<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ICX7150 - no available SSH session in ICX Switches</title>
    <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7150-no-available-SSH-session/m-p/31225#M1767</link>
    <description>Hi,&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Please try 8080e. It has 3 defects fixed for SSH.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Thanks&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Bill&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
    <pubDate>Wed, 24 Apr 2019 12:34:56 GMT</pubDate>
    <dc:creator>william_hadley_</dc:creator>
    <dc:date>2019-04-24T12:34:56Z</dc:date>
    <item>
      <title>ICX7150 - no available SSH session</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7150-no-available-SSH-session/m-p/31224#M1766</link>
      <description>&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Good evening to all, I would have a problem on a Ruckus ICX7150-48P-4X10GR switch installed in the company where I work, in some cases it involves connecting to ssh.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Initially we had no problem connecting to ssh, for about two weeks it has happened that trying to connect in ssh we have this error (I add stamp).&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Receiving this error is as if there were no more sessions available for the ssh connection, connecting to the console giving the "sh who" command we actually see that the ssh sessions are almost all closed and therefore available.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;The solution to this problem is to wait a few minutes (usually 10-15) to be able to connect again.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Has anyone like this happened to anyone?&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;The version mounted on the switch is&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;SW: Version 08.0.80dT211&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Thank you in advance&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Wed, 24 Apr 2019 12:25:15 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7150-no-available-SSH-session/m-p/31224#M1766</guid>
      <dc:creator>andrea_tassi</dc:creator>
      <dc:date>2019-04-24T12:25:15Z</dc:date>
    </item>
    <item>
      <title>Re: ICX7150 - no available SSH session</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7150-no-available-SSH-session/m-p/31225#M1767</link>
      <description>Hi,&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Please try 8080e. It has 3 defects fixed for SSH.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Thanks&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Bill&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Wed, 24 Apr 2019 12:34:56 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7150-no-available-SSH-session/m-p/31225#M1767</guid>
      <dc:creator>william_hadley_</dc:creator>
      <dc:date>2019-04-24T12:34:56Z</dc:date>
    </item>
    <item>
      <title>Re: ICX7150 - no available SSH session</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7150-no-available-SSH-session/m-p/31226#M1768</link>
      <description>Hi ,&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;if you copy and paste these commands you can connect via telnet&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;en&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;con t&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;telnet serv&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;wr mem&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;end&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Wed, 24 Apr 2019 13:06:45 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7150-no-available-SSH-session/m-p/31226#M1768</guid>
      <dc:creator>ryan_guerrero_6</dc:creator>
      <dc:date>2019-04-24T13:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: ICX7150 - no available SSH session</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7150-no-available-SSH-session/m-p/31227#M1769</link>
      <description>Hi&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I also found this online for enabling SSH:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;A alt="" href="http://docs.ruckuswireless.com/fastiron/08.0.80/fastiron-08080-securityguide/GUID-1D2BFDC1-B1B5-4B4D-B3BB-18B3D5BD410A.html" name="" rel="nofollow" target="" title="" type="" value=""&gt;http://docs.ruckuswireless.com/fastiron/08.0.80/fastiron-08080-securityguide/GUID-1D2BFDC1-B1B5-4B4D-B3BB-18B3D5BD410A.html&lt;/A&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Thanks,&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Ryan</description>
      <pubDate>Wed, 24 Apr 2019 13:09:01 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7150-no-available-SSH-session/m-p/31227#M1769</guid>
      <dc:creator>ryan_guerrero_6</dc:creator>
      <dc:date>2019-04-24T13:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: ICX7150 - no available SSH session</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7150-no-available-SSH-session/m-p/31228#M1770</link>
      <description>Hi - Is this ICX7150 being managed by Smartzone? Or has SZ function been enable/disable on this ICX several times since bootup? If this is true, please upgrade to 8090a. I'm suspecting that it's running into a known issue which already fixed in 8090a. Also, 8090 is our long term patch, we're recommending 8090x over 8080x&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Thanks,&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Vu&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Wed, 24 Apr 2019 13:41:15 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7150-no-available-SSH-session/m-p/31228#M1770</guid>
      <dc:creator>vu_pham_ghtztqm</dc:creator>
      <dc:date>2019-04-24T13:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: ICX7150 - no available SSH session</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7150-no-available-SSH-session/m-p/31229#M1771</link>
