A network automation script is encountering an issue where it fails to connect to a Cisco IOS XE device using NETCONF over SSH. The error message indicates 'authentication failed'. The script uses username/password authentication. Which of the following is the MOST likely cause of this issue, assuming the username and password are correct?
- AThe NETCONF subsystem is not enabled on the device.
- BThe SSH transport for NETCONF is not configured on the device.
- CThe NETCONF client is using an incorrect SSH host key.
- DThe device's local user account lacks SSH access or appropriate privilege levels.
Show answer & explanationAnswer & explanation
Correct answer: D. The device's local user account lacks SSH access or appropriate privilege levels.
Even if NETCONF and SSH are enabled, an 'authentication failed' error for username/password, assuming correct credentials, often points to the user account itself. The local user might exist but lack the necessary `privilege 15` or not be configured for SSH access (e.g., `transport input ssh` not applied to VTY lines, or local authentication not configured for SSH). The NETCONF client uses the underlying SSH authentication; if SSH authentication fails for the user, NETCONF will also fail.
Why the other options are wrong
- A. If the NETCONF subsystem were not enabled, the error typically would be 'subsystem not found' or a similar connection refusal, not an authentication failure.
- B. If SSH transport for NETCONF was not configured, the connection would likely refuse or timeout before an authentication attempt, or indicate an invalid service.
- C. An incorrect SSH host key would result in a 'host key verification failed' error, not an 'authentication failed' error with username/password.
NETCONF over SSH Authentication
NETCONF typically uses SSH as its secure transport. Authentication for NETCONF over SSH relies on the underlying SSH authentication mechanism. If username/password authentication fails, it often indicates an issue with the local user account's configuration for SSH access or privilege level on the device.
- NETCONF uses SSH for secure transport.
- Authentication is handled by SSH (e.g., username/password, SSH keys).
- Local user accounts on Cisco devices need `privilege 15` for full NETCONF capabilities.
- SSH server must be enabled and VTY lines configured for SSH access.
Memory trick: Authentication failed? Check the user's SSH rights and privilege first.