LOGBOOK

HELP

Quiz Entry - updated: 2026.08.27

Before enabling SSH (Secure Shell) on a Cisco switch, how do you check that its operating system is even capable of it?

Run show version and look for k9 in the IOS image name — that marks a cryptographic image. Without it the switch has no encryption engine to build an SSH session on.

S1# show version
Cisco IOS Software, C2960 Software (C2960-LANBASEK9-M), Version 15.0(2)SE7, RELEASE SOFTWARE (fc1)

SSH is not a feature you can simply switch on everywhere. It needs working ciphers and a key generator compiled into the operating system, and Cisco has long shipped IOS in two flavours — plain images and crypto-capable ones — a split that dates back to export controls on encryption software.

The tell sits in the filename. C2960-LANBASEK9-M reads as platform (C2960), feature set (LANBASE), K9 = cryptographic support, then memory/compression markers (M). Strip the k9 and the very same switch runs the very same feature set with no SSH available.

The symptom when it is missing is easy to misread: show ip ssh and crypto key generate rsa come back as unrecognised commands, as if you had mistyped them. A crypto command the parser refuses to accept is the signature of a non-k9 image, and the only cure is loading a cryptographic IOS — no amount of configuration will conjure one.

Tip: read k9 as canine. It is a made-up hook rather than the real etymology, but it sticks: no dog in the filename, no secrets kept.

Go deeper:

From Quiz: NETW2 / Basic Device Configuration | Updated: Aug 27, 2026