Created on 09-27-2016 07:11 AM Edited on 04-08-2022 11:13 AM By Anonymous
Description
After I replace target Unix/Linux server with the same IP address, SSH credential does not work with correct user ID and password. Device discovery is fails.
AO VA keeps RSA public key of target SSH server. To protect from Man-in-the-middle attack, SSH does not allow the key to be updated automatically so the discovery fails. You need to delete old key and re-discover the target device.
1. Please login to your AO host via SSH as root
2. Run the command: cd /opt/phoenix/bin/.ssh
3. Please run the command: vi known_hosts
4. Find the IP address that you want to reset the SSH key for
5. Delete the entry of the device's IP
6. To save the changes press the follow keys: [ESC] [:] [w][q] [ENTER]
Change your user account to admin
User the following instructions to remove the SSH key to the device IP
Here is the output as an example:
[root@myhost .ssh]# su - admin
[admin@myhost ~]$ ssh-keygen -R 64.29.235.1
/opt/phoenix/bin/.ssh/known_hosts updated.
Original contents retained as /opt/phoenix/bin/.ssh/known_hosts.old
All
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.