Examples
The following example shows the gNSI configurations on the router:
Router# config
Router(config)# grpc port 57888
Router(config)# grpc no-tls
Router(config)# commit
Router(config)# end
To view the gNSI configuration on the router, use the show ssh server gnsi configuration command.
Router# show ssh server gnsi configuration
Wed May 1 14:45:29.008 UTC
----------------------------------------
AuthorizedKeysFile /etc/ciscossh/authorized_list/%u/authorized_keys
AuthorizedPrincipalsFile /etc/ciscossh/authorized_list/%u/authorized_principals
HostCertificate /etc/ciscossh/host_certs/ecdsa-sha2-nistp256-cert.pub
HostCertificate /etc/ciscossh/host_certs/ecdsa-sha2-nistp521-cert.pub
HostCertificate /etc/ciscossh/host_certs/ed25519-cert.pub
----------------------------------------
The following example shows the VRF configurations on the router:
Router# config
Router(config)# ssh server vrf default
Router(config)# commit
Router(config)# end
To view the server VRF configuration on the router, use the show ssh server vrf command.
Router# show ssh server vrf default configuration
----------------------------------------
UsePAM yes
HostKeyAlgorithms x509v3-ssh-rsa,ssh-rsa-cert-v01@openssh.com,ssh-ed25519-cert-v01@openssh.com,
ecdsa-sha2-nistp521-cert-v01@openssh.com,ecdsa-sha2-nistp256-cert-v01@openssh.com,
ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,ssh-ed25519,rsa-sha2-512,
rsa-sha2-256,ssh-rsa,ssh-dss
PermitRootLogin yes
MaxAuthTries 20
MaxSessions 16
RekeyLimit 1024M 60m
Subsystem sftp /pkg/bin/sftp-server
MACs hmac-sha2-512,hmac-sha2-256,hmac-sha1
LoginGraceTime 30
ClientAliveInterval 60
AllowTcpForwarding no
MaxStartups 150
LogLevel DEBUG
IPQoS 0x40
HostKey /pkg/ecdsa-sha2-nistp256
HostKey /pkg/ecdsa-sha2-nistp384
HostKey /pkg/ecdsa-sha2-nistp521
HostKey /pkg/ed25519
HostKey /pkg/rsa
HostKey /pkg/dsa
HostKey /pkg/x509v3-ssh-rsa
HostKey /pkg/ssh-rsa-cert-v01
AcceptedAlgorithms x509v3-ssh-rsa,x509v3-ecdsa-sha2-nistp256,x509v3-ecdsa-sha2-nistp384,
x509v3-ecdsa-sha2-nistp521,x509v3-ssh-dss,ssh-rsa,ssh-rsa-cert-v01@openssh.com,
rsa-sha2-256-cert-v01@openssh.com,rsa-sha2-512-cert-v01@openssh.com,
ecdsa-sha2-nistp256-cert-v01@openssh.com,ecdsa-sha2-nistp384-cert-v01@openssh.com,
ecdsa-sha2-nistp521-cert-v01@openssh.com,ssh-dss-cert-v01@openssh.com,ssh-ed25519-cert-v01@openssh.com,
ecdsa-sha2-nistp256,ecdsa-sha2-nistp384,ecdsa-sha2-nistp521,ssh-ed25519,rsa-sha2-256,rsa-sha2-512,ssh-rsa
Port 22
PidFile /var/run/sshd_default.pid
To view the server host-keys on the router, use the show ssh server host-keys command.
