• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 1940
  • Last Modified:

Catalyst 6509 - SSH Connectivity

Greetings,

I have a Catalyst 6509 that I can telnet to just fine.  It accepts my username/password and recognizes my privilege level, so I can perform administrator functions just fine.  

With SSH it is a different story.  I can login to SSH, but once I authenticate and I'm at at the CLI, I have to enter EN for enabled mode and it doesn't accept my enable mode password...  I already tried resetting the password.

Any ideas?

My version information is below:

Cisco Internetwork Operating System Software
IOS (tm) s72033_rp Software (s72033_rp-PK9SV-M), Version 12.2(17d)SXB10, RELEASE
 SOFTWARE (fc1)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2005 by cisco Systems, Inc.
Compiled Thu 11-Aug-05 14:15 by kellythw
Image text-base: 0x40020FBC, data-base: 0x41F20000

ROM: System Bootstrap, Version 12.2(17r)S2, RELEASE SOFTWARE (fc1)
BOOTLDR: s72033_rp Software (s72033_rp-PK9SV-M), Version 12.2(17d)SXB10, RELEASE
 SOFTWARE (fc1)
0
bbanis2k
Asked:
bbanis2k
  • 10
  • 8
1 Solution
 
mikebernhardtCommented:
Do you have an "enable secret" password? that one takes precedence over the regular enable password.
0
 
bbanis2kAuthor Commented:
Right, the enable secret is the password I'm using...not just a standard enable.
0
 
mikebernhardtCommented:
Do you have local privilege levels set? Post your config and maybe I can see what the problem is.
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
bbanis2kAuthor Commented:
Do you need a specific portion of the config?  I probably should not be posting anything with sensitive information in it...
0
 
mikebernhardtCommented:
You can put xxxx in any IP address or passwords, those aren't relevant here anyway.
0
 
mikebernhardtCommented:
And I don't need any interface configuration either.
0
 
bbanis2kAuthor Commented:
I had to remove access-lists...

sh config
Using 29449 out of 1964024 bytes
!
! Last configuration change at 11:25:55 CST Thu Mar 30 2006 by brandon
! NVRAM config last updated at 11:25:57 CST Thu Mar 30 2006 by brandon
!
version 12.2
service timestamps debug datetime msec localtime
service timestamps log datetime msec localtime
service password-encryption
service counters max age 10
!
hostname S1NSI03545
!
boot system flash sup-bootflash:s72033-pk9sv-mz.122-17d.SXB10.bin
logging buffered notifications
no logging console
enable secret 5 $1$b7/G$oO6e.pmvUSXHveeLgcj1b0
!

