systemd-ssh-proxy.conf
debug1: Reading configuration data /etc/ssh/ssh_config.d/clab-debian-r2.conf
debug1: /etc/ssh/ssh_config line 21: Applying options for *
debug1: Connecting to sandbox-iosxr-1.cisco.com [131.226.217.150] port 22.
debug1: Connection established.
debug1: identity file /home/fandre/.ssh/id_rsa type -1
debug1: identity file /home/fandre/.ssh/id_rsa-cert type -1
debug1: identity file /home/fandre/.ssh/id_ecdsa type -1
debug1: identity file /home/fandre/.ssh/id_ecdsa-cert type -1
debug1: identity file /home/fandre/.ssh/id_ecdsa_sk type -1
debug1: identity file /home/fandre/.ssh/id_ecdsa_sk-cert type -1
debug1: identity file /home/fandre/.ssh/id_ed25519 type -1
debug1: identity file /home/fandre/.ssh/id_ed25519-cert type -1
debug1: identity file /home/fandre/.ssh/id_ed25519_sk type -1
debug1: identity file /home/fandre/.ssh/id_ed25519_sk-cert type -1
debug1: identity file /home/fandre/.ssh/id_xmss type -1
debug1: identity file /home/fandre/.ssh/id_xmss-cert type -1
debug1: Local version string SSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4
debug1: Remote protocol version 2.0, remote software version OpenSSH_9.6 PKIX[14.4.2]
debug1: compat_banner: match: OpenSSH_9.6 PKIX[14.4.2] pat OpenSSH* compat 0x04000000
debug1: Authenticating to sandbox-iosxr-1.cisco.com:22 as 'felix.andre86'
debug1: load_hostkeys: fopen /home/fandre/.ssh/known_hosts2: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
debug1: SSH2_MSG_KEXINIT sent
debug1: SSH2_MSG_KEXINIT received
debug1: kex: algorithm: curve25519-sha256
debug1: kex: host key algorithm: ssh-ed25519
debug1: kex: server->client cipher: [email protected] MAC: <implicit> compression: none
debug1: kex: client->server cipher: [email protected] MAC: <implicit> compression: none
debug1: expecting SSH2_MSG_KEX_ECDH_REPLY
debug1: SSH2_MSG_KEX_ECDH_REPLY received
debug1: Server host key: ssh-ed25519 SHA256:WPzkCcE0izDljjOKraE4SgoVmrijJEL8iekEwAvYXjA
debug1: load_hostkeys: fopen /home/fandre/.ssh/known_hosts2: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory
debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory
debug1: Host 'sandbox-iosxr-1.cisco.com' is known and matches the ED25519 host key.
debug1: Found key in /home/fandre/.ssh/known_hosts:10
debug1: ssh_packet_send2_wrapped: resetting send seqnr 3
debug1: rekey out after 134217728 blocks
debug1: SSH2_MSG_NEWKEYS sent
debug1: expecting SSH2_MSG_NEWKEYS
debug1: ssh_packet_read_poll2: resetting read seqnr 3
debug1: SSH2_MSG_NEWKEYS received
debug1: rekey in after 134217728 blocks
debug1: SSH2_MSG_EXT_INFO received
debug1: kex_ext_info_client_parse: [email protected] (unrecognised)
debug1: kex_ext_info_client_parse: server-sig-algs=<x509v3-ecdsa-sha2-nistp256,x509v3-ecdsa-sha2-nistp384,x509v3-ecdsa-sha2-nistp521,x509v3-ssh-rsa,x509v3-rsa2048-sha256,x509v3-sign-rsa,x509v3-sign-dss,x509v3-ssh-dss,x509v3-ssh-ed25519,ssh-ed25519,ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,ssh-rsa,rsa-sha2-256,rsa-sha2-512,ssh-dss>
debug1: SSH2_MSG_SERVICE_ACCEPT received
Connection closed by 131.226.217.150 port 22
 ~ 


Thank you.-

Jesus Illescas
Cisco Employee
Cisco Employee

@fandre207 I tested now the XR Always On sandbox and is working. I went through the logs and I noticed the host key between your log and mine is different, meaning we tested against different instances. We always destroy and create a new instance when the sandbox is reset.

Can you try again? Make sure your reservation is new, and capture the logs this way.

date
ssh -vvv [email protected] 2>&1 | tee ssh-retry-real.log
date
ssh -vvv [email protected] 2>&1 | tee ssh-retry-control.log