SCP and SFTP on Cisco IOS XE
Move configs and IOS XE images securely with SCP and SFTP over SSH: prerequisites, ip scp server enable, copy scp:// and sftp:// commands, and verification.
- SCP and SFTP ride inside SSH on TCP 22, so the file and the login are both encrypted. TFTP and FTP send everything in clear text.
- No working SSH means no SCP. You need a hostname, a domain name, RSA keys, SSH version 2 and a privilege 15 user before any secure copy works.
- The router can be the SCP server (
ip scp server enable, you push files to it) or the client (copy scp://user@server/file flash:, it pulls files itself).
Mental model
Routers need files moved: config backups out, new IOS XE images in. The old tools, TFTP and FTP, were built for a network where nobody was listening.
SCP (Secure Copy) and SFTP (SSH File Transfer Protocol) do the same job inside an SSH session, so the transfer gets encryption and a real login for free. SSH is the armored truck; SCP and SFTP are two ways of loading the cargo.
So if SSH to the box does not work, SCP will not work either. Fix SSH first. This is CCNA v2.0 objective 4.2; file system names like flash: are covered in Cisco IOS File System.
Why not TFTP or FTP
| Protocol | Transport | Login | Encrypted |
|---|---|---|---|
| TFTP | UDP 69 | None | No |
| FTP | TCP 21 and 20 | Username and password in clear text | No |
| SCP | SSH, TCP 22 | SSH login | Yes |
| SFTP | SSH, TCP 22 | SSH login | Yes |
A running config holds SNMP communities, pre-shared keys and usernames. Send it with TFTP and anyone capturing traffic can read it; TFTP does not even ask who you are. FTP asks, but sends the password in clear text. Fine in an isolated lab, not in production.
Prerequisites (SSH)
Cisco’s Secure Copy guide requires SSH, authentication and authorization, plus an RSA key pair. A working baseline:
R1(config)# hostname R1
R1(config)# ip domain name lab.local
R1(config)# crypto key generate rsa modulus 2048
R1(config)# ip ssh version 2
R1(config)# username admin privilege 15 secret Str0ngPass!
R1(config)# line vty 0 4
R1(config-line)# login local
R1(config-line)# transport input ssh
Why each line matters:
- Hostname and domain name. The RSA key is named from them, so IOS wants both set before you generate keys.
crypto key generate rsa modulus 2048. Creates the RSA key pair, and generating it turns on the SSH server. If you later delete the keys withcrypto key zeroize rsa, SSH is disabled again.ip ssh version 2. Allow SSHv2 only.privilege 15. SCP allows only privilege 15 users to copy files. Cisco’s guide says a lower privilege level results in the connection closing.
The router as SCP server
Here your laptop starts the transfer. Cisco pairs ip scp server enable with AAA so the router can check the user’s privilege level. The exec authorization line is the one people forget. See the AAA topic for what these lines do in general.
R1(config)# aaa new-model
R1(config)# aaa authentication login default local
R1(config)# aaa authorization exec default local
R1(config)# ip scp server enable
Push a file from Linux or macOS:
$ scp -O new-image.bin admin@10.0.0.1:new-image.bin
The -O flag matters. Starting with OpenSSH 9.0, the scp command uses SFTP under the hood by default. Cisco’s troubleshooting note explains that IOS XE does not accept that, so -O forces the classic SCP protocol.
Cisco also recommends turning the server off when the transfer is done:
R1(config)# no ip scp server enable
The router as SCP or SFTP client
Here the router starts the connection and pulls or pushes a file to a server you run. The server needs SSH, and the account you use needs rights on it. The SCP URL format from the IOS XE file system guide is scp:[[//username[:password]@location]/directory]/filename.
Pull a file from an SCP server into flash:
R1# copy scp://backup@10.0.0.5/new-image.bin flash:
Push the running config out to the same server:
R1# copy running-config scp://backup@10.0.0.5/R1-confg
Leave out the password and IOS prompts for it.
SFTP looks almost the same. On Catalyst 9000 switches, the SFTP client is always enabled, and Cisco lists ip ssh source-interface as a prerequisite. The SFTP server is not supported on those switches, so the switch is the client only.
R1(config)# ip ssh source-interface GigabitEthernet0/0/0
R1(config)# ip sftp username backup
R1(config)# ip sftp password 0 BackupPass1
R1(config)# end
R1# copy sftp://backup@10.0.0.5//images/new-image.bin flash:new-image.bin
R1# copy running-config sftp://backup@10.0.0.5//configs/R1-confg
Backing up configs and upgrading images
Config backup. Run the copy running-config scp://... line above after every change window.
Image upgrade. Copy the image to flash, then check it before you trust it:
R1# dir flash:
R1# copy scp://backup@10.0.0.5/new-image.bin flash:
R1# verify /md5 flash:new-image.bin
dir flash: first shows whether there is room. verify /md5 computes the MD5 hash of a file on the device; compare it with the MD5 on Cisco’s download page. If you paste the expected hash at the end of the command, IOS compares them for you and prints a Verified line when they match:
R1# verify /md5 flash:new-image.bin <published-md5-hash>
Plain verify flash:new-image.bin also works. The next steps (boot variable, install mode on Catalyst 9000) are platform specific and live in the IOS File System and device management topics.
