SSH Configuration in Cisco 3700 and 2960 switches

Dear All,
I have couple of Cisco switches i need to allow some particular ip address for accessing switches through SSH
below is the user ip address details , Kindly help me for a configuring SSH in below listed ip address
user ip address
==========
172.188.50.7
172.188.51.7
172.188.7.222
172.188.100.7
172.188.101.7
172.16.2.222
172.16.1.6
Switch ip address
=============
1. 172.16.9.1
2. 172.16.9.2
3. 172.16.9.3
4. 172.16.9.4
Waiting for the reply 
Regards
Muhammed

Please refer this doc for configuring ssh .
http://www.cisco.com/c/en/us/support/docs/security-vpn/secure-shell-ssh/4145-ssh.html
Define these ip address in a access-list and call that access-class into  line vty .
Regards
PrajithTR

Similar Messages

  • How i can calculate the backplane speed & throughput of cisco 48 1G 2960S switch?

    How i can calculate the backplane speed & throughput of cisco 48 1G 2960S switch?

    Disclaimer
    The  Author of this posting offers the information contained within this  posting without consideration and with the reader's understanding that  there's no implied or expressed suitability or fitness for any purpose.  Information provided is for informational purposes only and should not  be construed as rendering professional advice of any kind. Usage of this  posting's information is solely at reader's own risk.
    Liability Disclaimer
    In  no event shall Author be liable for any damages whatsoever (including,  without limitation, damages for loss of use, data or profit) arising out  of the use or inability to use the posting's information even if Author  has been advised of the possibility of such damage.
    Posting
    Calculate?  Calculate for wirespeed/line-rate?  If the latter, take all the port bandwidths, and assuming they are duplex, double for necessary fabric bandwidth.  I.e. 48 gig ports would need a 96 Gbps fabric.  Take all your port bandwidths, and allow 1.448 Mpps per gig (for minimum size Ethernet packets), i.e. 48 gig ports would need 69.5 Mpps.  Once you have required fabric bandwidth and PPS, you can compare to vendor's specs.

  • 3560G and 2960 switch CPU loading

    Hi all,
    I'm using PRTG monitoring switchs performance, the core switch 3560G CPU is 75% and outsite switch 2960 CPU is 25%, is it high loading of those switch ?
    Thanks

    Hi Leo
    I have attached PRTG report and Cisco show proc memory command to you, thanks for help.
    3560G
    Processor Pool Total:   94334556 Used:   14594348 Free:   79740208
          I/O Pool Total:    8380416 Used:    3587708 Free:    4792708
    Driver te Pool Total:    1048576 Used:         40 Free:    1048536
    2960
    Processor Pool Total:   34988900 Used:    8256776 Free:   26732124
          I/O Pool Total:    4186112 Used:    1641672 Free:    2544440
    Driver te Pool Total:    1048576 Used:         40 Free:    1048536

  • The difference of the IEEE802.1x Auth between Cisco Routers and Catalyst switches

    Hello
    I am investigating the difference of the IEEE802.1x Auth between Routers and Switches.
    Basically dot1x auth is availlable on Catalyst Switches. however if I want to check to
    PortBased Multi-Auth , MAC address Auth and any certification Auth with this feature,
    Is it possible to integrate into Cisco Router such as Cisco 891F ?
    In my opinion Cisco891F is also available to use basic IEEE802.1x but if it compares with Catalyst switches such as Cat3560X
    I think there might be any unsupported feature on Cisco 891F.
    I appreciate any information. thank you very much in advance.
    Best Regards,
    Masanobu Hiyoshi

    Many time in interviews asked comaprison between cisco  routers and switches that i was answerless bcoz i dont have much knowledge about that.Can anyone provide me the compariosin sheet of the same.how are the cisco devices differ with each other how much Bandwidth each routres support and Etc...
    Ummmm ... The most common question I get is "what is the difference between a router and a switch".
    However, if you get a question like this, then my impression to this line of questioning are:
    1.  The candidate they are looking for has in-depth knowledge of routers and switches.  And I mean IN-DEPTH!;
    2.  They are not looking for a candidate.  They just want to stroke their ego.  There is not alot of people who can give you the "names and numbers" of routers and switches at a snap of a finger.  And if you do happen to know the answer, then and there, then expect a tougher follow-up question. 

  • How to erase all configuration in Cisco ESW 500 Series Switches

    Hi anybody,
    Anyone show me how to erase or remove  configuration file from ESW 500 Series Switches?
    Thanks
    Thuc

    Hi Thuc,
    The restart / reset function will allow for local or remote reset of the  the unit to Factory defaults, see screen capture below. ;
    Alternatively, the Switch can be reset by inserting a paper clip into the RESET opening on the friont of the switch.
    Pressing the manual reset for 0 to 10 seconds only  reboots the switch.
    Pressing the manual reset for longer than 10 seconds results in the switch being reset to factory defaults.
    does this answer your question, not exactly sure it does ?
    regards Dave

  • Buffer Misses on Cisco 2970 and 2950 switches

    Hi,
    I am seeing a lot of big buffer misses, some small buffer misses and medium buffer misses on our 2970 and 2950 switches. I'm seeing this on most of our switches (about 10 of them). I've searched the forum and docs and only found info relating to routers. Anybody know what these errors mean and how to troubleshoot them for switches? Thanks in advance.

