S2750 SSH login is slow

Latest reply: Dec 27, 2018 07:51:41 671 6 1 0

        1. First step: We need to collect some information when trying to login the switch, by using the commands below:

<Huawei>debugging ssh server all all  

<Huawei>terminal monitor

Info: Current terminal monitor is on.

<Huawei>terminal debugging

Info: Current terminal debugging is on.


        2. Second step: Analyze the debugging logs, firstly check the algorithm and then check how long it take:



S2750 SSH login is slow-2735569-1


       3. After analyzing the debug we noticed it use the highest complex one which should use the most time to compute.

SSH have 3 different algorithms dh_group_exchange_sha1dh_group14_sha1dh_group1_sha1 . It uses now “dh_group_exchange_sha1” which is the highest algorithms with complex security.

Since uses the most complex algorithm and since this switch does not have enough CPU to compute, it is normal to take that long.


       4. As a workaround, we can use this command to adjust the sequence but this will compromise the security:

“ssh server key-exchange”

The default sequence is dh_group_exchange_sha1 | dh_group14_sha1 | dh_group1_sha1 and the security is from high to low. We can also change the algorithm from Putty tool.


S2750 SSH login is slow-2735569-2

This article contains more resources

You need to log in to download or view. No account?Register

x
  • x
  • convention:

Created Aug 25, 2018 02:03:05 Helpful(0) Helpful(0)

Nice sharing, I´ll consider in the future.....!!! thanks very much !! :):)
  • x
  • convention:

Created Dec 11, 2018 12:59:26 Helpful(0) Helpful(0)

with the 5720 series ssh is slow too. are there some best practise workarounds too?
  • x
  • convention:

Created Dec 22, 2018 01:24:44 Helpful(0) Helpful(0)

After analyzing the debug we noticed it use the highest complex one which should use the most time to compute.

SSH have 3 different algorithms dh_group_exchange_sha1、dh_group14_sha1、dh_group1_sha1 . It uses now “dh_group_exchange_sha1” which is the highest algorithms with complex security.

Since uses the most complex algorithm and since this switch does not have enough CPU to compute, it is normal to take that long.

thanks for sharing.
  • x
  • convention:

Created Dec 24, 2018 01:41:12 Helpful(0) Helpful(0)

This post was last edited by xiaomumu at 2018-12-27 02:57. S2750 SSH login speed is very slow, is there any way to avoid it?
  • x
  • convention:

Created Dec 24, 2018 17:10:14 Helpful(0) Helpful(0)

It's hard
  • x
  • convention:

Created Dec 27, 2018 07:51:41 Helpful(1) Helpful(1)

After analyzing the debug we noticed it use the highest complex one which should use the most time to compute.How do you understand this sentence?
  • x
  • convention:

Reply

Reply
You need to log in to reply to the post Login | Register

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " Privacy."
If the attachment button is not available, update the Adobe Flash Player to the latest version!

Login and enjoy all the member benefits

Login
Fast reply Scroll to top