networking-forum.com
Community BlogCommunity Wiki * Register  * Search  * Login
View unanswered postsView active topics

All times are UTC - 6 hours [ DST ]



Post new topic Reply to topic  [ 6 posts ] 
Author Message
PostPosted: Sun May 13, 2012 1:57 pm 
Offline
Ultimate Member
Ultimate Member

Joined: Wed Aug 03, 2011 12:24 pm
Posts: 504
Location: Charleston, SC
Certs: MCSE, MCP+I, SEC+ (working on CCENT/CCNA)
Folks:

I have several 3560G switches which have recently been upgraded to 12.2.58.....

prior, they were running 12.2.20, and ACLs were in place. No changes have been made to the config (they still have ACLs in place) or to the client I am trying to access them from via SSH.

Client is on the ACL, in other words.

I upgraded and although I can ping the switches from the machine I am trying to SSH to them from, and the nodes behind them work just fine (we can access web, logins, everything from the workstations behind the switches), I can not reach some of the switches via SSH.

Any thoughts? One or two of the switches I changed the names on, weeks ago. First thought was perhaps that had invalidated the RSA certificate on the switches. However, I've been able to access these same switches since the name change, right up till I upgraded IOS.

I am not getting SSH timeout, I am getting "connection refused" in putty. Same error I would get in event of an ACL issue (ie: trying to access from a host not on the ACL allow list).

Something I need to look into is the possibility of too many users on SSH into the device, by way of hung sessions. However, one ofthe switches in question was power-cycled after reload, so I doubt that's the issue.


Top
 Profile  
 
PostPosted: Sun May 13, 2012 2:36 pm 
Offline
Ultimate Member
Ultimate Member

Joined: Wed Aug 03, 2011 12:24 pm
Posts: 504
Location: Charleston, SC
Certs: MCSE, MCP+I, SEC+ (working on CCENT/CCNA)
OK this makes NO sense- since I have other, identical-case switches that didn't require this.. :shrugs:

I resolved this be rekeying the switch.


Top
 Profile  
 
PostPosted: Sun May 13, 2012 2:45 pm 
Offline
Post Whore
Post Whore

Joined: Fri Jul 09, 2010 7:38 pm
Posts: 1802
I bumped in to a similar issue with that code, but telnet was also broken, and you couldn't log in through the console.

_________________
http://networking.ventrefamily.com


Top
 Profile  
 
PostPosted: Sun May 13, 2012 3:22 pm 
Offline
Ultimate Member
Ultimate Member

Joined: Wed Aug 03, 2011 12:24 pm
Posts: 504
Location: Charleston, SC
Certs: MCSE, MCP+I, SEC+ (working on CCENT/CCNA)
god, I'd be screwed if not for the console working..

luckily, Telnet is forbidden in this enclave :)


Top
 Profile  
 
PostPosted: Sun May 13, 2012 8:57 pm 
Offline
Member
Member

Joined: Fri Nov 13, 2009 4:42 pm
Posts: 199
Certs: CCIE R&S
Try regenerating your crypto key. Something like:
crypto key gen rsa usa mod 1024
should do the trick.


Top
 Profile  
 
PostPosted: Mon May 14, 2012 6:41 am 
Offline
Ultimate Member
Ultimate Member

Joined: Wed Aug 03, 2011 12:24 pm
Posts: 504
Location: Charleston, SC
Certs: MCSE, MCP+I, SEC+ (working on CCENT/CCNA)
Yep, that's what I did


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 6 posts ] 

All times are UTC - 6 hours [ DST ]


Who is online

Users browsing this forum: anauj0101, Exabot [Bot], javin, srg, wintermute000 and 8 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB® Forum Software © phpBB Group