cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
6652
Views
0
Helpful
28
Replies

Can't access Switch via SSH

BBWinterthur
Level 1
Level 1

Hi

 

We have a little Problem with two Switches. The Problem is that we can't connect to these switches via ssh or Network Assistant from the Computer, but it works perfectly from another switch. 

VLAN or IP shouldn't be a the problem, because we can connect to the other switches without any problem.

 

Does anyone have a solution for that Problem?

28 Replies 28

Sarbjit-2014
Level 1
Level 1

Hi,

What error message do you get when you are trying to connect, also its worth checking your TACACs/RADIUS logs to see why you are being denied access.

I think i didn't explain the problem properly.

The Problom is that i can't even ping the switch, so if try to connect via ssh, i get a connection timeout error.

Sorry should have explained that better.

Sounds like a routing issue, a tracert to the switch will show where the problem lies ?

Hi

A tracert doesnt help much, there is one hop, the core switch, then the nex hop should be the swich but it doesnt reply. All other switches are connected the same way and are also routed via the core switch.

 

Can you post the config of both switch's ?

Switch 1


Current configuration : 10428 bytes
!
! Last configuration change at 04:20:41 UTC Mon Mar 29 1993 by cisco
!
version 15.0
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname SWITCH-A316-01
!
boot-start-marker
boot-end-marker
!
enable secret 5
!
username cisco privilege 15 secret 5
no aaa new-model
clock timezone UTC 1 0
clock summer-time UTC recurring last Sun Mar 2:00 last Sun Oct 3:00
system mtu routing 1500
ip domain-name gibwintra.ch
!
!
!
!
crypto pki trustpoint TP-self-signed-3186553600
 enrollment selfsigned
 subject-name cn=IOS-Self-Signed-Certificate-3186553600
 revocation-check none
 rsakeypair TP-self-signed-3186553600
!
!
crypto pki certificate chain TP-self-signed-3186553600
 certificate self-signed 01
  30820246 308201AF A0030201 02020101 300D0609 2A864886 F70D0101 04050030
  31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
  69666963 6174652D 33313836 35353336 3030301E 170D3933 30333031 30303033
  32385A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
  4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 31383635
  35333630 3030819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
  8100BCFA 8D440D26 1FA33F72 933EEA23 E16878F3 B0D21DC6 ED99519B 57A36C35
  4D9F78EE 132996FE C8D7E589 FF41D7D0 2CA75155 DE112E52 1118A336 CD04B876
  6EC5AF83 19D87BAE DBAB596C A4204838 8217ED3C 3CEB5805 44BEE55F 7937FD0F
  05EFB477 163A744F 19B73A07  05940350 504F5683 BC9F8590
  069562F1 350AE342 EF072463 191781FD 6B3B2487 14FE9516 F9247FA2 CBED6ADC
  0199E79E 7F12ABA8 1013A657 8C6F7D1D 4DF78370 BFBAA4FD FD19F608 B2E39109
  587A92C9 13E65B8B ACBB
        quit
!
!
!
port-channel load-balance src-dst-ip
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
vlan dot1q tag native
!
ip ssh time-out 90
ip ssh authentication-retries 2
ip ssh version 2

interface Port-channel1
 switchport access vlan 10
 switchport trunk encapsulation dot1q
 switchport trunk native vlan 10
 switchport mode trunk
!
interface GigabitEthernet0/1
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/2
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/3
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/4
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/5
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/6
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/7
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/8
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/9
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/10
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/11
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/12
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/13
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/14
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/15
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/16
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/17
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/18
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/19
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/20
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/21
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/22
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/23
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/24
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/25
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/26
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/27
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/28
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/29
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/30
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/31
 switchport access vlan 20
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/32
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/33
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/34
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/35
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/36
 switchport access vlan 20
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/37
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/38
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast

