I am a bit new to writing code, and I'm trying to automate some kind of searching mac-address in APR Table in firewalls.
in our deployment, we can access (SSH) the firewalls only through a jump server. so this is kind of nested ssh and I've found posts and codes that run that with no issues using Paramiko.
The challenge for me here is that the jump server after entering the username and password sends an email to me with a link to click to complete the authentication or to copy a code from this email and enter it in the shell following the messages that ask to enter this code.
Of course with my code, I always get authentication fails because I am ignoring this second authentication step. I don't know how to keep the ssh tunnel open and prompt the script to allow me to enter this auth code I receive in the email and to continue the script afterwards?
My piece of code that accesses the jump server and verify that I can run a command from its shell is below:
import paramiko
import sys
import subprocess
ssh_access = paramiko.SSHClient()
ssh_access.set_missing_host_key_policy(paramiko.AutoAddPolicy())
ssh_access.connect('192.168.1.1', username='root', password='root')
stdin, stdout, stdrr = ssh_access.exec_command("ls -l")
response = stdout.read()
print(response)
I am stuck on this part and appreciate help to continue with doing the actual target from the script.
Part of debugging file when I do SSH to the jump server
debug1: Authentications that can continue: password,keyboard-interactive^M
debug1: Next authentication method: keyboard-interactive^M
debug1: Authentication succeeded (keyboard-interactive).^M
Authenticated to 10.101.xx.xx ([10.101.xx.xx]:22).^M
debug1: channel 0: new [client-session]^M
debug1: Requesting no-more-sessions@openssh.com^M
debug1: Entering interactive session.^M
debug1: pledge: network^M
debug1: client_input_global_request: rtype hostkeys-00@openssh.com
want_reply 0^M
debug1: Sending environment.^M
debug1: Sending env LANG = C.UTF-8^M
debug1: client_input_channel_req: channel 0 rtype exit-status reply 0^M
debug1: client_input_channel_req: channel 0 rtype eow@openssh.com reply
0^M
debug1: channel 0: free: client-session, nchannels 1^M
debug1: fd 2 clearing O_NONBLOCK^M
Connection to 10.101.xx.xx closed.^M
Transferred: sent 2760, received 4520 bytes, in 21.5 seconds^M
Bytes per second: sent 128.4, received 210.3^M
debug1: Exit status 0^M