Ansible+NAPALM连接Juniper设备时SSH密码套件适配异常求助
故障排查方案
核心原因分析
- NAPALM底层SSH库兼容性问题:NAPALM默认可能使用
paramiko而非系统原生OpenSSH,而paramiko对OpenSSH自定义的加密套件(如aes128-gcm@openssh.com这类带@openssh.com后缀的)支持不完善,早期版本甚至不识别这类命名格式的套件。 - Ansible参数未传递到NAPALM:部分NAPALM模块不会直接继承
ansible_ssh_common_args,因为它们有独立的SSH连接逻辑,导致你设置的加密套件参数未生效。
具体排查与解决步骤
- 确认NAPALM使用的SSH库:执行Playbook时加上
-vvv参数查看详细日志,搜索paramiko或ssh关键字,判断底层用的是哪个SSH客户端。ansible-playbook -vvv your_poc_playbook.yml - 升级paramiko版本:如果日志显示用的是paramiko,升级到2.7.x及以上版本(该版本开始完善对GCM类加密套件的支持):
pip install --upgrade paramiko - 强制NAPALM使用系统OpenSSH:在inventory或Playbook中指定连接方式为原生SSH,让NAPALM调用系统ssh命令,从而继承你设置的加密参数:
在inventory文件中添加:
或者在Playbook的hosts块中设置:[juniper_devices] device1 ansible_connection=ssh ansible_ssh_common_args="-o Ciphers=aes128-gcm@openssh.com,aes256-gcm@openssh.com -o MACs=hmac-sha2-256,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-512-etm@openssh.com -o KexAlgorithms=ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521"- hosts: juniper_devices connection: ssh vars: ansible_ssh_common_args: "-o Ciphers=aes128-gcm@openssh.com,aes256-gcm@openssh.com -o MACs=hmac-sha2-256,hmac-sha2-256-etm@openssh.com,hmac-sha2-512,hmac-sha2-512-etm@openssh.com -o KexAlgorithms=ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521" tasks: # 你的NAPALM任务 - 核对设备SSH全量配置:除了ciphers,确认Juniper设备的KEX和MACs配置是否和你指定的匹配,避免单向设置导致协商失败。比如检查设备上的:
[edit system services ssh] kex-algorithms [ ... ]; macs [ ... ]; - 提取连接阶段错误日志:从
-vvv的输出中定位SSH连接协商的具体错误,比如是否出现no matching cipher found这类提示,精准定位不兼容的套件。
内容的提问来源于stack exchange,提问作者Jonathan Warren
相关产品推荐
相关产品推荐

