Login local / SSH / username not working (not the basic configuration SSH stuff but more tricky)
I'm sorry to bother all of you with such a simple question but the answer is avoiding me for the whole morning and after browsing the web with frenesy I still can't find my answer. I hope you guys have the answer I search.
I have a switch 2940 with IOS ssh capable.
IOS (tm) C2940 Software (C2940-I6K2L2Q4-M), Version 12.1(22)EA14, RELEASE SOFTWARE (fc1)
On this switch I have an IP address, let's say 192.168.1.2 for the sake of the example, which allows me to connect remotely via telnet.
I have the basic SSH configuration set up:
ip domain-name test.com ip ssh time-out 120 ip ssh authentication-retries 3
enable secret test
username user1 privilege 15 secret 5 $1$hh/A$ZJqF74RtN03fbbVwPu4m.1 (this is the result of show run not the actual password)
line vty 0 4
line vty 5 15
transport input ssh
With this configuration SSH is not working. The description of not working is this one:
I access the switch with SSH. OK
I get prompted with username and password. OK
When entering my credentials, I get a bad credentials from entering the user1 login/password.
However if I delete login local and add on global config mode aaa new-model the SSH will work.
At first I didn't pay attention because I use aaa new model (+ the method list set) on all of my switches, but I want to understand why login local is not working with this set up.
On line "vty 0 4" you only have configured "login" which is not valid if you use SSH. When you connect with SSH you land on the first line and whatever you enter, it will fail. When you switch to AAA, login with username/password is default and now you have "disabled" the "login" config and you can use the configured username/password.
-- Don't stop after you've improved your network! Improve the world by lending money to the working poor: http://www.kiva.org/invitedby/karsteni
Question We run asr9001 with XR 6.1.3, and we have a very long delay to
login w/ SSH 1 or 2 to the device compare to IOS device. After
investigation, the there is 1s delay between the client KEXDH_INIT and
the server (XR) KEXDH_REPLY. After debug ssh serv...
Introduction The purpose of this document is to demonstrate the Open
Shortest Path First (OSPF) behavior when the V-bit (Virtual-link bit) is
present in a non-backbone area. The V-bit is signaled in Type-1 LSA only
if the router is the endpoint of one or ...
Hi, I am seeing quite a few issues with patch install and wanted to
share my experience and workaround to this. Login to admin via CLI, then
access root with the “shell” command Issue “df –h” and you’ll probably
see the following directory full or nearly ...