cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
779
Views
6
Helpful
4
Replies

Disable SSH on Cucm

Rajan R
Level 1
Level 1

Hi

Have a customer who wants to disable ssh in cucm and unity connection, can this be done ?

Thanks

4 Replies 4

Leo Laohoo
Hall of Fame
Hall of Fame

@Rajan R wrote:
Have a customer who wants to disable ssh in cucm and unity connection

Oh, FFS!Oh, FFS!

It is not appropriate to ask if "it can be done" but, rather, "WTF would anyone want to disable SSH (and lower the security)?". 

No that is not possible.



Response Signature


No, it can’t be disabled from CUCM. However, the customer can manage this at the network level if the traffic to the CUCM passes through a firewall. They should create a policy to disable all SSH traffic to the server.

 

 



Response Signature


I believe that this request came from your vulnerability remediation team or the security department, simply it is not possible to disable the SSH totally, however SSH is mandatory  for not only  the CUCM but for many other systems, but I believe again the security team have concern regarding weak SSH ciphers such as Blowfish  and Keys exchange algorithm such as DES, to change your CUCM SSH ciphers and keys exchange algorithm please refer to the following link, also please note that any change requires server rebooting to take affect.
https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/security/12_5_1SU3/cucm_b_security_guide_1251SU3/cucm_m_cipher-management_reorg.html