CONTAP-554359: SwitchSSHAccess_Alert on BES-53248 after ONTAP upgrade to 9.16
Issue
After an upgrade to ONTAP 9.16 alerts for SSH access are seen:Cluster::*> system health alert show
Node: Node_reporting
Alert ID: SwitchSSHAccess_Alert
Resource: Switch1
Severity: Minor
Indication Time: Mon Sep 15 14:18:37 2025
Suppress: false
Acknowledge: false
Probable Cause: SSH access to the Ethernet switch failed. ONTAP cannot
collect switch logs.
Possible Effect: Ethernet switch logs are not available, especially via
AutoSupport messages for troubleshooting.
Corrective Actions: 1) Ensure that the provided credentials are valid for
accessing the switch and that SSH connectivity to the switch is possible from the node running cshmd.
2) Confirm that the correct RCF (Remote Configuration
File) is configured on the switch.
3) If public SSH key authentication is already
configured, log in to the Ethernet switch with
administrative credentials from an SSH host or serial
console to investigate the login failures.
4) If issues persist, regenerate the SSH keys within
ONTAP and switch and retry the connection.
5) To disable log collection, run the "system switch
ethernet log disable-collection" command.
6) Refer to ONTAP switch health monitor log collection
documentation for further guidance. Node: Node_reporting
Alert ID: SwitchSSHAccess_Alert
Resource: Switch2
Severity: Minor
Indication Time: Mon Sep 15 13:42:41 2025
Suppress: false
Acknowledge: false
Probable Cause: SSH access to the Ethernet switch failed. ONTAP cannot
collect switch logs.
Possible Effect: Ethernet switch logs are not available, especially via
AutoSupport messages for troubleshooting.
Corrective Actions: 1) Ensure that the provided credentials are valid for
accessing the switch and that SSH connectivity to the switch is possible from the node running cshmd.
2) Confirm that the correct RCF (Remote Configuration
File) is configured on the switch.
3) If public SSH key authentication is already
configured, log in to the Ethernet switch with
administrative credentials from an SSH host or serial
console to investigate the login failures.
4) If issues persist, regenerate the SSH keys within
ONTAP and switch and retry the connection.
5) To disable log collection, run the "system switch
ethernet log disable-collection" command.
6) Refer to ONTAP switch health monitor log collection
documentation for further guidance.
Switch health shows as degraded:Cluster::*> system health subsystem show -subsystem switch-health -instance
Subsystem: Switch-Health
Health: degraded
Initialization State: initialized
Number of Outstanding Alerts: 2
Number of Suppressed Alerts: 0
Node: Node_reporting
Subsystem Refresh Interval: 5m