    One common reason for this in 2950 switches is due to flooded traffic. Plug in a sniffer in promiscous mode and check for any broadcast/multicast/unknown unicast flooded traffic.

  • Cisco Cat. 2960 switch to SF 302-08MP

    I am trying to get the VLANS in our company network to work in the SF-302 switch. I set a port in the 2960 to "switchport mode trunk"
    and cannot get any vlans except default vlan 1 to work in the SF-302. I understand that VTP is not available in the 302 but if VTP is set to transparent mode in the 2960.. is there not a way to make the 302 usuable with all the other vlans? It has the latest firmware 1.2.9.44.
    Should I turn on GVRP in the SF-302 or will that cause grief with my other Cisco VTP switches?

    Hi Tim, you need to configure each vlan to the port of the SF300- example
    config t
    vlan database
    vlan 2-5
    interface fa01
    switchport mode trunk
    switchport trunk native vlan 1
    switchport trunk allowed vlan add 2-5
    This will allow all vlan on the SF300 to trunk to the 2960. Of course this is just an example. If you need specifics, let me know.
    -Tom
    Please mark answered for helpful posts

  • Vlan routing with cisco router and linksys switch

    I have a linksys switch width vlan configured, connected to a Cisco router (1841), but I cant route between vlan’s.
    Please help me!!
    It Works with a Cisco switch perfectly(with the same ip and vlan).

    Yes. the linksys switch (SRW2024 24-Port 10/100/1000 Gigabit Switch) supports trunking.
    If you want you can visit the link and see that the switch supports vlan, dot1q and trunking.
    http://www.linksys.com/servlet/Satellite?childpagename=US%2FLayout&packedargs=c%3DL_Product_C2%26cid%3D1123638180432&pagename=Linksys%2FCommon%2FVisitorWrapper

  • How often should the Cisco 6509 and 3750 switches be rebooted? Does Cisco have a best practice recommendation?

    How often should the 6509's and 3750's switches be rebooted?
    Does Cisco have a best practice document on this and recommendation how long the switch should be up before it gets rebooted?
    Why is a reboot needed if there are no indications of issues on the log?

    I'd agree with Larry here.
    If you're not seeing any issues with your IOS revision and there are no relevant PSIRTs (security notices applicalble to features and or exposure of your device requiring an IOS upgrade) then you can go a very long time without rebooting, if ever.
    I'm sure it's far from a record, but our corporate distribution router that supports >1000 downstream devices day in and day out has never been rebooted since installation just over 5 years ago. I have a top of rack Layer 2 switch (2900 series running CatOS) that's almost at 10 years.
    That said, you should have some monitoring scheme that assures you everything is healthy. But as long as memory and cpu are happy, the device will run forever.

  • Cisco WAAS and Content Switching Module compatiblity

    We are planning to implement WAAS on our hub's 6500 core switches, so that TCP connections from the end sites users to the servers in the hub can be optimized. But we have the servers VLAN groups under the Cisco CSM module already. Are the client-server connections still able to be optimized by WAAS?

    Hi Joe
    let's seperate out the two topics here.
    a) WAAS traffic interception with wccp
    b) CSM
    a) when you say vlan 200 is where target servers are connected, is that the CSM client side vlan? or the actual server vlan ?
    the bottom line is you need to make sure the interface where you configure "ip wccp 61 redirect in" is recieving traffic from servers towards .
    Good reference for WCCP best practices in 6500
    http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps708/white_paper_c11-629052.html
    b) yes you can configure stickiness for session persistance as in below URL
    http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/csm/4.2.x/configuration/guide/addftrs.html
    Thanks

  • ISDN dial-in with Cisco 1721 and WIC-1B-S/T

    Hi there,
    we use a Cisco 1721 with a WIC-1B-S/T interface for ISDN backup purposes. I configured the Cisco 1721 and connected the BRI-WIC to a ISDN channel. When I try to test the ISDN connection, I always get the error that the line protocol is down. The WIC is connected to the ISDN correctly. I do not understand why the line protocol is always down. Could anybody help? The chosen encapsulation is PPP, the ISDN Switch Type is basic-1tr6 (I think thats the right one for Germany). The IOS version is 12.4 (1c).
    Regards, J. Schroeder

