| Follow me on:

PDF    Send article as PDF to

Cisco banners with SSH

July 31st, 2009

When configuring a Cisco device I always configure some kind of banner, which is displayed when logging in. This banner contains some information, like security warnings and general information. There are different kind of banners.

  • exec: display a banner before displaying the enable prompt;
  • login: display a banner before the password login prompt when accessing the security appliance using Telnet;
  • motd: display a message-of-the-day banner when you first connect;

I was used to configuring a banner login with different variables, like shown below:

banner login ^
You have entered device $(hostname).$(domain) at line $(line) $(line-desc)
^C

This works fine when connecting with Telnet to the device, but this doesn’t work when using SSH. For security reason, I always use SSH to connect to devices, but I didn’t notice the “corrupt” banner since recently.

Banner login doesn’t support SSH:

“When accessing the security appliance through Telnet or SSH, the session closes if there is not enough system memory available to process the banner messages or if a TCP write error occurs. Only the exec and motd banners support access to the security appliance through SSH. The login banner does not support SSH.”

The example below shows the output from a banner motd and a banner login when connecting via SSH.

ssh -l admin 10.10.66.12

You have entered device $(hostname).$(domain) at line $(line) $(line-desc)

Password:

You have entered device C877.booches.nl at line 1
C877#

The first banner is de banner login and the second is the banner motd. So when using SSH to connect to a device, it is better to use a banner motd or a banner exec.

Related Articles

Leave a Reply

  • my Tweetz

    • Going to install new PacketShaper licenses in an hour. The installation steps from BlueCoat are very clear... hope the installation is too 2 days ago
    • Just met some former class mates from 15 years ago. It's funny to hear what everbody is doing nowadays 3 days ago
    • Mysteryland is over. We had a great time. We saw great dj's and herad some good sets. And only 2 drops of rain!!! 5 days ago
    • We arrived at Mysteryland. The party can begin http://moby.to/22oq2q 5 days ago
    • Online mysteryland in de zwembroek ciao 6 days ago
    • More updates...

    Powered by Twitter Tools

  • Advertisements