ip ssh encryption

Enables the SSH encryption algorithms specified.
Syntax
ip ssh encryption { aes256-cbc | aes192-cbc | aes128-cbc | aes256-ctr | aes192-ctr | aes128-ctr | disable-aes-cbc | 3des-cbc }
no ip ssh encryption { aes256-cbc | aes192-cbc | aes128-cbc | aes256-ctr | aes192-ctr | aes128-ctr | disable-aes-cbc | 3des-cbc }
Command Default

By default, all methods are supported but are not displayed in the running-configuration unless explicitly configured.

By default, when BSI Cloud mode is enabled, weaker algorithms are removed, and available algorithms are displayed in the running-configuration.

Modes

Global configuration mode

Usage Guidelines

Enter a series of encryption algorithms separated by a space to enable multiple encryption methods.

The no form of the command disables the encryption algorithm specified in the same command line.

At least one encryption algorithm must be enabled. It is not possible to remove all the algorithms.

Examples

The following example enables three kinds of AES encyrption.

device(config)# ip ssh encryption aes256-cbc aes192-cbc aes128-cbc
History
Release version Command history
10.0.10c This command was added.