We help IT Professionals succeed at work.

We've partnered with Certified Experts, Carl Webster and Richard Faulkner, to bring you two Citrix podcasts. Learn about 2020 trends and get answers to your biggest Citrix questions!Listen Now

x

Catalyst 6509 - SSH Connectivity

bbanis2k
bbanis2k asked
on
Medium Priority
2,031 Views
Last Modified: 2012-05-05
Greetings,

I have a Catalyst 6509 that I can telnet to just fine.  It accepts my username/password and recognizes my privilege level, so I can perform administrator functions just fine.  

With SSH it is a different story.  I can login to SSH, but once I authenticate and I'm at at the CLI, I have to enter EN for enabled mode and it doesn't accept my enable mode password...  I already tried resetting the password.

Any ideas?

My version information is below:

Cisco Internetwork Operating System Software
IOS (tm) s72033_rp Software (s72033_rp-PK9SV-M), Version 12.2(17d)SXB10, RELEASE
 SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2005 by cisco Systems, Inc.
Compiled Thu 11-Aug-05 14:15 by kellythw
Image text-base: 0x40020FBC, data-base: 0x41F20000

ROM: System Bootstrap, Version 12.2(17r)S2, RELEASE SOFTWARE (fc1)
BOOTLDR: s72033_rp Software (s72033_rp-PK9SV-M), Version 12.2(17d)SXB10, RELEASE
 SOFTWARE (fc1)
Comment
Watch Question

CERTIFIED EXPERT
Top Expert 2004

Commented:
Do you have an "enable secret" password? that one takes precedence over the regular enable password.

Author

Commented:
Right, the enable secret is the password I'm using...not just a standard enable.
CERTIFIED EXPERT
Top Expert 2004

Commented:
Do you have local privilege levels set? Post your config and maybe I can see what the problem is.

Author

Commented:
Do you need a specific portion of the config?  I probably should not be posting anything with sensitive information in it...
CERTIFIED EXPERT
Top Expert 2004

Commented:
You can put xxxx in any IP address or passwords, those aren't relevant here anyway.
CERTIFIED EXPERT
Top Expert 2004

Commented:
And I don't need any interface configuration either.

Author

Commented:
I had to remove access-lists...

sh config
Using 29449 out of 1964024 bytes
!
! Last configuration change at 11:25:55 CST Thu Mar 30 2006 by brandon
! NVRAM config last updated at 11:25:57 CST Thu Mar 30 2006 by brandon
!
version 12.2
service timestamps debug datetime msec localtime
service timestamps log datetime msec localtime
service password-encryption
service counters max age 10
!
hostname S1NSI03545
!
boot system flash sup-bootflash:s72033-pk9sv-mz.122-17d.SXB10.bin
logging buffered notifications
no logging console
enable secret 5 $1$b7/G$oO6e.pmvUSXHveeLgcj1b0
!

clock timezone CST -6
 --More--         clock summer-time CDT recurring
clock calendar-valid
ip subnet-zero
!
!
no ip ftp passive
ip ftp username netxxx
ip ftp password 7 xxxxxxxx
no ip domain-lookup
ip domain-name xxxxxxxxxxxx
!
ip multicast-routing
ip ssh time-out 60
ip ssh authentication-retries 2
ip ssh version 2
mpls ldp logging neighbor-changes
mls rp ip
mls ip multicast threshold 10
mls ip multicast bidir gm-scan-interval 10
no mls flow ip
no mls flow ipv6
mls cef error action freeze
!
 --More--         spanning-tree mode pvst
no spanning-tree optimize bpdu transmission
diagnostic cns publish cisco.cns.device.diag_results
diagnostic cns subscribe cisco.cns.device.diag_commands
!
redundancy
 mode sso
 main-cpu
  auto-sync running-config
  auto-sync standard
!
vlan internal allocation policy ascending
vlan access-log ratelimit 2000
!
!
interface Loopback0
 ip address 10.0.253.233 255.255.255.248
!
interface GigabitEthernet3/1
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface GigabitEthernet3/2
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/3
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/4
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/5
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/6
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface GigabitEthernet3/7
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/8
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/9
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/10
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/11
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/12
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/13
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/14
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/15
 no ip address
 switchport
 switchport access vlan 10
 --More--         !
interface GigabitEthernet3/16
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/1
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/2
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/3
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/4
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface GigabitEthernet4/5
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/6
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/7
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/8
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface GigabitEthernet4/9
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/10
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/11
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/12
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/13
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface GigabitEthernet4/14
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/15
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/16
 description Trunk to Executive 2950 Switch
 no ip address
 switchport
 switchport trunk encapsulation dot1q
 switchport mode trunk
!
interface GigabitEthernet5/1
 no ip address
 shutdown
!
 --More--         interface GigabitEthernet5/2
 no ip address
 shutdown
!
interface FastEthernet6/1
 description IDS Monitor 10 FA6/48
 no ip address
 speed 100
 duplex full
 switchport
!
interface FastEthernet6/2
 description IDS Management Port
 no ip address
 switchport
!
interface FastEthernet6/3
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/4
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface FastEthernet6/5
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/6
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/7
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/8
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet6/9
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/10
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/11
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/12
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/13
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet6/14
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/15
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/16
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/17
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/18
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/19
 description EXCHAGE 2003 BACK-END SERVER
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/20
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/21
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/22
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet6/23
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/24
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/25
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/26
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/27
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/28
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/29
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/30
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/31
 no ip address
 switchport
 switchport access vlan 10
 --More--         !
interface FastEthernet6/32
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/33
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/34
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/35
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/36
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface FastEthernet6/37
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/38
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/39
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/40
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet6/41
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/42
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/43
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/44
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/45
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet6/46
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/47
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/48
 description Connection to PIX
 ip address x.x.x.x 255.255.255.0
 speed 100
 duplex full
!
interface FastEthernet7/1
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet7/2
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/3
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/4
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/5
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/6
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet7/7
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/8
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/9
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/10
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/11
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/12
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/13
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/14
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/15
 no ip address
 switchport
 switchport access vlan 10
 --More--         !
interface FastEthernet7/16
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/17
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/18
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/19
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/20
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface FastEthernet7/21
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/22
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/23
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/24
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet7/25
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/26
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/27
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/28
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/29
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet7/30
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/31
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/32
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/33
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/34
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/35
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/36
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/37
 no ip address
 shutdown
!
interface FastEthernet7/38
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet7/39
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/40
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/41
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/42
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/43
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet7/44
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/45
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/46
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/47
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/48
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/1
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/2
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/3
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/4
 no ip address
 switchport
 switchport access vlan 10
 --More--         !
interface FastEthernet8/5
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/6
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/7
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/8
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/9
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface FastEthernet8/10
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/11
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/12
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/13
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet8/14
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/15
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/16
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/17
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/18
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet8/19
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/20
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/21
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/22
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/23
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/24
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/25
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/26
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/27
 no ip address
 switchport
 switchport access vlan 10
 --More--         !
interface FastEthernet8/28
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/29
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/30
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/31
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/32
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface FastEthernet8/33
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/34
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/35
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/36
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet8/37
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/38
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/39
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/40
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/41
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet8/42
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/43
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/44
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/45
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/46
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/47
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/48
 no ip address
 switchport
 switchport access vlan 10
!
interface Serial9/0/0
 description 7C6X  AT&T Circuit ID
 bandwidth 1544
 ip address x.x.x.x 255.255.255.248
 no ip unreachables
 no ip mroute-cache
 no fair-queue
!
interface Serial9/0/1
 --More--          no ip address
 shutdown
 no fair-queue
!
interface Serial9/0/2
 no ip address
 shutdown
 no fair-queue
!
interface Serial9/0/3
 no ip address
 shutdown
 no fair-queue
!
interface Vlan1
 ip address 10.106.1.1 255.255.255.0
 no ip redirects
 no ip unreachables
 ip pim sparse-dense-mode
!
interface Vlan10
 ip address 10.106.10.1 255.255.255.0
 ip helper-address 10.106.10.11
 --More--          ip helper-address 10.106.10.13
 no ip redirects
 no ip unreachables
 ip pim sparse-dense-mode
 ip cgmp

