Specifications
Managing the Management Services
5-10 Configuring and Managing IP Interfaces and Services
Session Timeouts
EachSSHsessionisgovernedbytwotimeouts:
•Idletimeout—controlshowlonganopenSSHsessioncanremainidlebeforeMSSclosesthe
session.Thedefaultidletimeoutis30minutes.Youcansettheidletimeouttoavaluefrom0
(disabled)to2,147,483,647minutes.
•Absolutetimeout—controlshowlonganSSH
sessioncanremainopen,regardlessofhow
activethesessionis.Theabsolutetimeoutisdisabledbydefault.EnterasysNetworks
recommendsusingtheidletimeouttocloseunusedsessions.However,iftheidletimeoutis
disabled,MSSchangesthedefaultabsolutetimeoutfrom0(disabled)to60minutestoprevent
anabandonedsessionfromremainingopenindefinitely.Youcansettheabsolutetimeouttoa
valuefrom0(disab led)to2,147,483,647minutes
Enabling SSH
SSHisenabledbydefault.Todisableorreenableit,usethefollowing command:
setipsshserver{enable|disable}
Example
SSHrequiresanSSHauthenticationkey.YoucangenerateoneorallowMSStogenerate one.The
firsttimeanSSHclientattemptstoaccesstheSSHserveronaRoamAboutSwitch,theswitch
automaticallygeneratesa1024‐byteSSHkey.If youwanttousea2048‐bytekeyinstead,
usethe
followingcommandtogenerateone:
crypto generate key ssh 2048
keypairgenerated
Ifakeyhasalreadybeengenerated,thecommandreplacestheoldkeywithanewone.Thenew
keytakesaffectforallnewSSHsessions.
Youcanverifythekeyusingthefollowingcommand:
show crypto key ssh
Example
show crypto key ssh
ec:6f:56:7f:d1:fd:c0:28:93:ae:a4:f9:7c:f5:13:04
Thiscommanddisplaysthechecksum(alsocalledafingerprint)ofthepublickey.Whenyou
initiallyconnecttotheRoamAboutSwitchwithanSSHclient,youcancomparetheSSHkey
checksumdisplayedbytheRoamAboutSwitchwiththeonedisplayedbytheclienttoverifythat
youreallyare
connectedtotheRoamAboutSwitchandnotanotherdevice.Generally,SSHclients
remembertheencryptionkeyafterthefirstconnection,soyouneedtocheckthekeyonlyonce.
TheRoamAboutSwitchswitchstoresthekeyinnonvolatilestoragewherethekeyremainseven
aftersoftwarereboots.
Note: To ensure that all CLI management sessions are encrypted, after you configure SSH, disable
Tel n e t .