Verification
R1# show ip ssh
R1# show ssh
R1# dir flash:
show ip sshshows whether SSH is enabled and its settings, such as the version.show sshlists active SSH sessions with the username and encryption in use.dir flash:confirms the file arrived and that the byte count looks right.
For deeper trouble, debug ip scp shows the server side of each transfer. Turn it off with undebug all when you are done.
Common mistakes
No RSA keys, so SSH never started. Without a key pair there is no SSH server, and SCP fails before it even asks for a password. Check
show ip ssh, then generate keys withcrypto key generate rsa modulus 2048.The user is not privilege 15. The login works, then the connection closes. SCP only allows privilege 15 users to copy files. Fix the
usernameline or the AAA server profile.Missing
aaa authorization exec default local. Withaaa new-modelon, the router still needs exec authorization to learn the user’s privilege level. Without it, the copy is refused.Forgetting
ip scp server enable. SSH works, but pushing a file to the router fails until the SCP server is on.Using a modern
scpclient without-O. OpenSSH 9.0 and later sends SFTP by default, which IOS XE does not accept as an SCP server. Add-O.Skipping the hash check. A corrupted image can still land in flash. Run
verify /md5first.
Lab to try tonight
- On a router or CML node, build the SSH baseline from the Prerequisites section.
- From your laptop, SSH to the router with the privilege 15 user. Do not move on until this works.
- Add the AAA lines and
ip scp server enable. - From your laptop, run
scp -O test.txt admin@<router-ip>:test.txt, thendir flash:on the router. - Run a Linux VM with OpenSSH and a
backupuser. From the router, runcopy running-config scp://backup@<vm-ip>/R1-confgand open the file on the VM. - Pull the file back with
copy scp://backup@<vm-ip>/R1-confg flash:R1-confgand runverify /md5 flash:R1-confg. Compare it withmd5sum R1-confgon the VM. - Clean up with
no ip scp server enable.
Cheat strip
| Item | Plain English |
|---|---|
| Transport | SSH, TCP 22, for both SCP and SFTP |
crypto key generate rsa modulus 2048 | RSA keys, which also turn on SSH |
ip ssh version 2 | SSHv2 only |
username X privilege 15 secret Y | SCP needs privilege 15 |
aaa authorization exec default local | Lets the router check the privilege level |
ip scp server enable | Router accepts SCP transfers |
copy scp://user@host/file flash: | Router pulls a file with SCP |
copy running-config sftp://user@host//path | Router pushes a file with SFTP |
ip ssh source-interface | Fixed source IP for outgoing SSH, SCP and SFTP |
verify /md5 flash:file | Hash check before you trust an image |
show ip ssh / show ssh | SSH settings / live SSH sessions |
Frequently asked questions
Q: What port do SCP and SFTP use? A: Both run inside SSH, which listens on TCP 22. There is no separate port to open on the firewall.
Q: What is the difference between SCP and SFTP? A: Both are secure and both use SSH. SCP just copies a file from one place to another. SFTP is a fuller file protocol with directory listings and file operations. On IOS XE the router acts as an SCP server, while on Catalyst 9000 switches it acts only as an SFTP client.
Q: Why does my SCP login succeed and then the connection drops? A: Almost always the privilege level. SCP allows only privilege 15 users to copy files, and a lower level closes the connection. Also check that aaa authorization exec default local is configured.
Q: Why does scp from my laptop fail against the router when it used to work? A: OpenSSH 9.0 changed the default so scp uses SFTP under the hood. Cisco’s fix is to add -O to use the classic SCP protocol.
Practice: quick check
Every question in the bank, once. No repeats. Missed ones cycle back at the end.
TFTP and FTP: Network File Transfer Basics
TFTP (UDP/69, config uploads) vs FTP (TCP/20 and 21, larger IOS images) for the CCNA: when to use each and the copy commands between flash and a server.
FHRP: HSRP, VRRP & GLBP
First-hop redundancy protocols. How two routers share one virtual IP so hosts don't notice when their default gateway fails. Covers HSRP states, election, preemption, and the GLBP load-balancing twist.
Want this drilled into reflex?
1:1 weekly sessions, live feedback on your labs, and US interview prep: built around the CCNA® exam blueprint. Free first session. No card on file until you decide.
Related topics
AAA · RADIUS & TACACS+
AAA (authentication, authorization and accounting) explained: RADIUS vs TACACS+, method lists, and why networks over 5 devices use centralized auth.
Device OperationsCisco IOS Device Management
How you actually log into and configure a Cisco device. Covers console / SSH / Telnet access, command modes (user / privileged / config), saving config, banners, the password types, and modern best practices for line security.
Device OperationsCisco IOS File System
Where Cisco IOS stores configs, images and logs (flash:, nvram:, system:, tftp:), plus copy syntax, image management, boot variables and file commands.
Get the free CCNA 12-week roadmap
You're already reading up on SCP and SFTP on Cisco IOS XE. The roadmap is the order I recommend studying every CCNA topic in: with what to lab each week and where SCP and SFTP on Cisco IOS XE fits. A written personal reply, not an autoresponder. Expect it within one business day.
Personal reply from a senior network engineer. No third-party tracking. Unsubscribe any time.
