09-21-2013 09:51 AM - edited 03-07-2019 03:36 PM
I have a problem with Cisco Prime Infrastructure and my Nexus gear (1000v, 5Ks and 7Ks). The problem is that Prime doesn't properly close down the ssh sessions and eventually it consumes all available sessions and then we're no longer able to SSH to our gear. To work around this we have to console in and disable/re-enable the SSH feature. I noticed that there's a sub-command under the "line vty" section called absolute-timeout. I'm assuming that I can set this paramter so that the switch will kill a session which has reached the configured time. I've seen references to this command in Cisco documentation and it looks like the default is disabled (don't apply an absolute timeout timer). However, no matter what value I stuff into this command a subsequent verification of 'show run | sec "line vty"' reveals the following:
line vty
access-class ssh-access in
which would imply that a) the command really isn't supported or b) Cisco is really, really bad at writing software (refer to Cisco Prime Infrastructure for details). It's a toss-up. I cannot find a single command I can run at the CLI that shows me whether an absolute-timeout feature is configured and, if it is, the value of the timeout. Any ideas?
05-03-2018 06:31 AM
11-07-2018 06:41 AM
To see the configuration information for "absolute-timeout" command run the following:
show run all | beg "line vty"
you should see the "absolute-timeout set to 0 which is the default.
The reason your were not see it is because you did not include "all" in your "show run" command so default configuration commands would be seen. Hope this answers your question.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide