cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1259
Views
0
Helpful
2
Replies

Problem with SSH in NetConfig!

Hello,

if someone could help me I would appreciate a lot.

I have RME 4.3.0 and I have difficulties in configuring NetConfig to use

SSH for changing configurations on devices. SSH is configured correctly

on devices because I can connect from normal SSH client with the same

credentials which NetConfig uses for SSH. It is interesting that with

telnet it works OK, no problem, same credentials. Telnet is not solution,

because I have explicit request that transport protocol must be SSH.

When I run SSH, NetConfig shows output : successuful, not attempted!

I captured some debuging information from devices (cisco router 2911) :

debug ip ssh packets

Apr 21 06:50:36.588: SSH1: starting SSH control process
Apr 21 06:50:36.588: SSH1: sent protocol version id SSH-2.0-Cisco-1.25
Apr 21 06:50:36.596: SSH1: receive failure - status 0x03
Apr 21 06:50:36.620: SSH2: starting SSH control process
Apr 21 06:50:36.620: SSH2: sent protocol version id SSH-2.0-Cisco-1.25
Apr 21 06:50:36.696: SSH1: Session terminated normally
Apr 21 06:50:36.920: SSH2: protocol version id is - SSH-2.0-CmdSvc
Apr 21 06:50:36.920: SSH2 2: SSH2_MSG_KEXINIT sent
Apr 21 06:50:36.936: SSH2 2: SSH2_MSG_KEXINIT received
Apr 21 06:50:36.936: SSH2:kex: client->server enc:3des-cbc mac:hmac-sha1
Apr 21 06:50:36.936: SSH2:kex: server->client enc:3des-cbc mac:hmac-sha1
Apr 21 06:50:36.952: SSH2 2: expecting SSH2_MSG_KEXDH_INIT
Apr 21 06:50:37.144: SSH2 2: SSH2_MSG_KEXDH_INIT received
Apr 21 06:50:37.412: SSH2: kex_derive_keys complete
Apr 21 06:50:37.432: SSH2 2: SSH2_MSG_NEWKEYS sent
Apr 21 06:50:37.432: SSH2 2: waiting for SSH2_MSG_NEWKEYS
Apr 21 06:50:37.468: SSH2 2: SSH2_MSG_NEWKEYS received
Apr 21 06:50:37.696: SSH2 2: Using method = none
Apr 21 06:50:37.712: SSH2 2: Using method = password
Apr 21 06:50:37.836: SSH2 2: authentication successful for netconfiguser
Apr 21 06:50:37.848: SSH2 2: channel open request
Apr 21 06:50:37.860: SSH2 2: pty-req request
Apr 21 06:50:37.860: SSH2 2: setting TTY - requested: height 0, width 0; set: height 24, width 80
Apr 21 06:50:37.868: SSH2 2: shell request
Apr 21 06:50:37.868: SSH2 2: shell message received
Apr 21 06:50:37.868: SSH2 2: starting shell for vty
Apr 21 06:50:53.108: SSH2: Session terminated normally

Apr 21 06:50:54.272: SSH1: starting SSH control process
Apr 21 06:50:54.272: SSH1: sent protocol version id SSH-2.0-Cisco-1.25
Apr 21 06:50:54.284: SSH1: receive failure - status 0x03
Apr 21 06:50:54.296: SSH2: starting SSH control process
Apr 21 06:50:54.296: SSH2: sent protocol version id SSH-2.0-Cisco-1.25
Apr 21 06:50:54.384: SSH1: Session terminated normally
Apr 21 06:50:54.596: SSH2: protocol version id is - SSH-2.0-CmdSvc
Apr 21 06:50:54.596: SSH2 2: SSH2_MSG_KEXINIT sent
Apr 21 06:50:54.612: SSH2 2: SSH2_MSG_KEXINIT received
Apr 21 06:50:54.612: SSH2:kex: client->server enc:3des-cbc mac:hmac-sha1
Apr 21 06:50:54.612: SSH2:kex: server->client enc:3des-cbc mac:hmac-sha1
Apr 21 06:50:54.628: SSH2 2: expecting SSH2_MSG_KEXDH_INIT
Apr 21 06:50:54.820: SSH2 2: SSH2_MSG_KEXDH_INIT received
Apr 21 06:50:55.088: SSH2: kex_derive_keys complete
Apr 21 06:50:55.104: SSH2 2: SSH2_MSG_NEWKEYS sent
Apr 21 06:50:55.104: SSH2 2: waiting for SSH2_MSG_NEWKEYS
Apr 21 06:50:55.144: SSH2 2: SSH2_MSG_NEWKEYS received
Apr 21 06:50:55.360: SSH2 2: Using method = none
Apr 21 06:50:55.376: SSH2 2: Using method = password
Apr 21 06:50:55.408: SSH2 2: authentication successful for netconfiguser
Apr 21 06:50:55.424: SSH2 2: channel open request
Apr 21 06:50:55.436: SSH2 2: pty-req request
Apr 21 06:50:55.436: SSH2 2: setting TTY - requested: height 0, width 0; set: height 24, width 80
Apr 21 06:50:55.444: SSH2 2: shell request
Apr 21 06:50:55.444: SSH2 2: shell message received
Apr 21 06:50:55.444: SSH2 2: starting shell for vty
Apr 21 06:51:12.145: SSH2: Session terminated normally

It looks like it tries two times and terminates.

If someone knows solution, please answer me!

Thanks in advance.

2 Replies 2

Joe Clarke
Cisco Employee
Cisco Employee

There should be a directory created for your Netconfig job which is the same as the job ID (e.g. NMSROOT/files/rme/jobs/NetConfigJob/JID).  Post the contents of this directory.

Hello again, and thanks for your time,

Here you are files from specified directory that I can

post here, because of security concerns. I turned

debugging level for NetConfig, and hope that it will

be usefull.

Thanks again!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: