cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
27863
Views
32
Helpful
11
Replies

Unable to SSH to Switch - no matching mac found: client hmac-sha1 server hmac-sha1-96 error

CiscoPurpleBelt
Level 6
Level 6

So I am unable to ssh from one device to another. I am testing this way because right now I only have the devices connected to each other and I console into them. Anybody familiar with what is going on?

 

no matching mac found: client hmac-sha1 server hmac-sha1-96

11 Replies 11

Hello,

 

your devices cannot agree on a common message authentication code (MAC). Which devices are those, and what IOS versions are you running ? Which rsa keys do you have configured ?

These are 4431 Routers and configured for 2048.

What is the output of "sh ip ssh"?

SSH Enabled - version 2.0                                                              
Authentication methods:publickey,keyboard-interactive,password                         
Authentication Publickey Algorithms:x509v3-ssh-rsa,ssh-rsa                             
Hostkey Algorithms:x509v3-ssh-rsa,ssh-rsa                                              
Encryption Algorithms:aes256-ctr                                                       
MAC Algorithms:hmac-sha1-96                                                            
Authentication timeout: 60 secs; Authentication retries: 3                             
Minimum expected Diffie Hellman key size : 1024 bits                                   
IOS Keys in SECSH format(ssh-rsa, base64 encoded): BB1_InterRt_4431_A.pmo.com          
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAAAgQCWqleK7VQA+2Sl2cCFALBZJ4cm09Uh3N1dW+q4C4qo       
fbWXGcGzmiR1LuBHtakYlNrVqv2B3v0D1BgXbakK2zlJPXyyIgLD0iIJKHvcySDOdH6P4xJ8MWIRhd7m       
Eaqp80jd8PPxdrB4g/FMF+kFhVtobGKV4CFX2TE1yYCGndLNZw==

Hello,

 

zeroize the keys and try a new key with 1024 modulus...

Ok I will do that ASAP and let you know the status thanks so much!

can you redo SSH config without locking yourself out?  which parts are you suggesting redoing?

Ethan and Mia
Level 1
Level 1

I had same issue after upgrade IOS-XE to some switchs

How you fix ? Thanks

Hi Shat1478,

I've fixed it upgrading ssh client....in my case Putty from release 0.60 to release 0.74.

Ciao

 

 

Mario

 

 

Hi,

It worked! Upgrading ssh client from release 0.60 to release 0.78.

Thanks

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card