GNS3模拟Cisco C7200路由器SSH权限拒绝问题求助
GNS3模拟Cisco C7200路由器SSH权限拒绝问题求助
我现在遇到一个棘手的问题,想请各位帮忙排查:我的目标是通过GNS3模拟Cisco C7200路由器,后续能从Python应用SSH到设备并获取命令输出,但目前连手动从终端SSH到路由器都失败了,一直提示权限拒绝。
环境与配置详情
- 系统:Manjaro Linux
- 模拟工具:GNS3
- 设备镜像:Cisco C7200
路由器的配置如下(已进入全局配置模式执行):
conf t username admin privilege 15 password 1234 hostname R1 ip domain-name local crypto key generate rsa ip ssh version 2 line vty 0 4 transport input ssh login local exit interface fa0/0 ip address 192.168.12.1 255.255.255.0 no shut end
我把路由器Fa0/0接口设置成和WiFi适配器同网段的IP,目前能正常ping通:
$ ping 192.168.12.1 PING 192.168.12.1 (192.168.12.1) 56(84) bytes of data. 64 bytes from 192.168.12.1: icmp_seq=1 ttl=64 time=3.11 ms 64 bytes from 192.168.12.1: icmp_seq=2 ttl=64 time=3.72 ms
问题现象
但尝试SSH连接时,输入正确密码后一直提示权限拒绝:
$ ssh admin@192.168.12.1 admin@192.168.12.1's password: Permission denied, please try again. admin@192.168.12.1's password: Permission denied, please try again. admin@192.168.12.1's password: admin@192.168.12.1: Permission denied (publickey,password).
SSH verbose模式的输出如下:
OpenSSH_9.5p1, OpenSSL 3.1.4 24 Oct 2023 debug1: Reading configuration data /etc/ssh/ssh_config debug1: /etc/ssh/ssh_config line 2: include /etc/ssh/ssh_config.d/*.conf matched no files debug1: Connecting to 192.168.12.1 [192.168.12.1] port 22. debug1: Connection established. debug1: identity file /home/gabriel/.ssh/id_rsa type 0 debug1: identity file /home/gabriel/.ssh/id_rsa-cert type -1 debug1: identity file /home/gabriel/.ssh/id_ecdsa type -1 debug1: identity file /home/gabriel/.ssh/id_ecdsa-cert type -1 debug1: identity file /home/gabriel/.ssh/id_ecdsa_sk type -1 debug1: identity file /home/gabriel/.ssh/id_ecdsa_sk-cert type -1 debug1: identity file /home/gabriel/.ssh/id_ed25519 type 3 debug1: identity file /home/gabriel/.ssh/id_ed25519-cert type -1 debug1: identity file /home/gabriel/.ssh/id_ed25519_sk type -1 debug1: identity file /home/gabriel/.ssh/id_ed25519_sk-cert type -1 debug1: identity file /home/gabriel/.ssh/id_xmss type -1 debug1: identity file /home/gabriel/.ssh/id_xmss-cert type -1 debug1: identity file /home/gabriel/.ssh/id_dsa type -1 debug1: identity file /home/gabriel/.ssh/id_dsa-cert type -1 debug1: Local version string SSH-2.0-OpenSSH_9.5 debug1: Remote protocol version 2.0, remote software version dropbear_2012.55 debug1: compat_banner: no match: dropbear_2012.55 debug1: Authenticating to 192.168.12.1:22 as 'admin' debug1: load_hostkeys: fopen /home/gabriel/.ssh/known_hosts2: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory debug1: SSH2_MSG_KEXINIT sent debug1: SSH2_MSG_KEXINIT received debug1: kex: algorithm: diffie-hellman-group1-sha1 debug1: kex: host key algorithm: ssh-rsa debug1: kex: server->client cipher: aes128-ctr MAC: hmac-sha1 compression: none debug1: kex: client->server cipher: aes128-ctr MAC: hmac-sha1 compression: none debug1: expecting SSH2_MSG_KEX_ECDH_REPLY debug1: SSH2_MSG_KEX_ECDH_REPLY received debug1: Server host key: (redacted) debug1: load_hostkeys: fopen /home/gabriel/.ssh/known_hosts2: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts: No such file or directory debug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory debug1: Host '192.168.12.1' is known and matches the RSA host key. debug1: Found key in /home/gabriel/.ssh/known_hosts:4 debug1: rekey out after 4294967296 blocks debug1: SSH2_MSG_NEWKEYS sent debug1: expecting SSH2_MSG_NEWKEYS debug1: SSH2_MSG_NEWKEYS received debug1: rekey in after 4294967296 blocks debug1: get_agent_identities: bound agent to hostkey debug1: get_agent_identities: agent returned 2 keys debug1: Will attempt key: /home/gabriel/.ssh/id_ed25519 ED25519 (redacted) agent debug1: Will attempt key: /home/gabriel/.ssh/id_rsa RSA (redacted) agent debug1: Will attempt key: /home/gabriel/.ssh/id_ecdsa debug1: Will attempt key: /home/gabriel/.ssh/id_ecdsa_sk debug1: Will attempt key: /home/gabriel/.ssh/id_ed25519_sk debug1: Will attempt key: /home/gabriel/.ssh/id_xmss debug1: Will attempt key: /home/gabriel/.ssh/id_dsa debug1: SSH2_MSG_SERVICE_ACCEPT received debug1: Authentications that can continue: publickey,password debug1: Next authentication method: publickey debug1: Offering public key: /home/gabriel/.ssh/id_ed25519 ED25519 (redacted) agent debug1: Authentications that can continue: publickey,password debug1: Offering public key: /home/gabriel/.ssh/id_rsa RSA (redacted) agent debug1: Authentications that can continue: publickey,password debug1: Trying private key: /home/gabriel/.ssh/id_ecdsa debug1: Trying private key: /home/gabriel/.ssh/id_ecdsa_sk debug1: Trying private key: /home/gabriel/.ssh/id_ed25519_sk debug1: Trying private key: /home/gabriel/.ssh/id_xmss debug1: Trying private key: /home/gabriel/.ssh/id_dsa debug1: Next authentication method: password admin@192.168.12.1's password: debug1: Authentications that can continue: publickey,password Permission denied, please try again. admin@192.168.12.1's password: debug1: Authentications that can continue: publickey,password Permission denied, please try again. admin@192.168.12.1's password: debug1: Authentications that can continue: publickey,password debug1: No more authentication methods to try. admin@192.168.12.1: Permission denied (publickey,password).
我的/etc/ssh/ssh_config配置如下:
# Include drop-in configurations Include /etc/ssh/ssh_config.d/*.conf # This is the ssh client system-wide configuration file. See # ssh_config(5) for more information. This file provides defaults for # users, and the values can be changed in per-user configuration files # or on the command line. # Configuration data is parsed as follows: # 1. command line options # 2. user-specific file # 3. system-wide file # Any configuration value is only changed the first time it is set. # Thus, host-specific definitions should be at the beginning of the # configuration file, and defaults at the end. # Site-wide defaults for some commonly used options. For a comprehensive # list of available options, their meanings and defaults, please see the # ssh_config(5) man page. # Host * # ForwardAgent no # ForwardX11 no # PasswordAuthentication yes # HostbasedAuthentication no # GSSAPIAuthentication no # GSSAPIDelegateCredentials no # BatchMode no # CheckHostIP no # AddressFamily any # ConnectTimeout 0 # StrictHostKeyChecking ask # IdentityFile ~/.ssh/id_rsa # IdentityFile ~/.ssh/id_dsa # IdentityFile ~/.ssh/id_ecdsa # IdentityFile ~/.ssh/id_ed25519 # Port 22 # Ciphers aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,3des-cbc # MACs hmac-md5,hmac-sha1,umac-64@openssh.com # EscapeChar ~ # Tunnel no # TunnelDevice any:any # PermitLocalCommand no # VisualHostKey no # ProxyCommand ssh -q -W %h:%p gateway.example.com # RekeyLimit 1G 1h # UserKnownHostsFile ~/.ssh/known_hosts.d/%k KexAlgorithms +diffie-hellman-group1-sha1,diffie-hellman-group14-sha1 PubkeyAcceptedAlgorithms +ssh-rsa HostKeyAlgorithms +ssh-rsa # PubkeyAuthentication yes
已尝试的排查动作
- 重新在路由器内生成RSA密钥
- 尝试不强制使用SSH版本2
但以上操作都没能解决问题,想请教各位我哪里配置错了?
排查建议
我仔细梳理了你的配置和日志,给你几个具体的排查方向:
- 确认路由器用户配置生效:在路由器上执行
show running-config | include username,检查输出里是否存在username admin privilege 15(密码会加密显示,只要用户名和权限正确即可);再执行show users查看是否有异常会话占用资源。 - 强制优先使用密码认证:OpenSSH默认会先尝试公钥认证,你可以直接指定用密码认证跳过公钥步骤,命令为:
ssh -o PreferredAuthentications=password admin@192.168.12.1。 - 检查VTY线路状态:执行
show line vty 0 4,确认线路的Login状态为Local,没有额外的access-class规则限制你的IP连接。 - 查看路由器SSH运行状态:执行
show ip ssh,确认SSH版本为2,密钥长度至少2048位(生成时可以用crypto key generate rsa general-keys modulus 2048指定),同时检查Authentication retries是否为默认的3次。 - 临时关闭系统防火墙:Manjaro的防火墙可能会拦截SSH连接,试试执行
sudo systemctl stop firewalld或者sudo iptables -F,之后再尝试SSH连接。 - 验证GNS3桥接设置:确认GNS3的桥接适配器确实绑定到你的WiFi网卡,没有出现IP冲突或网络隔离的情况(虽然ping通了,但桥接模式偶尔会有端口过滤问题)。
备注:内容来源于stack exchange,提问作者Gabriel
相关产品推荐
相关产品推荐

