Catalyst 6509 - SSH Connectivity

Greetings,

I have a Catalyst 6509 that I can telnet to just fine.  It accepts my username/password and recognizes my privilege level, so I can perform administrator functions just fine.  

With SSH it is a different story.  I can login to SSH, but once I authenticate and I'm at at the CLI, I have to enter EN for enabled mode and it doesn't accept my enable mode password...  I already tried resetting the password.

Any ideas?

My version information is below:

Cisco Internetwork Operating System Software
IOS (tm) s72033_rp Software (s72033_rp-PK9SV-M), Version 12.2(17d)SXB10, RELEASE
 SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2005 by cisco Systems, Inc.
Compiled Thu 11-Aug-05 14:15 by kellythw
Image text-base: 0x40020FBC, data-base: 0x41F20000

ROM: System Bootstrap, Version 12.2(17r)S2, RELEASE SOFTWARE (fc1)
BOOTLDR: s72033_rp Software (s72033_rp-PK9SV-M), Version 12.2(17d)SXB10, RELEASE
 SOFTWARE (fc1)
bbanis2kAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

mikebernhardtCommented:
Do you have an "enable secret" password? that one takes precedence over the regular enable password.
0
bbanis2kAuthor Commented:
Right, the enable secret is the password I'm using...not just a standard enable.
0
mikebernhardtCommented:
Do you have local privilege levels set? Post your config and maybe I can see what the problem is.
0
Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

bbanis2kAuthor Commented:
Do you need a specific portion of the config?  I probably should not be posting anything with sensitive information in it...
0
mikebernhardtCommented:
You can put xxxx in any IP address or passwords, those aren't relevant here anyway.
0
mikebernhardtCommented:
And I don't need any interface configuration either.
0
bbanis2kAuthor Commented:
I had to remove access-lists...

sh config
Using 29449 out of 1964024 bytes
!
! Last configuration change at 11:25:55 CST Thu Mar 30 2006 by brandon
! NVRAM config last updated at 11:25:57 CST Thu Mar 30 2006 by brandon
!
version 12.2
service timestamps debug datetime msec localtime
service timestamps log datetime msec localtime
service password-encryption
service counters max age 10
!
hostname S1NSI03545
!
boot system flash sup-bootflash:s72033-pk9sv-mz.122-17d.SXB10.bin
logging buffered notifications
no logging console
enable secret 5 $1$b7/G$oO6e.pmvUSXHveeLgcj1b0
!

clock timezone CST -6
 --More--         clock summer-time CDT recurring
clock calendar-valid
ip subnet-zero
!
!
no ip ftp passive
ip ftp username netxxx
ip ftp password 7 xxxxxxxx
no ip domain-lookup
ip domain-name xxxxxxxxxxxx
!
ip multicast-routing
ip ssh time-out 60
ip ssh authentication-retries 2
ip ssh version 2
mpls ldp logging neighbor-changes
mls rp ip
mls ip multicast threshold 10
mls ip multicast bidir gm-scan-interval 10
no mls flow ip
no mls flow ipv6
mls cef error action freeze
!
 --More--         spanning-tree mode pvst
no spanning-tree optimize bpdu transmission
diagnostic cns publish cisco.cns.device.diag_results
diagnostic cns subscribe cisco.cns.device.diag_commands
!
redundancy
 mode sso
 main-cpu
  auto-sync running-config
  auto-sync standard
!
vlan internal allocation policy ascending
vlan access-log ratelimit 2000
!
!
interface Loopback0
 ip address 10.0.253.233 255.255.255.248
!
interface GigabitEthernet3/1
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface GigabitEthernet3/2
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/3
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/4
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/5
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/6
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface GigabitEthernet3/7
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/8
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/9
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/10
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/11
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/12
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/13
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/14
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/15
 no ip address
 switchport
 switchport access vlan 10
 --More--         !
interface GigabitEthernet3/16
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/1
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/2
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/3
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/4
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface GigabitEthernet4/5
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/6
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/7
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/8
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface GigabitEthernet4/9
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/10
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/11
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/12
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/13
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface GigabitEthernet4/14
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/15
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/16
 description Trunk to Executive 2950 Switch
 no ip address
 switchport
 switchport trunk encapsulation dot1q
 switchport mode trunk
!
interface GigabitEthernet5/1
 no ip address
 shutdown
!
 --More--         interface GigabitEthernet5/2
 no ip address
 shutdown
!
interface FastEthernet6/1
 description IDS Monitor 10 FA6/48
 no ip address
 speed 100
 duplex full
 switchport
!
interface FastEthernet6/2
 description IDS Management Port
 no ip address
 switchport
!
interface FastEthernet6/3
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/4
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface FastEthernet6/5
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/6
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/7
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/8
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet6/9
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/10
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/11
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/12
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/13
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet6/14
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/15
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/16
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/17
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/18
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/19
 description EXCHAGE 2003 BACK-END SERVER
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/20
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/21
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/22
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet6/23
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/24
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/25
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/26
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/27
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/28
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/29
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/30
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/31
 no ip address
 switchport
 switchport access vlan 10
 --More--         !
interface FastEthernet6/32
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/33
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/34
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/35
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/36
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface FastEthernet6/37
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/38
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/39
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/40
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet6/41
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/42
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/43
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/44
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/45
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet6/46
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/47
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/48
 description Connection to PIX
 ip address x.x.x.x 255.255.255.0
 speed 100
 duplex full
!
interface FastEthernet7/1
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet7/2
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/3
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/4
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/5
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/6
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet7/7
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/8
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/9
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/10
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/11
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/12
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/13
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/14
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/15
 no ip address
 switchport
 switchport access vlan 10
 --More--         !
interface FastEthernet7/16
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/17
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/18
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/19
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/20
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface FastEthernet7/21
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/22
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/23
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/24
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet7/25
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/26
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/27
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/28
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/29
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet7/30
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/31
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/32
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/33
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/34
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/35
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/36
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/37
 no ip address
 shutdown
!
interface FastEthernet7/38
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet7/39
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/40
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/41
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/42
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/43
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet7/44
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/45
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/46
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/47
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/48
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/1
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/2
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/3
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/4
 no ip address
 switchport
 switchport access vlan 10
 --More--         !
interface FastEthernet8/5
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/6
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/7
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/8
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/9
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface FastEthernet8/10
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/11
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/12
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/13
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet8/14
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/15
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/16
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/17
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/18
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet8/19
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/20
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/21
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/22
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/23
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/24
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/25
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/26
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/27
 no ip address
 switchport
 switchport access vlan 10
 --More--         !
interface FastEthernet8/28
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/29
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/30
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/31
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/32
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface FastEthernet8/33
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/34
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/35
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/36
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet8/37
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/38
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/39
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/40
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/41
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet8/42
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/43
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/44
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/45
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/46
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/47
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/48
 no ip address
 switchport
 switchport access vlan 10
!
interface Serial9/0/0
 description 7C6X  AT&T Circuit ID
 bandwidth 1544
 ip address x.x.x.x 255.255.255.248
 no ip unreachables
 no ip mroute-cache
 no fair-queue
!
interface Serial9/0/1
 --More--          no ip address
 shutdown
 no fair-queue
!
interface Serial9/0/2
 no ip address
 shutdown
 no fair-queue
!
interface Serial9/0/3
 no ip address
 shutdown
 no fair-queue
!
interface Vlan1
 ip address 10.106.1.1 255.255.255.0
 no ip redirects
 no ip unreachables
 ip pim sparse-dense-mode
!
interface Vlan10
 ip address 10.106.10.1 255.255.255.0
 ip helper-address 10.106.10.11
 --More--          ip helper-address 10.106.10.13
 no ip redirects
 no ip unreachables
 ip pim sparse-dense-mode
 ip cgmp