      <description>&lt;B alt="" name="" rel="" target="" title="" type="" value=""&gt;I wouldn't use telenet... It is not encrypted nor secure!&lt;/B&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Also if you use SMMP, I would recommend only v3 for the same reasons.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;We have been running 08.0.80 code since 08.0.80b and have not run into the SSH issue.&amp;nbsp; I would say, "good for us," but that doesn't help you.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;*knocks on wood* before I start having problems with hundreds of devices running 08.0.80d, but thus far SSH works fine in our environment every time!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;B alt="" name="" rel="" target="" title="" type="" value=""&gt;Based on the post above, if you want to disable Smartzone:&lt;/B&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;sz disable&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;B alt="" name="" rel="" target="" title="" type="" value=""&gt;Here is our SSH config:&lt;/B&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip ssh&amp;nbsp; authentication-retries 2&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip ssh&amp;nbsp; timeout 30&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip ssh&amp;nbsp; idle-time 30&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip ssh&amp;nbsp; scp disable&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip ssh&amp;nbsp; encryption disable-aes-cbc&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;B alt="" name="" rel="" target="" title="" type="" value=""&gt;We are generating an RSA with a 2048 bit modulus:&lt;/B&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;crypto key generate rsa modulus 2048&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;We are also using RADIUS for the authentication with a backup account to authenticate if RADIUS is broken:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;B alt="" name="" rel="" target="" title="" type="" value=""&gt;Our AAA looks like this:&lt;/B&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication web-server default local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication enable default radius local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication login default radius local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication login privilege-mode&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;username backupacct password .....&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;radius-server host 10.1.2.3&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;radius-server host 10.4.5.6&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;radius-server key 2 $dyIqJzYoZmlpdUldZzBzRShTOjIwXzkzJUNmME8rQjBdNE9QTG1JPVUiOidpFtGh4m2TaCU0XF44XDojb3RrZw==&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Each device is uniquely keyed though if you really want, you can create a 10.0.0.0/8 entry in RADIUS for example or whatever your switch management IPs are and key everything with one entry if that is your desire.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;B alt="" name="" rel="" target="" title="" type="" value=""&gt;If you do not run RADIUS your AAA will be something like:&lt;/B&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication web-server default local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication enable default local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication login default local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication login privilege-mode&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;B alt="" name="" rel="" target="" title="" type="" value=""&gt;Locking down by OOB or Access List(Unrelated):&lt;/B&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Forgot to mention I would lock down SSH access to either Out-of-Bound Management or an Access list.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;If you do an ACL, you want to make a simple Standard numbered or named Access list, so you are filtering simply based on the source.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;A permit allows access, a deny doesn't.&amp;nbsp; The lists are processed top down, and once it matches, execution terminates.&amp;nbsp; There is an implicit deny all at the end, so if nothing matches and returns permit, then access will be denied.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Let's say you want to allow only one device to be able to SSH:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Here would be the Standard ACL statement:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;permit host 10.1.2.3&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;You would apply it&amp;nbsp; like:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ssh access-group &lt;NUMBER or="" name=""&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Specifically:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;lt;1-99&amp;gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Standard IP access list&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; ASCII string&amp;nbsp; &amp;nbsp;Standard Access List Name&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;B&gt;﻿&lt;/B&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;/NUMBER&gt;</description>
      <pubDate>Wed, 24 Apr 2019 19:43:28 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7150-no-available-SSH-session/m-p/31229#M1771</guid>
      <dc:creator>netwizz</dc:creator>
      <dc:date>2019-04-24T19:43:28Z</dc:date>
    </item>
    <item>
      <title>Re: ICX7150 - no available SSH session</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7150-no-available-SSH-session/m-p/31230#M1772</link>
      <description>I updated the switch to 08.0.80eT211 as you suggested.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;For now it seems to have solved everything, the problem is no longer recurring.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;thanks for the help&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Andrea&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Mon, 29 Apr 2019 12:59:11 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX7150-no-available-SSH-session/m-p/31230#M1772</guid>
      <dc:creator>andrea_tassi</dc:creator>
      <dc:date>2019-04-29T12:59:11Z</dc:date>
    </item>
  </channel>
</rss>

