Cisco ASR1002-10G-VPN/K9 Software Guide - Page 282

Examples, Step 8

Page 282 highlights

Configuring Persistent SSH Chapter 8 Console Port, Telnet, and SSH Handling Step 8 Step 9 Step 10 Step 11 Command or Action time-out timeout-interval Example: Router(config-tmap)# time-out 30 transport interface gigabitethernet 0 Example: Router(config-tmap)# transport interface gigabitethernet 0 exit Example: Router(config-tmap)# exit transport type persistent ssh input transport-map-name Example: Router(config)# transport type persistent ssh input sshhandler Purpose (Optional) Specifies the SSH time-out interval in seconds. The default timeout-interval is 120 seconds. Applies the transport map settings to the Management Ethernet interface (interface gigabitethernet 0). Persistent SSH can only be applied to the Management Ethernet interface on the Cisco ASR 1000 Series Routers. Exits transport map configuration mode to re-enter global configuration mode. Applies the settings defined in the transport map to the Management Ethernet interface. The transport-map-name for this command must match the transport-map-name defined in the transport-map type persistent ssh command. Examples In the following example, a transport map that will make all SSH connections wait for the vty line to become active before connecting to the router is configured and applied to the Management Ethernet interface (interface gigabitethernet 0). The RSA keypair is named sshkeys. This example only uses the commands required to configure persistent SSH. Router(config)# transport-map type persistent ssh sshhandler Router(config-tmap)# connection wait allow Router(config-tmap)# rsa keypair-name sshkeys Router(config-tmap)# transport interface gigabitethernet 0 In the following example, a transport map is configured that will apply the following settings to any users attempting to access the Management Ethernet port via SSH: • Users using SSH will wait for the vty line to become active, but will enter diagnostic mode if the attempt to access IOS through the vty line is interrupted. • The RSA keypair name is sshkeys • The connection allows one authentication retry. • The banner "--Welcome to Diagnostic Mode--" will appear if diagnostic mode is entered as a result of SSH handling through this transport map. • The banner "--Waiting for vty line--" will appear if the connection is waiting for the vty line to become active. The transport map is then applied to the interface when the transport type persistent ssh input command is entered to enable persistent SSH: Router(config)# transport-map type persistent ssh sshhandler Router(config-tmap)# connection wait allow interruptible 8-10 Cisco ASR 1000 Series Aggregation Services Routers Software Configuration Guide OL-16506-10

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378

8-10
Cisco ASR 1000 Series Aggregation Services Routers Software Configuration Guide
OL-16506-10
Chapter 8
Console Port, Telnet, and SSH Handling
Configuring Persistent SSH
Examples
In the following example, a transport map that will make all SSH connections wait for the vty line to
become active before connecting to the router is configured and applied to the Management Ethernet
interface (interface gigabitethernet 0). The RSA keypair is named sshkeys.
This example only uses the commands required to configure persistent SSH.
Router(config)# transport-map type persistent ssh sshhandler
Router(config-tmap)# connection wait allow
Router(config-tmap)# rsa keypair-name sshkeys
Router(config-tmap)# transport interface gigabitethernet 0
In the following example, a transport map is configured that will apply the following settings to any users
attempting to access the Management Ethernet port via SSH:
Users using SSH will wait for the vty line to become active, but will enter diagnostic mode if the
attempt to access IOS through the vty line is interrupted.
The RSA keypair name is sshkeys
The connection allows one authentication retry.
The banner “
--Welcome to Diagnostic Mode--
” will appear if diagnostic mode is entered as a
result of SSH handling through this transport map.
The banner “
--Waiting for vty line--
” will appear if the connection is waiting for the vty line
to become active.
The transport map is then applied to the interface when the
transport type persistent ssh input
command is entered to enable persistent SSH:
Router(config)# transport-map type persistent ssh sshhandler
Router(config-tmap)# connection wait allow interruptible
Step 8
time-out
timeout-interval
Example:
Router(config-tmap)#
time-out 30
(Optional) Specifies the SSH time-out interval in seconds.
The default
timeout-interval
is 120 seconds.
Step 9
transport interface gigabitethernet 0
Example:
Router(config-tmap)#
transport interface
gigabitethernet 0
Applies the transport map settings to the Management
Ethernet interface (interface gigabitethernet 0).
Persistent SSH can only be applied to the Management
Ethernet interface on the Cisco ASR 1000 Series Routers.
Step 10
exit
Example:
Router(config-tmap)#
exit
Exits transport map configuration mode to re-enter global
configuration mode.
Step 11
transport type persistent ssh input
transport-map-name
Example:
Router(config)#
transport type persistent ssh
input sshhandler
Applies the settings defined in the transport map to the
Management Ethernet interface.
The
transport-map-name
for this command must match the
transport-map-name
defined in the
transport-map type
persistent ssh
command.
Command or Action
Purpose