!
ip classless
ip route 10.1.1.0 255.255.255.0 192.168.250.185
ip route 172.16.66.0 255.255.255.0 10.106.255.1
ip route 172.16.76.0 255.255.255.0 10.106.255.1
ip route 172.16.106.0 255.255.255.0 10.106.255.1
ip route 172.16.206.0 255.255.255.0 10.106.255.1
no ip http server
ip pim rp-address 10.0.253.233
!
!

!
line con 0
 exec-timeout 15 0
 timeout login response 300
 login local
line vty 0 4
 access-class 110 in
 exec-timeout 15 0
 timeout login response 300
 login local
 transport input telnet ssh
!
!
monitor session 10 source interface Fa6/48
 --More--         monitor session 10 destination interface Fa6/1
ntp clock-period 17180057
ntp server 192.5.41.41
ntp server 192.5.41.40
end

S1NSI03545#
0
mikebernhardtCommented:
I don't see how the user names are configured. If you have a privilege 15 argument on it I would suggest removing that and seeing if it works better. You'll need to remove the name and then add it back without that.
0
bbanis2kAuthor Commented:
Yeah, I removed the user names from the config as well...

I'll try that.
0
bbanis2kAuthor Commented:
I tried creating an account without the privilege level specified and that doesn't work when I try to connect via SSH...
0
mikebernhardtCommented:
What do you mean it doesn't work exactly? Do you log in but the enable command fails, or the password fails, or the login fails? Is your ssh client set up to do something automatically? Do you have any privilege levels specified in the config further down that got stripped out accidentally?
0
bbanis2kAuthor Commented:
The enable password fails.
0
mikebernhardtCommented:
But the same enable password works fine with telnet using the new user configuration?
0
bbanis2kAuthor Commented:
No, it still doesn't work when I use the new account w/ out privilege levels set...
0
mikebernhardtCommented:
OK, look for a command in the config that is something like
privilege exec level xx enable

Verify your own privileges are at level 1 with
"show privilege"

look in both the running and startup config

You might also try just setting it the way it should be:
config t
privilege exec level 1 enable
0
bbanis2kAuthor Commented:
Yes, the privilege level is set to 1.
0
mikebernhardtCommented:
Try
config t
privilege exec level 0 enable

To make sure that the "enable" command is normalized.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
mikebernhardtCommented:
So somewhere along the way the privilege level for enable was raised... we used to do that too and it's nothing but trouble!
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Routers

From novice to tech pro — start learning today.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.