Router# show ssh server host-keys
Wed May 1 14:39:36.746 UTC
----------------------------------------
Key label: the_default
Type : ED25519
Data : ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAILMXlhKk4HixCE/HGwKGkbGwgLAT7ecm0fze7ZsQQIJw
xxxx@vxr-slurm-146.xxxx.com
Key label: the_default
Type : ECDSA General Curve Nistp256
Degree : 256
Data : ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBA9mwnz5O1+
oV5m6Zdo3Mqmc6IjkxrCbt+E/vhK67/B8mEaGEO5JfFcJ7zHp905HsiLm0mYijS4zQCZNYRMcvNk= xxxx@vxr-slurm-146.xxxx.com
Key label: the_default
Type : ECDSA General Curve Nistp521
Degree : 521
Data : ecdsa-sha2-nistp521 AAAAE2VjZHNhLXNoYTItbmlzdHA1MjEAAAAIbmlzdHA1MjEAAACFBABjiqUtIXeBAfO
sur6xhCaX0865nf6Gp0gIQC/DzBNC1AJTtqZfQl4FMHPTkixAsHZ/7OVSh70tMgk4VzCHH+EmpAB5zIrz7fSzJFXSs9DJqw
75DxtOsjb/mcovLnHU2wfSiDD7qOjhyznL/VlAkKRq60aFK9w4r0qWW5L/infNDoDfvg== xxxx@vxr-slurm-146.xxxx.com
----------------------------------------
Router#
To view the host certificates on the router, use the show ssh server host-certs command.
Router# show ssh server host-certs
Wed May 1 13:56:21.596 UTC
----------------------------------------
Type : ecdsa-sha2-nistp521-cert
Data : ecdsa-sha2-nistp521-cert-v01@openssh.com AAAAKGVjZHNhLXNoYTItbmlzdHA1MjEt
Y2VydC12MDFAb3BlbnNzaC5jb20AAAAgKjWh4uPFNKIr4uZV5maPUoOfyys/ncTyMpBbQZX+7KMAAAAI
bmlzdHA1MjEAAACFBABjiqUtIXeBAfOsur6xhCaX0865nf6Gp0gIQC/DzBNC1AJTtqZfQl4FMHPTk
ixAsHZ/7OVSh70tMgk4VzCHH+EmpAB5zIrz7fSzJFXSs9DJqw75DxtOsjb/mcovLnHU2wfSiDD7qOjhyznL/
VlAkKRq60aFK9w4r0qWW5L/infNDoDfvgAAAAAAAAAAAAAAAgAAAAVjaXNjbwAAAAAAAAAAZdQxHgAAAAB
n1loeAAAAAAAAAAAAAAAAAAABFwAAAAdzc2gtcnNhAAAAAwEAAQAAAQEA26xFTM/0hzlcDKmg6q17s8lk+
UqOqEm6FUytpKw/aPd4cBFNxGWO5BaiTQjTWSDLik9+rxmBF+vpBh4fScT64WDFHUx0OX9URaDl4cyK21
z1KUP7L607ypurZDqmsLuNHYH+nQgwCBJKQzd6/Ph2iuYxY5xhDCG8FzSrxyoMltHrL7gCey9fdO8+Jl
dTMADqp8SCvJjJcKuj0GJ68ut3pII4j0xZCTIMvQQ6ZmWSJgemN7xJLMUN4ZzJjGT1olDkq5kMEVP8pOk8