interface GigabitEthernet0/39
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/40
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/41
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/42
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/43
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/44
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/45
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/46
 switchport access vlan 10
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/47
 description Extron A413
 switchport access vlan 10
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/48
 description Extron A405
 switchport access vlan 10
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/49
 switchport access vlan 10
 switchport trunk native vlan 10
 spanning-tree portfast
!
interface GigabitEthernet0/50
 switchport access vlan 10
 switchport trunk native vlan 10
 spanning-tree portfast
!
interface GigabitEthernet0/51
 switchport access vlan 10
 switchport trunk encapsulation dot1q
 switchport trunk native vlan 10
 switchport mode trunk
 channel-group 1 mode active
!
interface GigabitEthernet0/52
 switchport access vlan 10
 switchport trunk encapsulation dot1q
 switchport trunk native vlan 10
 switchport mode trunk
 channel-group 1 mode active
!
interface Vlan1
 no ip address
 no ip route-cache
!
interface Vlan10
 ip address 172.30.1.24 255.255.255.0
 no ip route-cache
!
interface Vlan20
 no ip address
 no ip route-cache
!
ip http server
ip http secure-server
!
!
logging esm config
!
!
line con 0
 logging synchronous
line vty 0 4
 logging synchronous
 login local
 transport input ssh
line vty 5 15
 logging synchronous
 login local
 transport input ssh
!
end

 

 

Switch 2


Current configuration : 2425 bytes
!
version 12.2
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname SWITCH-M104-01
!
enable secret 5
enable password
!
no aaa new-model
system mtu routing 1500
ip subnet-zero
ip routing
!
!
!
!
no file verify auto
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
vlan dot1q tag native
!
interface GigabitEthernet0/1
 switchport access vlan 15
 switchport mode access
!
interface GigabitEthernet0/2
 switchport access vlan 20
!
interface GigabitEthernet0/3
 switchport access vlan 20
!
interface GigabitEthernet0/4
 switchport access vlan 51
!
interface GigabitEthernet0/5
!
interface GigabitEthernet0/6
!
interface GigabitEthernet0/7
 switchport access vlan 15
 switchport mode access
!
interface GigabitEthernet0/8
!
interface GigabitEthernet0/9
 switchport access vlan 20
!
interface GigabitEthernet0/10
!
interface GigabitEthernet0/11
 switchport access vlan 30
!
interface GigabitEthernet0/12
!
interface GigabitEthernet0/13
 switchport access vlan 50
!
interface GigabitEthernet0/14
!
interface GigabitEthernet0/15
 switchport access vlan 20
!
interface GigabitEthernet0/16
!
interface GigabitEthernet0/17
 switchport access vlan 20
!
interface GigabitEthernet0/18
 switchport access vlan 20
!
interface GigabitEthernet0/19
 switchport access vlan 51
!
interface GigabitEthernet0/20
 switchport access vlan 10
 switchport mode access
!
interface GigabitEthernet0/21
 switchport access vlan 901
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/22
 switchport access vlan 10
 switchport mode access
!
interface GigabitEthernet0/23
 switchport access vlan 15
 switchport mode access
!
interface GigabitEthernet0/24
 switchport access vlan 901
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/25
 description To Rack 3.OG
 switchport trunk encapsulation dot1q
 switchport mode trunk
!
interface GigabitEthernet0/26
!
interface GigabitEthernet0/27
!
interface GigabitEthernet0/28
!
interface Vlan1
 no ip address
 shutdown
!
interface Vlan10
 ip address 172.30.1.2 255.255.255.0
!
ip default-gateway 172.30.1.1
ip classless
ip http server
!
!
control-plane
!
!
line con 0
line vty 0 4
 password
 logging synchronous
 login
 length 0
line vty 5 15
 password
 logging synchronous
 login
!
end

 

Sarbjit-2014
Level 1
Level 1

Your missing ip default-gateway, the I.P should be in the same network as VLAN10 pointing to your Core switch.

ip default-gateway 172.30.1.?

We haven't set the default gateway on the other switches either...

Sarbjit-2014
Level 1
Level 1

yes you have...

Switch 2

 

interface Vlan10
 ip address 172.30.1.2 255.255.255.0
!
ip default-gateway 172.30.1.1

 

Didn't see that, but doesn't matter anyway because Switch 2 doesn't work and we haven't set it on the other switches we are using.

So this can't be causing the problem

Switch 2 wont work, its not running SSH.

I do not think that we have enough information to know whether the switch is running SSH or not. Just because you do not see SSH commands in running config does not necessarily mean that SSH is not running. If it is running SSH with all default settings then there will not be SSH commands seen in running config.

 

Both switches have essentially the same problem which is that they do not know how to reach remote subnets, though the details of the problems are different. Switch 1 is configured to operate as a layer 2 switch (there is no ip routing command). As a layer 2 switch it would need a default-gateway command to be able to reach remote subnets. And switch 1 does not have default-gateway. If the original poster configures a correct default-gateway then the switch will be reachable.

