A situation
A switch in a wiring closet on the fifth floor needs a new VLAN. You are at your desk on the ground floor. Walking up with a console cable works, but it is slow, and with 200 switches it is not practical. You need to reach each device's command line over the network.
What it is
Telnet and SSH (Secure Shell) both give you a remote CLI (command-line interface). You type commands on your computer, and they run on the remote device. On a Cisco device, remote sessions arrive on VTY lines (virtual terminal lines), numbered 0 to 4 or 0 to 15.
| Telnet | SSH | |
|---|---|---|
| Port | TCP 23 | TCP 22 |
| Encryption | None: everything is in clear text | The whole session is encrypted |
| Server identity check | No | Yes, with the server's host key |
| Login options | Password | Password or public key |
| Use today | Old labs, port testing | Standard for remote management |
Why SSH replaced Telnet
Telnet sends every keystroke as clear text, including the username and password. Anyone who can capture traffic on the path can read them. SSH encrypts the session before the login prompt even appears.
- 1. Telnet: the attacker's capture shows "Username: admin" and "Password: Cisco123" in clear text.
- 2. SSH: the attacker sees only random-looking bytes. The password never appears.
How an SSH session starts
The first time you connect, your SSH client asks you to accept R1's host key. If the key changes later, treat it as a warning sign.
Configure SSH on a Cisco router
SSH needs a hostname and a domain name (used to name the key), an RSA key pair, a local user and VTY lines that accept only SSH. This configuration is based on Cisco documentation, not run on a lab device:
hostname R1 ip domain name example.com crypto key generate rsa modulus 2048 ip ssh version 2 username admin privilege 15 secret Str0ng-Passw0rd ! line vty 0 4 login local transport input ssh exec-timeout 10 0
crypto key generate rsa modulus 2048 creates the key pair, and ip ssh version 2 allows only SSH version 2. login local checks the username and password against the local user list. transport input ssh blocks Telnet on these lines. exec-timeout 10 0 logs out an idle session after 10 minutes.
How to verify it
This output is based on Cisco documentation, not run on a lab device.
R1#show ip ssh SSH Enabled - version 2.0 Authentication methods:publickey,keyboard-interactive,password Encryption Algorithms:aes128-ctr,aes192-ctr,aes256-ctr MAC Algorithms:hmac-sha2-256,hmac-sha2-512 Authentication timeout: 120 secs; Authentication retries: 3 Minimum expected Diffie Hellman key size : 2048 bits
R1#show ssh Connection Version Mode Encryption Hmac State Username 0 2.0 IN aes256-ctr hmac-sha2-256 Session started admin 0 2.0 OUT aes256-ctr hmac-sha2-256 Session started admin %No SSHv1 server connections running.
ssh -l admin 10.1.1.1Connect from a PC (or from another Cisco router) to R1 as user admin.
Check yourself
You configure transport input ssh on R1's VTY lines. A colleague then tries telnet 10.1.1.1. What happens?
On a new router, crypto key generate rsa fails with an error asking for a domain name. Why?