    Hi there,
    the BRI interface is connected to a telephone system and not directly to a NTBA. The hostname matches the username, is this right? When I try to dial out, I get this messages:
    *Mar 9 16:28:11.804: ISDN BR0 **ERROR**: host_disconnect_ack: Unfound B-channel on Disconnect_Ack call id 0x8003
    *Mar 9 16:28:33.792: ISDN BR0 **ERROR**: CCBRI_Go: NO CCB Src->HOST call id 0x8003, event 0x5 ces 1
    *Mar 9 16:29:47.324: ISDN BR0 **ERROR**: host_disconnect_ack: Unfound B-channel on Disconnect_Ack call id 0x8004
    *Mar 9 16:30:09.312: ISDN BR0 **ERROR**: CCBRI_Go: NO CCB Src->HOST call id 0x8004, event 0x5 ces 1
    *Mar 9 16:30:12.952: ISDN BR0 **ERROR**: host_disconnect_ack: Unfound B-channel on Disconnect_Ack call id 0x8005
    *Mar 9 16:30:34.940: ISDN BR0 **ERROR**: CCBRI_Go: NO CCB Src->HOST call id 0x8005, event 0x5 ces 1

  • How to configure a cisco 2960 switch to support two routers(data and voice), please give me any suggestions

    HI, I need to configure a 2960 switch at a client site. They have routers already been installed on site, one is for data traffic another is for voice. I have created two vlans on switch  for data and voice. Now I couldn't get any idea what would be the default gateway on switch. 
    Please give me any suggestions.

    HI Leo, 
                Many thanks for your reply.
             But there are two up-links going from Gi 0/1 and Gi 0/2. I have configured the S/W like below, 
    interface GigabitEthernet0/1
    description UPLINK TO Data router
    switchport access vlan 100
     switchport mode access
    interface GigabitEthernet0/2
    description UPLINK TO voice router
    switchport access vlan 100
     switchport mode access
    interface Vlan1
     no ip address
     no ip route-cache
     shutdown
    interface Vlan60
     ip address 192.168.1.253 255.255.255.0
     ip helper address 192.168.1.1
     no ip route-cache
    interface Vlan100
     ip address 172.16.1.253 255.255.255.0
     ip helper address 172.16.1.1
     no ip route-cache
     I have used IP helper address, but I am getting some connecting issues on PCs and IP phones. Please suggest me, Can I manage it with two uplinks with different IP addresses. 
    Thanks in advance.

  • How to priorities(QoS) the traffic for DSCP 46 and 34 in cisco 2960s switch

    HI,
    We are going to implement Microsoft Lyncs 2013 in our network, so how to priorities the traffic for DSCP 46 and 34 in cisco 2960s switch. Kindly replay with detailed QoS commands for enabling QOs in LAN.
    Thanks
    Sujish

    Hi,
    Have a look at this config guide for all the details:
    http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst2960/software/release/12-2_53_se/configuration/guide/2960scg/swqos.html
    HTH

  • Cisco 3700 Switch Secuirty Assessment

    Hello,
    I am in the process of scanning our network for vulnerabilities. In the process I came across our Core switch, Cisco 3700 with a physical stack, with some vulnerabilities. I would like your help on mitigating these risks and any possible road bloks I may encounter. Attached is the actual summary.
    1. SSH Protocol Version 1 Supported
    2. Management Interfaces Accessible on Cisco Device Vulnerabilitiy
    3. SSH Weak Cipher used
    4. UDP Contant IP Identifiaction Field Fingerprinting
    5. NTP Information Disclosure
    Any step in the righ direction would be most beneficial and very much appreciated.

    Cost is always a factor in any decision but the headline costs of the switches is only part of the consideration.
    When you are faced with a cost comparison between switch A and switch B from different vendors it is important to look past the upfront costs and factor in the support costs as well. If your current infrastructure is Cisco then you have people with Cisco skills and this is an important factor.
    You are the one that is going to have manage these switches not the consultant.
    I have worked on large networks and from previous experience if we had always gone with the cheapest option we would have ended up with a lot of different vendor switches, each needing to be supported which would mean people having skills in that vendor.
    And each having a different management platform etc.
    In addition, as Leo mentions, with multiple vendors you often find them passing the buck between each other when there is a problem with your network.
    That doesn't mean you have to buy everything from one vendor because there are times when a certain vendor's equipment has functionality that others don't and then the decision is fairly straightforward.
    But what it does mean is if you have standardised on one vendor then you need a good reason to use another especially in something as important as your base infrastructure and upfront cost alone, although important, should not be the only factor in the decision.
    I have never used AT switches so I can't so anything about them but one thing I would say in terms of support is that Cisco does really well in this regard not just with technical documentation but also with forums like these.
    I am not trying to talk you into buying Cisco, that's not what these forums are for, but in the end based on what you need the switches for there may not be a good technical reason that points to one vendor or the other, so it will come down to other factors.
    Jon

  • How to connet cisco 2960S switch to sony nexus 7?

    I want to buy an cisco WS-C2960S-24TS-S switch to help me solve business networking problem. Can someone help me to connect cisco 2960s switch to nexus 7 ?

    I don't need to do anything config on the new switch, I just need to upgrade the new switch's IOS version as the existing stack.
    Correct.  Upgrade using the command "archive download-sw" instead copying the BIN files.  
    After doing above task, I connect all stack cable and power cord as you said, and then the new switch can be synchronized with the MASTER switch. right??
    Correct.  The new switch should NOT have any configuration.  This includes VLAN.dat file.

Maybe you are looking for