Enable SSHv2 on Cisco IOS XE
More actions
Enable SSH Version 2 for encrypted administrative CLI access to a Cisco IOS XE device.
Prerequisites
SSH requires an RSA key pair. A hostname and domain name are commonly configured before generating the key.
Use organisation-approved management addressing, accounts, access controls and secret-handling standards rather than copying example values directly into production.
Enable SSHv2
The following example uses a 2048-bit RSA key, explicitly selects SSH Version 2 and permits only SSH on the VTY lines.
hostname Router1 ip domain-name example.net crypto key generate rsa modulus 2048 ip ssh version 2 ip ssh time-out 60 ip ssh authentication-retries 3
Cisco's IOS XE hardening guidance recommends explicitly configuring SSHv2 because allowing SSH version 1 compatibility weakens management-plane security.
Local authentication example
Where local fallback authentication is required, use a strong local secret format supported by the target IOS XE release.
username netadmin privilege 15 algorithm-type scrypt secret REPLACE_WITH_STRONG_SECRET
cisco. Do not deploy shared example credentials. Use unique organisation-approved administrative credentials or central AAA.Apply local authentication and SSH-only transport to the VTY lines:
line vty 0 4 login local transport input ssh
On devices with additional VTY lines, apply the approved policy consistently to all required lines.
Restrict management sources
Where appropriate, use a management access control list and/or a dedicated management interface so SSH is not reachable from untrusted networks.
ip access-list standard MGMT-VTY permit 192.0.2.0 0.0.0.255 ! line vty 0 4 access-class MGMT-VTY in
Replace the example documentation subnet with the approved management network.
Verify
show ip ssh show ssh
Test a new SSH session from an authorised management host before ending the original administrative session.