06-15-2023 12:04 PM
I know it's old, but I've got 2 48p Catalyst 3750Gs running IOS 15. I've setup SSH on cat switches before without issue but for some reason this one is just being super resistant. I can log in with my user account to the HTTP interface without any issues, but it says login failed for both SSH and telnet. I've generated the rsa keys and whatnot, putty connects just fine, it just always says that authentication failed. It does this with both accounts i've added. Both accounts work fine on HTTP.
version 15.0
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname house-cat3750G
!
boot-start-marker
boot-end-marker
!
no logging console
enable secret 5 [redacted]
!
username [redacted] secret 5 [redacted]
username [redacted] secret 5 [redacted]
aaa new-model
!
!
aaa authorization exec default local
!
!
aaa session-id common
clock timezone UTC -6 0
clock summer-time UTC recurring
switch 1 provision ws-c3750g-48ps
system mtu routing 1500
ip domain-name DOMAIN.com
!
!
!
[interface/crypto key configs removed to save space]
!
interface Vlan99
ip address 10.10.10.1 255.255.255.0
no ip route-cache
!
ip default-gateway 10.10.10.254
ip http server
ip http secure-server
!
!
!
!
!
vstack
!
line con 0
line vty 0 4
session-timeout 28800
password 7 [redacted]
transport input telnet ssh
transport output telnet ssh
line vty 5 15
session-timeout 28800
password 7 [redacted]
transport input telnet ssh
transport output telnet ssh
!
end
06-15-2023 01:46 PM
Ok, I followed the steps above (including creating the mhm account). I'm unable to login via SSH or telnet. I'm also now unable to access the console again. All 3 of these accounts are very simple (jason/jason, admin/admin, mhm/mhm) so I know I'm not mis-keying the passwords.
06-15-2023 01:49 PM
Do you think I should drop this switch back to 12.2?
06-15-2023 01:54 PM
Give me half hour I will try config in my lab.
Thanks
MHM
06-15-2023 01:13 PM
username [redacted] secret 5 [redacted]
username [redacted] secret 5 [redacted] <<- these not work
06-15-2023 01:15 PM
Correct, neither account works.
06-15-2023 02:45 PM
enable password mhm
!
aaa new-model
!
aaa authentication login default local
!
username mhm password 0 mhm
username mhm2 privilege 15 password 0 mhm2
!
interface Ethernet0/0
ip address 100.0.0.1 255.255.255.0
!
line con 0
exec-timeout 0 0
privilege level 15
logging synchronous
line aux 0
exec-timeout 0 0
privilege level 15
logging synchronous
line vty 0 4
transport input telnet
06-15-2023 05:21 PM
Hmm, what version of IOS is your lab running? My GNS3 instance has 12.2. Curious if it's something weird with 15.0.
06-15-2023 05:25 PM
I Dont think so'
Only add username password with privilege and remove password from line.
06-15-2023 06:13 PM
I fiddled with it for a while and couldn't get it to work. Cleared the entire config, built it back exactly like yours, and it still doesn't work. Any time I turn on aaa, it locks me out of console, telnet, and SSH.
I'm going to try reverting it to 12.2 tomorrow and see if that makes a difference.
06-16-2023 08:06 AM
Downgraded from 15.0(2) to the latest 12.2 and the issue is resolved.
Very odd, but at least I know I wasn't being stupid.
06-16-2023 08:10 AM
Oh happy ending
with your original config or with my config, which is work ?
06-16-2023 08:13 AM
I loaded my original config back into it before doing the downgrade
06-16-2023 08:13 AM
Thank you for all your help!
06-16-2023 08:22 AM
You are so so welcome
have a nice day friend
MHM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide