cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
452
Views
0
Helpful
7
Replies

Cant SSH to Router After Changing Modulos Size to 512

WildMan365
Level 1
Level 1


I was SSH'd into a router & changed the the modulos size using the "crypto key generate rsa" command. After that when I try SSH with Putty I get a "connection refused" error & cant log in anymore. Any ideas?

7 Replies 7

Hi,
Without seeing a debug, my guess is that the router or putty is not permitting the connection because modulus size 512 is too weak. The recommended modulus for a CA key is 2048 bits, try removing the existing key using "crypto key zeroize rsa" then recreating with modulus 2048.
HTH

WildMan365
Level 1
Level 1

I assume there is no way to do this remotely?

You can actually fix that remotely if you have your community read/write configured and have a software that can push the config change to the router. In my case, I use the solarwinds admin toolset. I fixed a lot of my SSH issues with it.

I have read only. I think I'm screwed here & need to console in to fix this.

Is your remote access on the vty restricted to only SSH, or is telnet also permitted??

 

HTH

 

Rick

HTH

Rick

Good question. Only SSH is enabled. I should have enabled telnet temporarily when I was reconfiguring.

If your SNMP is read only and if only SSH is permitted on vty then it looks like your only alternative is the console port.

 

HTH

 

Rick

HTH

Rick
Review Cisco Networking products for a $25 gift card