Optional Parameters Overview

You can adjust the following SSH settings on the RUCKUS device.

  • The user authentication method: For SSH connections, the RUCKUS ICX device can use several authentication types together or individually. Refer to SSH2 Authentication Types.

  • The number of SSH authentication retries: By default, the RUCKUS ICX device tries five times to negotiate a connection with the host. The number of authentication retries can be configured as 1 through 5. Open SSH counts the password, public key, and keyboard-interactive authentication attempts as authentication retries.

  • Key exchange method: RUCKUS ICX SSHv2 offers diffie-hellman-group14-sha1, diffie-hellman-group14-sha256, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, diffie-hellman-group-exchange-sha256, ecdh-sha2-nistp256, ecdh-sha2-nistp384, ecdh-sha2-nistp521, curve25519-sha256, and curve25519-sha256@libssh.org as the key exchange methods available for establishing an SSH connection. To change active support, use the ip ssh key-exchange-method command as described in Setting Optional Parameters.

  • Host key algorithm: ICX SSHv2 supports ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ssh-rsa, rsa-sha2-256, rsa-sha2-512, ecdsa-sha2-nistp521, and ssh-ed25519.

    Use the ip ssh host-key-method command to manage the available options as described in Setting Optional Parameters.

  • SSH encryption: ICX SSHv2 supports the following forms of encryption: 3des-cbc, aes128-cbc, aes192-cbc, aes256-cbc, aes128-ctr, aes192-ctr, and aes256-ctr. To change active support, use the ip ssh encryption command as described in Setting Optional Parameters.

  • The port number for SSH connections: By default, SSH traffic is carried on TCP port 22. You can change this port number; however, you must configure SSH clients to connect to the new port. You must also be careful not to assign SSH to a port that is used by another service.

  • The SSH login timeout value: When the SSH server attempts to negotiate a session key and encryption method with a connecting client, it waits a maximum of 120 seconds by default for a response from the client. If there is no response from the client after 120 seconds, the SSH server disconnects. You can configure a timeout value from 1 through 120 seconds.

  • Source interface for all SSH traffic from the device: By default, the management port is used as the source interface for all SSH traffic from the RUCKUS ICX device. You can instead designate an Ethernet port, virtual interface, or loopback interface.
  • The maximum idle time for SSH sessions: By default, SSH sessions time out after 5 minutes of inactivity. You can set the amount of time an SSH session can be inactive before the RUCKUS device closes it. An idle time of 0 minutes means that SSH sessions never time out. The maximum idle time for SSH sessions is 240 minutes.

  • SSH rekey: In an SSH2 implementation, if an SSH session is authenticated and established, it remains connected until the user closes it or until the configured idle time limit is reached. Prolonged use of the session key negotiated at connection poses several security issues and exposes the SSH connection to man-in-middle attacks. To safeguard the SSH connection from security vulnerability, new keys should be exchanged frequently for existing SSH sessions.