?
Solved

Remote Login to Cisco Router Fails

Posted on 2010-09-21
2
Medium Priority
?
3,331 Views
Last Modified: 2012-05-10
When attempting to use Cisco Configuration Professional to "Discover" and connect to my Cisco 2921 ISR (Second Generation), I receive the error: "Discovery could not be completed because the security certificate was rejected." SSHv2 login also fails, but with no errors.

There has been no change to the router configuration since the last time it worked.
The certificate being used is self signed.
Yes. I've already restarted the router (pulling a known good startup-config), which had not impact.

On reboot, the console indicates the following errors:
SSHv2  RSA Signature Generation Failed: Status 8
SSHv2  Signature creation failed: Status 22

show ip ssh, displays the key info as expected, and show ssh shows SSHv2 running, but with no connected sessions.

Any thoughts on why remote access spontaneously stopped working?

 
0
Comment
Question by:Matthew England
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 2

Accepted Solution

by:
fs40490 earned 1500 total points
ID: 33729734
Have you tried to regenerate a new self signed key?

I know that this does not get to the root cause but it should be able to get you back up and running.

0
 
LVL 7

Author Closing Comment

by:Matthew England
ID: 33738587
Yes. Creating a new self signed key works and is fine for this time, but it'd be nice to know why this occurred. And how to prevent it from happening again.

crypto key zeroize rsa
crypto key generate rsa
2048

This time I was onsite and able to get in to the router, but there's a point to having remote access. If it's going to randomly fail... what's the point in having it?
0

Featured Post

Supports up to 4K resolution!

The VS192 2-Port 4K DisplayPort Splitter is perfect for anyone who needs to send one source of DisplayPort high definition video to two or four DisplayPort displays. The VS192 can split and also expand DisplayPort audio/video signal on two or four DisplayPort monitors.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the hope of saving someone else's sanity... About a year ago we bought a Cisco 1921 router with two ADSL/VDSL EHWIC cards to load balance local network traffic over the two broadband lines we have, but we couldn't get the routing to work consi…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question