 

Switch 2 is different because switch 2 does have ip routing enabled. This makes it into a layer 3 switch. As a layer 3 switch it does not use the default-gateway that is configured but would need ip route 0.0.0.0 0.0.0.0 (or would need some dynamic routing protocol).

 

HTH

 

Rick

HTH

Rick

Hi

Thanks for the help so far.

Yes, on Switch 2 ssh isn't configured, so ssh won't work. But as mentioned the problem isn't only ssh. I can't connect at all: no telnet,no ssh, no CNA and it is not possible to ping the switch.

When directly connectet to VLAN10, there isn't a problem. SSH,Telnet,CNA and ping is working.

And the default gateway isn't set on other switches, wich are working. Because the switch 1 and 2 don't have to route anything. All routing is done on our coreswitch.

I have copied the config of a working switch, hope this helps.

 


!
! Last configuration change at 01:46:45 UTC Sat Sep 23 1995
!
version 15.0
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname SWITCH-A316-02
!
boot-start-marker
boot-end-marker
!
enable secret 5
!
username cisco privilege 15 secret 5
no aaa new-model
clock timezone UTC 1 0
clock summer-time UTC recurring last Sun Mar 2:00 last Sun Oct 3:00
system mtu routing 1500
ip domain-name gibwintra.ch
!
!
!
!
crypto pki trustpoint TP-self-signed-2682990976
 enrollment selfsigned
 subject-name cn=IOS-Self-Signed-Certificate-2682990976
 revocation-check none
 rsakeypair TP-self-signed-2682990976
!
!
crypto pki certificate chain TP-self-signed-2682990976
 certificate self-signed 01 nvram:IOS-Self-Sig#1.cer
!
!
!
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
vlan dot1q tag native
!
ip ssh time-out 90
ip ssh version 2
!
!
!
!
!
interface GigabitEthernet0/1
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/2
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/3
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/4
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/5
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/6
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/7
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/8
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/9
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/10
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/11
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/12
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/13
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/14
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet0/15
 description Embed PC 4.Stock
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/16
 description Embed PC 4.Stock
 switchport access vlan 260
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/17
 switchport access vlan 20
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/18
 switchport access vlan 231
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/19
 switchport access vlan 20
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/20
 switchport access vlan 20
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/21
 switchport access vlan 20
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/22
 switchport access vlan 20
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/23
 switchport access vlan 20
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/24
 switchport access vlan 20
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/25
 switchport access vlan 20
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/26
 switchport access vlan 20
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/27
 switchport access vlan 20
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/28
 switchport access vlan 20
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/29
 switchport access vlan 20
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/30
 switchport access vlan 20
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/31
 switchport access vlan 20
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/32
 switchport access vlan 20
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/33
 switchport access vlan 10
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/34
 switchport access vlan 10
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/35
 switchport access vlan 10
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/36
 switchport access vlan 10
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/37
 switchport access vlan 10
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/38
 switchport access vlan 10
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/39
 switchport access vlan 10
 switchport trunk encapsulation dot1q
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/40
 switchport access vlan 10
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/41
 switchport access vlan 10
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/42
 switchport access vlan 10
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/43
 switchport access vlan 10
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/44
 switchport access vlan 10
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/45
 switchport access vlan 10
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/46
 switchport access vlan 10
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/47
 switchport access vlan 900
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/48
 switchport access vlan 900
 switchport trunk native vlan 10
 switchport mode access
!
interface GigabitEthernet0/49
 switchport access vlan 10
 switchport trunk native vlan 10
!
interface GigabitEthernet0/50
 switchport access vlan 10
 switchport trunk native vlan 10
!
interface GigabitEthernet0/51
 switchport access vlan 10
 switchport trunk native vlan 10
!
interface GigabitEthernet0/52
 switchport access vlan 10
 switchport trunk encapsulation dot1q
 switchport trunk native vlan 10
 switchport mode trunk
!
interface Vlan1
 no ip address
!
interface Vlan10
 ip address 172.30.1.25 255.255.255.0
!
ip http server
ip http secure-server
!
!
logging esm config
!
!
line con 0
line vty 0 4
 logging synchronous
 login local
 transport input ssh
line vty 5 15
 logging synchronous
 login local
 transport input ssh
!
end

 

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card