04-04-2023 01:16 AM
Hello,
Looking for some help with the archive command to backup switch configs using SSH.
Configuration used -
archive
path scp://user:password@server//path/h$
write-memory
ip ssh source-interface GigabitEthernet1/0/1 (trunk port on switch)
Whenever I try and write the configuration, receive authentication failed.
The configuration works successfully on routers and C9300 switches so I know it is not an issue with the account or file path.
I am having problems with SCP (or SFTP) on C2960L (IOS15.2(7)E5) or C1000-2G-L (IOS 15.2(7)E7)
I can also see authentication failed logs on the SFTP server.
show archive
:Error - Bad file number <- Most Recent
show log
SFTP write_process: sftp_write failed err 13 (only if using SFTP, no log for SCP)
If I manually copy e.g. copy running sftp: this works
Any suggestions would be much appreciated.
Stewart
Solved! Go to Solution.
05-01-2023 02:37 AM
So it turns out the issue was because the randomly generated password had % special character in it and this is what has been causing authentication to fail. Routers support it but certain models of switches (or IOS versions) do not.
04-04-2023 02:08 AM
path scp://user:password@server//path/h$ <<- instead of h$ (try puting file name myconfig.cfg and see if that works.
Cat 9300 is latest IOS XE compare to IOS
also check the command syntax to support :
04-04-2023 08:28 AM
Thanks for the suggestion which I tried but unfortunately did not resolve.
Having looked a bit deeper, I think it might be to do with the MAC and/or KEX algorithms the switches are using and may not be supported / configured on the SFTP server.
Routers have a lot more algorithms available.
04-04-2023 09:50 AM
Sure show ssh and ciphers can show you, you can also see what message you getting on SFTP or SCP Server ?
Try manually first if that works you know where to go from there
05-01-2023 02:37 AM
So it turns out the issue was because the randomly generated password had % special character in it and this is what has been causing authentication to fail. Routers support it but certain models of switches (or IOS versions) do not.
05-01-2023 02:49 AM
there is also a shorter character limit for switches compared to routers
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide