A network engineer wants to secure management access to a Cisco IOS router by allowing only SSH and denying Telnet. The engineer applies the following configuration:
line vty 0 4
transport input ssh
However, after applying this, the engineer is unable to establish an SSH session to the router. Which additional configuration is required to enable SSH?
Trap 1: Configure an ACL to permit TCP port 22 inbound on the VTY lines…
While an ACL can restrict SSH access, it is not required to enable SSH. The inability to establish an SSH session is due to missing RSA keys, not an ACL. If an ACL were blocking, the session would be denied, but the symptom would be different (e.g., connection refused or timeout). The primary issue is the lack of SSH server configuration.
Trap 2: Set the login method to use the local database with the 'login…
The 'login local' command is necessary for authentication using local usernames, but it does not enable SSH itself. Without RSA keys, SSH will not work regardless of the login method. The engineer must first generate RSA keys to enable the SSH server, then configure authentication.
Trap 3: Enable the SSH server using the 'ip ssh server' command in global…
The 'ip ssh server' command is not required on Cisco IOS because the SSH server is enabled by default when RSA keys are present. The transport input ssh command already restricts VTY lines to SSH. The missing piece is the RSA key generation, not enabling the SSH server.
- A
Configure an ACL to permit TCP port 22 inbound on the VTY lines using the access-class command.
Why it fails: While an ACL can restrict SSH access, it is not required to enable SSH. The inability to establish an SSH session is due to missing RSA keys, not an ACL. If an ACL were blocking, the session would be denied, but the symptom would be different (e.g., connection refused or timeout). The primary issue is the lack of SSH server configuration.
- B
Set the login method to use the local database with the 'login local' command under the VTY lines.
Why it fails: The 'login local' command is necessary for authentication using local usernames, but it does not enable SSH itself. Without RSA keys, SSH will not work regardless of the login method. The engineer must first generate RSA keys to enable the SSH server, then configure authentication.
- C
Enable the SSH server using the 'ip ssh server' command in global configuration mode.
Why it fails: The 'ip ssh server' command is not required on Cisco IOS because the SSH server is enabled by default when RSA keys are present. The transport input ssh command already restricts VTY lines to SSH. The missing piece is the RSA key generation, not enabling the SSH server.
- D
Configure a domain name and generate RSA keys using the crypto key generate rsa command.
SSH requires a hostname and domain name to generate RSA keys. Without RSA keys, the SSH server cannot function. The 'crypto key generate rsa' command generates the keys after the domain name is set. This is a mandatory step to enable SSH on Cisco IOS devices.