cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1640
Views
0
Helpful
13
Replies

SSH Authentication

amh4y0001
Level 3
Level 3

Hi,

I am unable to SSH Cisco 890 ISR. user /password I am sure is correct. Any thoughts?

 

Here is the output for the sh ip ssh

 

sh ip ssh
SSH Enabled - version 2.0
Authentication methods:publickey,keyboard-interactive,password
Encryption Algorithms:aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,3des-cbc,aes192-cbc,aes256-cbc
MAC Algorithms:hmac-sha1,hmac-sha1-96
Authentication timeout: 120 secs; Authentication retries: 3
Minimum expected Diffie Hellman key size : 1024 bits
IOS Keys in SECSH format(ssh-rsa, base64 encoded):
ssh-rsa AAAAB-------v2qQ==

 

And here is partial output of the sh running:

line con 0
no modem enable
line aux 0
line vty 0 4
login local
transport input ssh
line vty 5 189
login local
transport input ssh
!
scheduler allocate 20000 1000

13 Replies 13

marce1000
VIP
VIP

 

  - The first iteration is what does unable to SSH mean ? Is there an error, if so which one, if anything else happens, then describe it.

M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Unable to connect / authenticate.

Authentication Failed. Please retry.

Ric Beeching
Level 7
Level 7
have you configured a domain-name for the router and then generated an SSH crypto key?
e.g.
conf t
ip domain-name test.com
exit
crytpo key generate rsa
1024
end

Alternatively, check telnet works first before troubleshooting ssh:
conf t
line vty 0 4
transport input telnet ssh
end
-----------------------------
Please rate helpful / correct posts

Hi,

Thanks for reply.

I have confirmed that ip domain name exists and the key were generated with 1024 as well.

 

Checked with telnet and its failed as Login Failed.

 

I have created SSH user with following command:

username admin secret MySSHPassword

 

crypto key generate rsa : 1024

Can you attach the full config with sensitive info removed?

Cheers,
Ric
-----------------------------
Please rate helpful / correct posts

Thanks, I have attached the config.

Looks good as far as I know.. is it possible for a firewall to be blocking or is it connected without one? Can you ping that interface from a workstation and ping workstation from router? Basic steps I know.. other thing to check is whether port is open from PC so try a simple telnet from command prompt (need to enable service in windows) and see if that establishes a session. That helps you determine if the workstation can even reach the router on that port to begin with.

Ric
-----------------------------
Please rate helpful / correct posts

Hi,

I can ping the host from client and router can ping the client as well.

Its very strange that it saying invalid login. I have verified several time that I am typing user / password correctly.

 

 - As a sanity check -> configure a different username and password on the device and try again,

M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Ok, problem solved. user name was "admin" changing user name to something else did the trick. Thanks all for suggestions.

Perhaps should be a separate thread, but I have a 2nd router where the ISP address is via DHCP (I have not configured WAN static address). In this case, how I can SSH? Which IP Address?

Hi,

When we use WAN link with DHCP (no static IP), how we can SSH to it? I tried with host name but it didn't worked. An thoughts?

Review Cisco Networking for a $25 gift card