Solved

How to change SSH v1 to v2 or 3 on IPS SSM-10 on ASA5510

Posted on 2011-03-11
1
1,394 Views
Last Modified: 2012-05-11
Hi,

I have IPS SSM-10 on ASA5510. I need to change SSH version. No we use version 1 which should be chanaged to 2 or 3.

Thanks for help !

Maxim.
0
Comment
Question by:Maxim33
1 Comment
 
LVL 3

Accepted Solution

by:
VespaMaru earned 125 total points
ID: 35113386
I don't think you can do it.  The Cisco IPS module supports SSH 1.5 with a 1024 bit RSA key.

From an NMAP
PORT   STATE SERVICE VERSION
22/tcp open  ssh     OpenSSH 3.7.1p2 (protocol 1.99)
|_sshv1: Server supports SSHv1
| ssh-hostkey: 1024 c4:xx:xx:xx:b9 (RSA1)
|_1024 5a:xx:xx:xx:ae (DSA)

Open in new window


Also from their web site:
http://www.cisco.com/en/US/docs/security/ips/7.0/configuration/guide/cli/cli_setup.html#wp1035869

The ASA server however will support SSH version 2 with a key size of 2048
PORT   STATE SERVICE VERSION
22/tcp open  ssh     Cisco SSH 1.25 (protocol 2.0)
|_ssh-hostkey: 2048 2f:xx:xx:xx:3b (RSA)

Open in new window


I would suspect that the reason they differ is because the IPS sensor is an embedded Linux image and theredore runs a different SSH server.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Enabling vNIC failover on a live system 3 83
Can't remote with RDC through ASUS RT-N66W Router 3 57
2960 and a VLAN id of 1237 2 49
Cisco Router / Switch - NAT 10 37
Hello , This is a short article on how would you go about enabling traceoptions on a Juniper router . Traceoptions are similar to Cisco debug commands but these traceoptions are implemented in Juniper networks router . The following demonstr…
Creating an OSPF network that automatically (dynamically) reroutes network traffic over other connections to prevent network downtime.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

895 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

17 Experts available now in Live!

Get 1:1 Help Now