Posts Tagged ‘ios’

Enabling SSH in Cisco IOS

Saturday, September 6th, 2008

Have you ever wanted to use SSH to reach your Cisco router?

Please follow these steps to enable SSH on a Cisco 7200 router.

Router(config)#hostname myrouter
myrouter(config)#ip domain-name gho.no
myrouter(config)#crypto key generate rsa general-keys

The name for the keys will be: myrouter.gho.no
Choose the size of the key modulus in the range of 360 to 2048 for your
General Purpose Keys. Choosing a key modulus greater than 512 may take
a few minutes.

How many bits in the modulus [512]: 1024
% Generating 1024 bit RSA keys, keys will be non-exportable…[OK]
*Sep  6 16:00:27.417: %SSH-5-ENABLED: SSH 1.99 has been enabled

SSH version 1 is prone to a lot of vulnerabilities, you should use SSH version 2.

Router(config)#ip ssh version 2

To verify that you are indeed running SSH version 2, you can issue the show ip ssh command in exec mode.

myrouter#sh ip ssh
SSH Enabled – version 2.0
Authentication timeout: 120 secs; Authentication retries: 3

Saving time with the cisco ‘do’ command

Saturday, September 6th, 2008

This is probably the most usefull and most overlooked command in Cisco IOS.

Have you ever been annoyed from having to leave config mode because you wanted to run exec commands?
Like if you are configuring an interface, and you want to look at that interface configuration?

Well, look no longer!
do To run exec commands in config mode

You can now use do show running-config interface fastethernet 2/0 while you are configuring fa 2/0!

Do you have other time saving commands?   Leave a comment!

Cisco wildcard cheat!

Tuesday, September 2nd, 2008

Just wanted to share a little fast cheat for figuring out the wildcard mask for networks!

The wildcard mask is used some places in IOS, for example in the network command in configuration of the OSPF routing process.

To figure out the network wildcard mask, just take each octet in the netmask and subtract it from 255.

For 255.255.255.0 the wildcard mask will then be 0.0.0.255
For 255.255.255.252 the wildcard mask will be 0.0.0.3 (255 – 252)

Makes work go faster !