ylIQkOyRcmuNlBW126D/W58dYXdY5z/OcYWZTBQ1SSIE+Lwbt0RktJfVqrYn1aNq/f38KDyYVQAAARQAAAAM
cnNhLXNoYTItNTEyAAABAIc35ctjmPfOb3RRc3bD9gvHRzKzIO5mGbHxeH06qrNFyDxjPx/A02QydllRU1qjeH/
REAi38/RhUInEj75Iwi+f349xZx0bGacULZHMJWPYy2cGgx3e4WLF43Z3Zu09xSNzVCcUea71d21JhJGUAMWGl
ak86RLbOBvAESyYCCUG+jdNDBq7dfiaeJ05DvY33RRszfEf/4Cy6X8GYzyB/V0bmjrCllUkb56JNscNYweWCB
je2da5BwqxSbQUaLkD97Lad1Jjjeo8A/qrXMWVm71e9AAm1htKtlUusqEAwW1KmeZ4rbUkyTOJ3NaxdW/gEs4
uuAh58oweCaZyasv3ay0= lavms@vxr-slurm-146.cisco.com
Type : ecdsa-sha2-nistp256-cert
Data : ecdsa-sha2-nistp256-cert-v01@openssh.com AAAAKGVjZHNhLXNoYTItbmlzdHAyNTYtY2Vyd
C12MDFAb3BlbnNzaC5jb20AAAAgQDMsG2AcMkoXfaK9SGTtyuJ65sd0GuR7037ikt6Yo9IAAAAIbmlzdHAyNTYAAABBBA9
mwnz5O1+oV5m6Zdo3Mqmc6IjkxrCbt+E/vhK67/B8mEaGEO5JfFcJ7zHp905HsiLm0mYijS4zQCZNYRMcvNk
AAAAAAAAAAAAAAAIAAAAFY2lzY28AAAAJAAAABWNpc2NvAAAAAAAAAAD//////////wAAAAAAAAAAAAAAAAAAAZ
cAAAAHc3NoLXJzYQAAAAMBAAEAAAGBAOiOhEHzx1mQXR84w/IoKLOSfq/XI0aFqHdQ4ysQu3nTxiQeqRJtdVSslQM2OZF+
iExpMl4ElZ9Y1pO1BbrMynRhSywx+vtfypBIONfqI/z+jj3uea9i8tf7XF43llt1zE/SuwG9koUb+UI/MhSjL4AUefc9
u4qqY1+OVjKvZe4OfSzQglbNAQWHzhngs1pTjEeYAM5w3zvlDN4SJkPaA41/cRYLj29LJOMhD8NuATfpKxjU55Ja/
cISsfQdQrsTXl+2cFl3vnVYL6JIqjBR9vX36fuKurlZLFx95y7D7lRAb0Nh8D1kbqM8H94LLOd850XfDC/ygOjthkh
MrKipBwX9NnHOE3pwXR7RLaVXNqso04rQCJJmltiQ6ujTfGbtBhvxh+v+uTGhIIcsnJ3ZPIjrsI4KoqaIWPsOkhHbzq
JGcMlJcs6DqfkTl6P/AUOCgo2ssUwaXIrG6sn9plipd27Pq0JvTrIcPdNce0hpr9jAWNpx9UGHeGGFXdXKWqSQh
wAAAZQAAAAMcnNhLXNoYTItNTEyAAABgLXLFmLOFZUUO1hb/c10F8NEe95I865wZ1GKPgF08so5B0yeufjcHuAGkVCC
aO6IYW6jmnfROF48kgmZO3Ri83fIs0McNk9Q0/zb6t2AcWGI/cZtzM2WxQJ0C9SZsIXMGvAK+JnG2CG8Ca7Pa25hCLyhm
Rt22ysGKyCAws1buFI+1AAhnIgoUkBpUiA9kwIBtZPT9dn5vezcmYfJfTgsa/X7mnSm6sfvrFprz6R4Zv6AtRqi6GkWA
g47UXPmo7lAjsIBgzryN1VpHm0uveWAIZu6zOLCCTiKTfqcitaIEbV0aZ5e0g72uB7T6RLhvyhwWaiZ3hqfgAiFqiTzO
omScKzM5+XTOwgW4stT5n8PqTxYXH3okHAlNH29ne8JcnFm9hxWgK8Ru9YxfTRqDO9sb2Z5XtSZEuBr9bUCLfmez4ZeY