clock timezone CST -6
 --More--         clock summer-time CDT recurring
clock calendar-valid
ip subnet-zero
!
!
no ip ftp passive
ip ftp username netxxx
ip ftp password 7 xxxxxxxx
no ip domain-lookup
ip domain-name xxxxxxxxxxxx
!
ip multicast-routing
ip ssh time-out 60
ip ssh authentication-retries 2
ip ssh version 2
mpls ldp logging neighbor-changes
mls rp ip
mls ip multicast threshold 10
mls ip multicast bidir gm-scan-interval 10
no mls flow ip
no mls flow ipv6
mls cef error action freeze
!
 --More--         spanning-tree mode pvst
no spanning-tree optimize bpdu transmission
diagnostic cns publish cisco.cns.device.diag_results
diagnostic cns subscribe cisco.cns.device.diag_commands
!
redundancy
 mode sso
 main-cpu
  auto-sync running-config
  auto-sync standard
!
vlan internal allocation policy ascending
vlan access-log ratelimit 2000
!
!
interface Loopback0
 ip address 10.0.253.233 255.255.255.248
!
interface GigabitEthernet3/1
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface GigabitEthernet3/2
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/3
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/4
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/5
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/6
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface GigabitEthernet3/7
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/8
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/9
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/10
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/11
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/12
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/13
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/14
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet3/15
 no ip address
 switchport
 switchport access vlan 10
 --More--         !
interface GigabitEthernet3/16
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/1
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/2
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/3
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/4
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface GigabitEthernet4/5
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/6
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/7
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/8
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface GigabitEthernet4/9
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/10
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/11
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/12
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/13
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface GigabitEthernet4/14
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/15
 no ip address
 switchport
 switchport access vlan 10
!
interface GigabitEthernet4/16
 description Trunk to Executive 2950 Switch
 no ip address
 switchport
 switchport trunk encapsulation dot1q
 switchport mode trunk
!
interface GigabitEthernet5/1
 no ip address
 shutdown
!
 --More--         interface GigabitEthernet5/2
 no ip address
 shutdown
!
interface FastEthernet6/1
 description IDS Monitor 10 FA6/48
 no ip address
 speed 100
 duplex full
 switchport
!
interface FastEthernet6/2
 description IDS Management Port
 no ip address
 switchport
!
interface FastEthernet6/3
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/4
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface FastEthernet6/5
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/6
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/7
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/8
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet6/9
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/10
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/11
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/12
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/13
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet6/14
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/15
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/16
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/17
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/18
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/19
 description EXCHAGE 2003 BACK-END SERVER
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/20
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/21
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/22
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet6/23
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/24
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/25
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/26
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/27
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/28
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/29
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/30
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/31
 no ip address
 switchport
 switchport access vlan 10
 --More--         !
interface FastEthernet6/32
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/33
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/34
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/35
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/36
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface FastEthernet6/37
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/38
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/39
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/40
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet6/41
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/42
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/43
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/44
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/45
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet6/46
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/47
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet6/48
 description Connection to PIX
 ip address x.x.x.x 255.255.255.0
 speed 100
 duplex full
!
interface FastEthernet7/1
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet7/2
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/3
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/4
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/5
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/6
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet7/7
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/8
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/9
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/10
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/11
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/12
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/13
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/14
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/15
 no ip address
 switchport
 switchport access vlan 10
 --More--         !
interface FastEthernet7/16
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/17
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/18
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/19
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/20
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface FastEthernet7/21
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/22
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/23
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/24
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet7/25
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/26
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/27
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/28
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/29
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet7/30
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/31
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/32
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/33
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/34
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/35
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/36
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/37
 no ip address
 shutdown
!
interface FastEthernet7/38
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet7/39
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/40
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/41
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/42
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/43
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet7/44
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/45
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/46
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/47
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet7/48
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/1
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/2
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/3
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/4
 no ip address
 switchport
 switchport access vlan 10
 --More--         !
interface FastEthernet8/5
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/6
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/7
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/8
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/9
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface FastEthernet8/10
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/11
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/12
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/13
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet8/14
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/15
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/16
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/17
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/18
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet8/19
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/20
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/21
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/22
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/23
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/24
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/25
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/26
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/27
 no ip address
 switchport
 switchport access vlan 10
 --More--         !
interface FastEthernet8/28
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/29
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/30
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/31
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/32
 no ip address
 --More--          switchport
 switchport access vlan 10
!
interface FastEthernet8/33
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/34
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/35
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/36
 no ip address
 switchport
 switchport access vlan 10
!
 --More--         interface FastEthernet8/37
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/38
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/39
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/40
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/41
 no ip address
 switchport
 --More--          switchport access vlan 10
!
interface FastEthernet8/42
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/43
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/44
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/45
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/46
 --More--          no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/47
 no ip address
 switchport
 switchport access vlan 10
!
interface FastEthernet8/48
 no ip address
 switchport
 switchport access vlan 10
!
interface Serial9/0/0
 description 7C6X  AT&T Circuit ID
 bandwidth 1544
 ip address x.x.x.x 255.255.255.248
 no ip unreachables
 no ip mroute-cache
 no fair-queue
!
interface Serial9/0/1
 --More--          no ip address
 shutdown
 no fair-queue
!
interface Serial9/0/2
 no ip address
 shutdown
 no fair-queue
!
interface Serial9/0/3
 no ip address
 shutdown
 no fair-queue
!
interface Vlan1
 ip address 10.106.1.1 255.255.255.0
 no ip redirects
 no ip unreachables
 ip pim sparse-dense-mode
!
interface Vlan10
 ip address 10.106.10.1 255.255.255.0
 ip helper-address 10.106.10.11
 --More--          ip helper-address 10.106.10.13
 no ip redirects
 no ip unreachables
 ip pim sparse-dense-mode
 ip cgmp

!
ip classless
ip route 10.1.1.0 255.255.255.0 192.168.250.185
ip route 172.16.66.0 255.255.255.0 10.106.255.1
ip route 172.16.76.0 255.255.255.0 10.106.255.1
ip route 172.16.106.0 255.255.255.0 10.106.255.1
ip route 172.16.206.0 255.255.255.0 10.106.255.1
no ip http server
ip pim rp-address 10.0.253.233
!
!

!
line con 0
 exec-timeout 15 0
 timeout login response 300
 login local
line vty 0 4
 access-class 110 in
 exec-timeout 15 0
 timeout login response 300
 login local
 transport input telnet ssh
!
!
monitor session 10 source interface Fa6/48
 --More--         monitor session 10 destination interface Fa6/1
ntp clock-period 17180057
ntp server 192.5.41.41
ntp server 192.5.41.40
end

S1NSI03545#
0
 
mikebernhardtCommented:
I don't see how the user names are configured. If you have a privilege 15 argument on it I would suggest removing that and seeing if it works better. You'll need to remove the name and then add it back without that.
0
 
bbanis2kAuthor Commented:
Yeah, I removed the user names from the config as well...

I'll try that.
0
 
bbanis2kAuthor Commented:
I tried creating an account without the privilege level specified and that doesn't work when I try to connect via SSH...
0
 
mikebernhardtCommented:
What do you mean it doesn't work exactly? Do you log in but the enable command fails, or the password fails, or the login fails? Is your ssh client set up to do something automatically? Do you have any privilege levels specified in the config further down that got stripped out accidentally?
0
 
bbanis2kAuthor Commented:
The enable password fails.
0
 
mikebernhardtCommented:
But the same enable password works fine with telnet using the new user configuration?
0
 
bbanis2kAuthor Commented:
No, it still doesn't work when I use the new account w/ out privilege levels set...
0
 
mikebernhardtCommented:
OK, look for a command in the config that is something like
privilege exec level xx enable

Verify your own privileges are at level 1 with
"show privilege"

look in both the running and startup config

You might also try just setting it the way it should be:
config t
privilege exec level 1 enable
0
 
bbanis2kAuthor Commented:
Yes, the privilege level is set to 1.
0
 
mikebernhardtCommented:
Try
config t
privilege exec level 0 enable

To make sure that the "enable" command is normalized.
0
 
mikebernhardtCommented:
So somewhere along the way the privilege level for enable was raised... we used to do that too and it's nothing but trouble!
0

Featured Post

What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

  • 10
  • 8
Tackle projects and never again get stuck behind a technical roadblock.
Join Now