Skip to main content
PacketMentor logo
Open menu
← All topics
IP Services Intermediate

SCP and SFTP on Cisco IOS XE

Move configs and IOS XE images securely with SCP and SFTP over SSH: prerequisites, ip scp server enable, copy scp:// and sftp:// commands, and verification.

Quick summary
  • SCP and SFTP ride inside SSH on TCP 22, so the file and the login are both encrypted. TFTP and FTP send everything in clear text.
  • No working SSH means no SCP. You need a hostname, a domain name, RSA keys, SSH version 2 and a privilege 15 user before any secure copy works.
  • The router can be the SCP server (ip scp server enable, you push files to it) or the client (copy scp://user@server/file flash:, it pulls files itself).

Mental model

Routers need files moved: config backups out, new IOS XE images in. The old tools, TFTP and FTP, were built for a network where nobody was listening.

SCP (Secure Copy) and SFTP (SSH File Transfer Protocol) do the same job inside an SSH session, so the transfer gets encryption and a real login for free. SSH is the armored truck; SCP and SFTP are two ways of loading the cargo.

So if SSH to the box does not work, SCP will not work either. Fix SSH first. This is CCNA v2.0 objective 4.2; file system names like flash: are covered in Cisco IOS File System.

Why not TFTP or FTP

ProtocolTransportLoginEncrypted
TFTPUDP 69NoneNo
FTPTCP 21 and 20Username and password in clear textNo
SCPSSH, TCP 22SSH loginYes
SFTPSSH, TCP 22SSH loginYes

A running config holds SNMP communities, pre-shared keys and usernames. Send it with TFTP and anyone capturing traffic can read it; TFTP does not even ask who you are. FTP asks, but sends the password in clear text. Fine in an isolated lab, not in production.

Prerequisites (SSH)

Cisco’s Secure Copy guide requires SSH, authentication and authorization, plus an RSA key pair. A working baseline:

R1(config)# hostname R1
R1(config)# ip domain name lab.local
R1(config)# crypto key generate rsa modulus 2048
R1(config)# ip ssh version 2
R1(config)# username admin privilege 15 secret Str0ngPass!
R1(config)# line vty 0 4
R1(config-line)# login local
R1(config-line)# transport input ssh

Why each line matters:

  • Hostname and domain name. The RSA key is named from them, so IOS wants both set before you generate keys.
  • crypto key generate rsa modulus 2048. Creates the RSA key pair, and generating it turns on the SSH server. If you later delete the keys with crypto key zeroize rsa, SSH is disabled again.
  • ip ssh version 2. Allow SSHv2 only.
  • privilege 15. SCP allows only privilege 15 users to copy files. Cisco’s guide says a lower privilege level results in the connection closing.

The router as SCP server

Here your laptop starts the transfer. Cisco pairs ip scp server enable with AAA so the router can check the user’s privilege level. The exec authorization line is the one people forget. See the AAA topic for what these lines do in general.

R1(config)# aaa new-model
R1(config)# aaa authentication login default local
R1(config)# aaa authorization exec default local
R1(config)# ip scp server enable

Push a file from Linux or macOS:

$ scp -O new-image.bin admin@10.0.0.1:new-image.bin

The -O flag matters. Starting with OpenSSH 9.0, the scp command uses SFTP under the hood by default. Cisco’s troubleshooting note explains that IOS XE does not accept that, so -O forces the classic SCP protocol.

Cisco also recommends turning the server off when the transfer is done:

R1(config)# no ip scp server enable

The router as SCP or SFTP client

Here the router starts the connection and pulls or pushes a file to a server you run. The server needs SSH, and the account you use needs rights on it. The SCP URL format from the IOS XE file system guide is scp:[[//username[:password]@location]/directory]/filename.

Pull a file from an SCP server into flash:

R1# copy scp://backup@10.0.0.5/new-image.bin flash:

Push the running config out to the same server:

R1# copy running-config scp://backup@10.0.0.5/R1-confg

Leave out the password and IOS prompts for it.

SFTP looks almost the same. On Catalyst 9000 switches, the SFTP client is always enabled, and Cisco lists ip ssh source-interface as a prerequisite. The SFTP server is not supported on those switches, so the switch is the client only.

R1(config)# ip ssh source-interface GigabitEthernet0/0/0
R1(config)# ip sftp username backup
R1(config)# ip sftp password 0 BackupPass1
R1(config)# end
R1# copy sftp://backup@10.0.0.5//images/new-image.bin flash:new-image.bin
R1# copy running-config sftp://backup@10.0.0.5//configs/R1-confg

Backing up configs and upgrading images

Config backup. Run the copy running-config scp://... line above after every change window.