ptRxm5tXYMhAevqrRovtMcRMyOsZCLqYANwEh+6n0J/xgkoHFEFY2G0W0gc+a9/Ag1QoQvqyDocYa42N9NLEg==
xxxxx@vxr-slurm-146.cisco.com
Type : ed25519-cert
Data : ssh-ed25519-cert-v01@openssh.com AAAAIHNzaC1lZDI1NTE5LWNlcnQtdjAxQG9wZW5zc2guY29t
AAAAIAHRCCkOCw1xUoTS9LsmH05SeyxMo1xYumXSaHygo9fFAAAAILMXlhKk4HixCE/HGwKGkbGwgLAT7ecm0fze7ZsQQIJ
wAAAAAAAAAAAAAAACAAAABWNpc2NvAAAAAAAAAABl1DE2AAAAAGfWWjYAAAAAAAAAAAAAAAAAAAEXAAAAB3NzaC1yc2
EAAAADAQABAAABAQDbrEVMz/SHOVwMqaDqrXuzyWT5So6oSboVTK2krD9o93hwEU3EZY7kFqJNCNNZIMuKT36vGYEX6+
kGHh9JxPrhYMUdTHQ5f1RFoOXhzIrbXPUpQ/svrTvKm6tkOqawu40dgf6dCDAIEkpDN3r8+HaK5jFjnGEMIbwXNKvHKgyW0
esvuAJ7L1907z4mV1MwAOqnxIK8mMlwq6PQYnry63ekgjiPTFkJMgy9BDpmZZImB6Y3vEksxQ3hnMmMZPWiUOSrmQwRU/
yk6TzKUhCQ7JFya42UFbXboP9bnx1hd1jnP85xhZlMFDVJIgT4vBu3RGS0l9WqtifVo2r9/fwoPJhVAAABFAAAAAxyc
2Etc2hhMi01MTIAAAEAFZeqNRf3YT9K+/Zqkh17fnh+TIT2GYPktlVmyZ364EQ9igkKeOTuvqg/TNCt3BBsdRMAPShxOWr+
qcvkU+Amk3u5oP3TbWKvqMA91T3t/ZP3Mo+C+7ONe2zcvC9Rj2JgMn0tcVFI464vNEnyqUcs2AAs/hppiCwdyXbm4kQKxkax
IukonW7E9PuBkV939L4K1VTvEn4S0nTRVPX0tFXO73dIW+BhjDec9NSE/+tJY0SsuvqlL80QV73K/gHv6cJ2QaNinMSBg84Eu/
SghQJO+092ocZSWQe4MiEg4Cgz/KjJhg4I4yyLbBNaL76aAt7k4VThl83QZFLDMU1a4UuT5g==xxxxx@vxr-slurm-146.cisco.com
To view the certificate authority keys on the router, use the show ssh server ca-keys command.
Router# show ssh server ca-keys
Wed May 1 15:06:21.094 UTC
----------------------------------------
ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC83fcxKGF2i5umMS5Xc74mUxfRIMJLkawJk/BzRc1t+
/lEbD8G+eIMrwRTZ5c60mI/B0Cy1hzgAKKW5KXouBPDEVyIn3BBmYlqzHzenj1RXZYmUlS0lqcB2K2jFL7qzS9+Q+vv3l
+fHvDRMWW5sJnsdPatdY8X1ZOdNlUqwa6C/WcQ4b2FkEp4FctmrJfXv8lMbe+KqiPA1+fjXWH7douS7FDUj2bNEt
f35gcxcDptbLS8oCGvJ4fQCB9kkGpKBe20a+WUkwsoRhDz5Y2e4PUfWFV5AsgbegZmnPrXkqGb7KMf2L1uJgcyxZT+
HZilvSY5gP7FawbkEYTOmgWJEv3f sabgupta@bgl-ads-4100
----------------------------------------
Router#
To view the authorized keys for a user on the router, use the server authorized-keys user command.