!
ip classless
ip route 10.1.1.0 255.255.255.0 192.168.250.185
ip route 172.16.66.0 255.255.255.0 10.106.255.1
ip route 172.16.76.0 255.255.255.0 10.106.255.1
ip route 172.16.106.0 255.255.255.0 10.106.255.1
ip route 172.16.206.0 255.255.255.0 10.106.255.1
no ip http server
ip pim rp-address 10.0.253.233
!
!

!
line con 0
 exec-timeout 15 0
 timeout login response 300
 login local
line vty 0 4
 access-class 110 in
 exec-timeout 15 0
 timeout login response 300
 login local
 transport input telnet ssh
!
!
monitor session 10 source interface Fa6/48
 --More--         monitor session 10 destination interface Fa6/1
ntp clock-period 17180057
ntp server 192.5.41.41
ntp server 192.5.41.40
end

S1NSI03545#
CERTIFIED EXPERT
Top Expert 2004

Commented:
I don't see how the user names are configured. If you have a privilege 15 argument on it I would suggest removing that and seeing if it works better. You'll need to remove the name and then add it back without that.

Author

Commented:
Yeah, I removed the user names from the config as well...

I'll try that.

Author

Commented:
I tried creating an account without the privilege level specified and that doesn't work when I try to connect via SSH...
CERTIFIED EXPERT
Top Expert 2004

Commented:
What do you mean it doesn't work exactly? Do you log in but the enable command fails, or the password fails, or the login fails? Is your ssh client set up to do something automatically? Do you have any privilege levels specified in the config further down that got stripped out accidentally?

Author

Commented:
The enable password fails.
CERTIFIED EXPERT
Top Expert 2004

Commented:
But the same enable password works fine with telnet using the new user configuration?

Author

Commented:
No, it still doesn't work when I use the new account w/ out privilege levels set...
CERTIFIED EXPERT
Top Expert 2004

Commented:
OK, look for a command in the config that is something like
privilege exec level xx enable

Verify your own privileges are at level 1 with
"show privilege"

look in both the running and startup config

You might also try just setting it the way it should be:
config t
privilege exec level 1 enable

Author

Commented:
Yes, the privilege level is set to 1.
CERTIFIED EXPERT
Top Expert 2004
Commented:
Try
config t
privilege exec level 0 enable

To make sure that the "enable" command is normalized.

Not the solution you were looking for? Getting a personalized solution is easy.

Ask the Experts
CERTIFIED EXPERT
Top Expert 2004

Commented:
So somewhere along the way the privilege level for enable was raised... we used to do that too and it's nothing but trouble!
Access more of Experts Exchange with a free account
Thanks for using Experts Exchange.

Create a free account to continue.

Limited access with a free account allows you to:

  • View three pieces of content (articles, solutions, posts, and videos)
  • Ask the experts questions (counted toward content limit)
  • Customize your dashboard and profile

*This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

OR

Please enter a first name

Please enter a last name

8+ characters (letters, numbers, and a symbol)

By clicking, you agree to the Terms of Use and Privacy Policy.