Image upgrade. Copy the image to flash, then check it before you trust it:

R1# dir flash:
R1# copy scp://backup@10.0.0.5/new-image.bin flash:
R1# verify /md5 flash:new-image.bin

dir flash: first shows whether there is room. verify /md5 computes the MD5 hash of a file on the device; compare it with the MD5 on Cisco’s download page. If you paste the expected hash at the end of the command, IOS compares them for you and prints a Verified line when they match:

R1# verify /md5 flash:new-image.bin <published-md5-hash>

Plain verify flash:new-image.bin also works. The next steps (boot variable, install mode on Catalyst 9000) are platform specific and live in the IOS File System and device management topics.

Verification

R1# show ip ssh
R1# show ssh
R1# dir flash:
  • show ip ssh shows whether SSH is enabled and its settings, such as the version.
  • show ssh lists active SSH sessions with the username and encryption in use.
  • dir flash: confirms the file arrived and that the byte count looks right.

For deeper trouble, debug ip scp shows the server side of each transfer. Turn it off with undebug all when you are done.

Common mistakes

  1. No RSA keys, so SSH never started. Without a key pair there is no SSH server, and SCP fails before it even asks for a password. Check show ip ssh, then generate keys with crypto key generate rsa modulus 2048.

  2. The user is not privilege 15. The login works, then the connection closes. SCP only allows privilege 15 users to copy files. Fix the username line or the AAA server profile.

  3. Missing aaa authorization exec default local. With aaa new-model on, the router still needs exec authorization to learn the user’s privilege level. Without it, the copy is refused.

  4. Forgetting ip scp server enable. SSH works, but pushing a file to the router fails until the SCP server is on.

  5. Using a modern scp client without -O. OpenSSH 9.0 and later sends SFTP by default, which IOS XE does not accept as an SCP server. Add -O.

  6. Skipping the hash check. A corrupted image can still land in flash. Run verify /md5 first.

Lab to try tonight

  1. On a router or CML node, build the SSH baseline from the Prerequisites section.
  2. From your laptop, SSH to the router with the privilege 15 user. Do not move on until this works.
  3. Add the AAA lines and ip scp server enable.
  4. From your laptop, run scp -O test.txt admin@<router-ip>:test.txt, then dir flash: on the router.
  5. Run a Linux VM with OpenSSH and a backup user. From the router, run copy running-config scp://backup@<vm-ip>/R1-confg and open the file on the VM.
  6. Pull the file back with copy scp://backup@<vm-ip>/R1-confg flash:R1-confg and run verify /md5 flash:R1-confg. Compare it with md5sum R1-confg on the VM.
  7. Clean up with no ip scp server enable.

Cheat strip

ItemPlain English
TransportSSH, TCP 22, for both SCP and SFTP
crypto key generate rsa modulus 2048RSA keys, which also turn on SSH
ip ssh version 2SSHv2 only
username X privilege 15 secret YSCP needs privilege 15
aaa authorization exec default localLets the router check the privilege level
ip scp server enableRouter accepts SCP transfers
copy scp://user@host/file flash:Router pulls a file with SCP
copy running-config sftp://user@host//pathRouter pushes a file with SFTP
ip ssh source-interfaceFixed source IP for outgoing SSH, SCP and SFTP
verify /md5 flash:fileHash check before you trust an image
show ip ssh / show sshSSH settings / live SSH sessions

Frequently asked questions

Q: What port do SCP and SFTP use? A: Both run inside SSH, which listens on TCP 22. There is no separate port to open on the firewall.

Q: What is the difference between SCP and SFTP? A: Both are secure and both use SSH. SCP just copies a file from one place to another. SFTP is a fuller file protocol with directory listings and file operations. On IOS XE the router acts as an SCP server, while on Catalyst 9000 switches it acts only as an SFTP client.

Q: Why does my SCP login succeed and then the connection drops? A: Almost always the privilege level. SCP allows only privilege 15 users to copy files, and a lower level closes the connection. Also check that aaa authorization exec default local is configured.

Q: Why does scp from my laptop fail against the router when it used to work? A: OpenSSH 9.0 changed the default so scp uses SFTP under the hood. Cisco’s fix is to add -O to use the classic SCP protocol.

Master this on a real network

Want this drilled into reflex?

1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA® exam blueprint. Free first session. No card on file until you decide.

Claim my free session →

Get the free CCNA 12-week roadmap

You're already reading up on SCP and SFTP on Cisco IOS XE. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where SCP and SFTP on Cisco IOS XE fits. A written personal reply, not an autoresponder. Expect it within one business day.

Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.