Router# show ssh server authorized-keys user user1
Wed May 1 14:29:48.644 UTC
----------------------------------------
pty ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC83fcxKGF2i5umMS5Xc74mUxfRIMJLkawJk/BzRc1t+/lEbD8G+eIMrwRTZ5c60mI/
B0Cy1hzgAKKW5KXouBPDEVyIn3BBmYlqzHzenj1RXZYmUlS0lqcB2K2jFL7qzS9+Q+vv3l+fHvDRMWW5sJnsdPatdY8X1ZOdNlUqwa6C/
WcQ4b2FkEp4FctmrJfXv8lMbe+KqiPA1+fjXWH7douS7FDUj2bNEtf35gcxcDptbLS8oCGvJ4fQCB9kkGpKBe20a+WUkwsoRhDz5Y2e4P
UfWFV5AsgbegZmnPrXkqGb7KMf2L1uJgcyxZT+HZilvSY5gP7FawbkEYTOmgWJEv3f rsavalue
from="192.0.2.1,192.0.2.22,192.0.2.33" ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC83fcxKGF2i5um
MS5Xc74mUxfRIMJLkawJk/BzRc1t+/lEbD8G+eIMrwRTZ5c60mI/B0Cy1hzgAKKW5KXouBPDEVyIn3BBmYlqzHzenj1RXZYmUlS0lqcB2
K2jFL7qzS9+Q+vv3l+fHvDRMWW5sJnsdPatdY8X1ZOdNlUqwa6C/WcQ4b2FkEp4FctmrJfXv8lMbe+KqiPA1+fjXWH7douS7FDUj2bNEtf
35gcxcDptbLS8oCGvJ4fQCB9kkGpKBe20a+WUkwsoRhDz5Y2e4PUfWFV5AsgbegZmnPrXkqGb7KMf2L1uJgcyxZT+HZilvSY5gP7FawbkEYTOmgWJEv3f rsavalue
expiry-time="20241001" ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC83fcxKGF2i5umMS5Xc74mUxfRIMJLkawJk/BzRc1t+/
lEbD8G+eIMrwRTZ5c60mI/B0Cy1hzgAKKW5KXouBPDEVyIn3BBmYlqzHzenj1RXZYmUlS0lqcB2K2jFL7qzS9+Q+vv3l+fHvDRMWW5sJnsdPatdY8X1ZOdNlUqwa6C/
WcQ4b2FkEp4FctmrJfXv8lMbe+KqiPA1+fjXWH7douS7FDUj2bNEtf35gcxcDptbLS8oCGvJ4fQCB9kkGpKBe20a+WUkwsoRhDz5Y2e4PUfWFV5Asgbeg
ZmnPrXkqGb7KMf2L1uJgcyxZT+HZilvSY5gP7FawbkEYTOmgWJEv3f rsavalue
expiry-time="20241001" ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC83fcxKGF2i5umMS5Xc74mUxfRIMJLkawJk/BzRc1t+/
lEbD8G+eIMrwRTZ5c60mI/B0Cy1hzgAKKW5KXouBPDEVyIn3BBmYlqzHzenj1RXZYmUlS0lqcB2K2jFL7qzS9+Q+vv3l+f
HvDRMWW5sJnsdPatdY8X1ZOdNlUqwa6C/WcQ4b2FkEp4FctmrJfXv8lMbe+KqiPA1+fjXWH7douS7FDUj2bNEtf35gcxcDptbLS8oCGvJ4fQCB9kkGpKBe20a+
WUkwsoRhDz5Y2e4PUfWFV5AsgbegZmnPrXkqGb7KMf2L1uJgcyxZT+HZilvSY5gP7FawbkEYTOmgWJEv3f rsavalue
from="abcd" ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC83fcxKGF2i5umMS5Xc74mUxfRIMJLkawJk/BzRc1t+/lEbD8G+eIMrwRTZ5c60mI/
B0Cy1hzgAKKW5KXouBPDEVyIn3BBmYlqzHzenj1RXZYmUlS0lqcB2K2jFL7qzS9+Q+vv3l+fHvDRMWW5sJnsdPatdY8X1ZOdNlUqwa6C/
WcQ4b2FkEp4FctmrJfXv8lMbe+KqiPA1+fjXWH7douS7FDUj2bNEtf35gcxcDptbLS8oCGvJ4fQCB9kkGpKBe20a+WUkwsoRhDz5Y2e4PUfWFV5AsgbegZmn
PrXkqGb7KMf2L1uJgcyxZT+HZilvSY5gP7FawbkEYTOmgWJEv3f rsavalue
----------------------------------------
To view the list of principals (identities) that are authorized for SSH access, use the show ssh server authorized-principals user command.
Router# show ssh server authorized-principals user user1
Wed May 1 14:37:37.933 UTC
----------------------------------------
pty cisco
from="192.0.2.1,192.0.2.22,192.0.2.32" lab
expiry-time="20241001" one
----------------------------------------