Jump to content
Toggle menu
  • 51 articles
  • 24 files
  • 4 users
  • 750 edits
Tech-Wiki
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

Enable SSHv2 on Cisco IOS XE

From Tech-Wiki


Enable SSH Version 2 for encrypted administrative CLI access to a Cisco IOS XE device.

ⓘ
Validation status
Reviewed against the current Cisco IOS XE Secure Shell documentation and Cisco IOS XE Software Hardening Guide on 27 September 2026.
!
Preserve management access
Make management-plane changes from a controlled administrative session and verify a second SSH session before closing the original connection. Ensure console or other approved recovery access is available before changing VTY authentication.

Prerequisites

SSH requires an RSA key pair. A hostname and domain name are commonly configured before generating the key.

Use organisation-approved management addressing, accounts, access controls and secret-handling standards rather than copying example values directly into production.

Enable SSHv2

The following example uses a 2048-bit RSA key, explicitly selects SSH Version 2 and permits only SSH on the VTY lines.

>_Basic SSHv2 configuration
hostname Router1
ip domain-name example.net
crypto key generate rsa modulus 2048
ip ssh version 2
ip ssh time-out 60
ip ssh authentication-retries 3

Cisco's IOS XE hardening guidance recommends explicitly configuring SSHv2 because allowing SSH version 1 compatibility weakens management-plane security.

Local authentication example

Where local fallback authentication is required, use a strong local secret format supported by the target IOS XE release.

>_Example local administrator
username netadmin privilege 15 algorithm-type scrypt secret REPLACE_WITH_STRONG_SECRET
!
Do not use sample credentials
The legacy page used a username and password of cisco. Do not deploy shared example credentials. Use unique organisation-approved administrative credentials or central AAA.

Apply local authentication and SSH-only transport to the VTY lines:

>_Restrict VTY access to SSH
line vty 0 4
 login local
 transport input ssh

On devices with additional VTY lines, apply the approved policy consistently to all required lines.

Restrict management sources

Where appropriate, use a management access control list and/or a dedicated management interface so SSH is not reachable from untrusted networks.

>_Example management ACL
ip access-list standard MGMT-VTY
 permit 192.0.2.0 0.0.0.255
!
line vty 0 4
 access-class MGMT-VTY in

Replace the example documentation subnet with the approved management network.

Verify

>_Verify SSH status
show ip ssh
show ssh

Test a new SSH session from an authorised management host before ending the original administrative session.

Official references

See also