cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4071
Views
5
Helpful
5
Replies

4500-X IOS-XE 3.11 SSH commands ?

jerem38
Level 1
Level 1

Hi all,

 

Just upgraded a VSS pair of 4500-X from 03.06 to the latest recommanded version, 03.11.02.E

For any reason ssh has been disabled and all reguar commands to enable it have disabled.

 

campus-sw01#sh license in-use
License Store: Primary License Storage
StoreIndex: 0 Feature: entservices Version: 1.0
License Type: Permanent
License State: Active, In Use
License Count: Non-Counted
License Priority: Medium
License Store: Dynamic License Storage

campus-sw01#
campus-sw01#sh privilege
Current privilege level is 15
campus-sw01#
campus-sw01#sh ip ssh
^
% Invalid input detected at '^' marker.

campus-sw01#conf t
Enter configuration commands, one per line. End with CNTL/Z.
campus-sw01(config)#ip ssh ?
% Unrecognized command
campus-sw01(config)#crypto key generate rsa
^
% Invalid input detected at '^' marker.

campus-sw01(config)#
campus-sw01#sh vers
Cisco IOS Software, IOS-XE Software, Catalyst 4500 L3 Switch Software (cat4500e-UNIVERSAL-M), Version 03.11.02.E RELEASE SOFTWARE (fc3)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2020 by Cisco Systems, Inc.

 

The link to the configuration guide version IOS XE 3.11.xE is pointing to a page where it is written "null".

https://www.cisco.com/c/en/us/support/switches/catalyst-4500-x-series-switches/products-installation-and-configuration-guides-list.html

The commands stated in the most recent configuration guide, 3.9, are talking about "ip ssh" commands

 

Any clue ?

 

Thx,

Jeremie

1 Accepted Solution

Accepted Solutions

Richard Burts
Hall of Fame
Hall of Fame

Jeremie

 

Cisco produces some versions of image files that do not support encryption to be able to comply with some export restrictions. In general the file name will include k9 if it does support encryption. It looks like the code you are running does not have k9 in the name and therefore does not support encryption, which is essential to supporting SSH. 

HTH

Rick

View solution in original post

5 Replies 5

Richard Burts
Hall of Fame
Hall of Fame

Jeremie

 

Cisco produces some versions of image files that do not support encryption to be able to comply with some export restrictions. In general the file name will include k9 if it does support encryption. It looks like the code you are running does not have k9 in the name and therefore does not support encryption, which is essential to supporting SSH. 

HTH

Rick

Thanks Richard, you are perfectly right. Seems I didn't pay enough attention :/

Jeremie

 

This is an easy mistake to make. And thank goodness not too difficult to fix. Thank you for marking this question as solved. This will help other participants in the community to identify discussions which have helpful information.

HTH

Rick

Hi Richard,

Is there some easy methods to have the crypto features?The current version is an enterprise version.I want to change to crypto version.

Look forward to your reply.

It depends on whether you have an active service contract for the device and what licenses you purchased. If you have an active service contract and the appropriate license you should be able to down load a new image file that does support crypto.

HTH

Rick
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: