Routelearn.net
Course menu

Unit 7: TCP, UDP and PortsLesson 7.3.3 (15 of 20 in this unit)48 of 84 in the Network Fundamentals course

SSH and Telnet

Logging in to a router or server remotely, and why SSH replaced Telnet.

Beginner · 8 min read

SSH (Secure Shell) is a protocol that provides an encrypted, authenticated remote command-line session, by default over TCP port 22. It replaces Telnet (TCP port 23), which sends everything, including passwords, in clear text.

In simple terms: SSH lets you type commands on a remote router or server as if you were sitting in front of it. Unlike Telnet, it encrypts everything, so nobody can read your password on the way.

A situation

A switch in a wiring closet on the fifth floor needs a new VLAN. You are at your desk on the ground floor. Walking up with a console cable works, but it is slow, and with 200 switches it is not practical. You need to reach each device's command line over the network.

What it is

Telnet and SSH (Secure Shell) both give you a remote CLI (command-line interface). You type commands on your computer, and they run on the remote device. On a Cisco device, remote sessions arrive on VTY lines (virtual terminal lines), numbered 0 to 4 or 0 to 15.

TelnetSSH
PortTCP 23TCP 22
EncryptionNone: everything is in clear textThe whole session is encrypted
Server identity checkNoYes, with the server's host key
Login optionsPasswordPassword or public key
Use todayOld labs, port testingStandard for remote management

Why SSH replaced Telnet

Telnet sends every keystroke as clear text, including the username and password. Anyone who can capture traffic on the path can read them. SSH encrypts the session before the login prompt even appears.

Admin PC10.1.1.50Access switchAttackercapturingR110.1.1.1
  1. 1. Telnet: the attacker's capture shows "Username: admin" and "Password: Cisco123" in clear text.
  2. 2. SSH: the attacker sees only random-looking bytes. The password never appears.

How an SSH session starts

Step 1 of 4 · Version exchange
Admin PC
10.1.1.50
Management LAN
R1
10.1.1.1:22

The first time you connect, your SSH client asks you to accept R1's host key. If the key changes later, treat it as a warning sign.

Configure SSH on a Cisco router

SSH needs a hostname and a domain name (used to name the key), an RSA key pair, a local user and VTY lines that accept only SSH. This configuration is based on Cisco documentation, not run on a lab device:

hostname R1
ip domain name example.com
crypto key generate rsa modulus 2048
ip ssh version 2
username admin privilege 15 secret Str0ng-Passw0rd
!
line vty 0 4
 login local
 transport input ssh
 exec-timeout 10 0

crypto key generate rsa modulus 2048 creates the key pair, and ip ssh version 2 allows only SSH version 2. login local checks the username and password against the local user list. transport input ssh blocks Telnet on these lines. exec-timeout 10 0 logs out an idle session after 10 minutes.

How to verify it

This output is based on Cisco documentation, not run on a lab device.

Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ip ssh
SSH Enabled - version 2.0
Authentication methods:publickey,keyboard-interactive,password
Encryption Algorithms:aes128-ctr,aes192-ctr,aes256-ctr
MAC Algorithms:hmac-sha2-256,hmac-sha2-512
Authentication timeout: 120 secs; Authentication retries: 3
Minimum expected Diffie Hellman key size : 2048 bits
What to look for: SSH Enabled - version 2.0 confirms that SSH is running (so the RSA key exists) and that only SSH version 2 is allowed. The Encryption Algorithms line lists the ciphers R1 will accept, and Authentication retries: 3 is how many failed logins are allowed per connection.
Example output · based on Cisco documentation; exact format varies by platform and software version
R1#show ssh
Connection Version Mode Encryption  Hmac           State             Username
0          2.0     IN   aes256-ctr  hmac-sha2-256  Session started   admin
0          2.0     OUT  aes256-ctr  hmac-sha2-256  Session started   admin
%No SSHv1 server connections running.
What to look for: one active session (connection 0) from user admin, using SSH version 2.0. The IN and OUT lines show it is encrypted with AES-256 in both directions.
ssh -l admin 10.1.1.1

Connect from a PC (or from another Cisco router) to R1 as user admin.

Check yourself

Predict · scenario 1

You configure transport input ssh on R1's VTY lines. A colleague then tries telnet 10.1.1.1. What happens?

Predict · scenario 2

On a new router, crypto key generate rsa fails with an error asking for a domain name. Why?