SSHv2 Supported Features
Secure Shell version 2 protocol (SSHv2) provides an SSH server and an SSH client. The SSH server allows secure remote access management functions on a RUCKUS device.
RUCKUS SSHv2 supports the following options.
- The following key exchange methods are supported
for establishing an SSH connection:
- diffie-hellman-group14-sha1
- diffie-hellman-group-exchange-sha256
- diffie-hellman-group14-sha256
- diffie-hellman-group16-sha512
- diffie-hellman-group18-sha512
- curve25519-sha256@libssh.org
- ecdh-sha2-nistp256
- ecdh-sha2-nistp384
- ecdh-sha2-nistp521
- curve25519-sha256
To change active support, use the
ip ssh key-exchange-methodcommand as described in Setting Optional Parameters. - The following host key algorithms are
supported:
Use the
ip ssh host-key-methodcommand to manage the available algorithms as described in Setting Optional Parameters. - The following forms of encryption are
supported:
Use the
ip ssh encryptioncommand to manage the encryption options as described in Setting Optional Parameters.AES encryption has been adopted by the U.S. Government as an encryption standard.
- The following message authentication codes are supported:
- umac-64-etm@openssh.com
- umac-128-etm@openssh.com
- hmac-sha2-256-etm@openssh.com
- hmac-sha2-512-etm@openssh.com
- hmac-sha1-etm@openssh.com
- umac-64@openssh.com
- umac-128@openssh.com
- hmac-sha2-256
- hmac-sha2-512
- hmac-sha1
Note: By default, all the message-authentication-codes mentioned above are enabled. To enable a specific message authentication code, enter the
ip ssh message-authentication-codecommand and specify the desired message-authentication-code in the global configuration mode. This command will automatically disable all other message-authentication-codes. Use the no form of the command to disable a specific message-authentication-code.
- Supported authentication methods are password, interactive, and key authentication.
- Supported SSH security options
ip ssh stricthostkeycheck askandip ssh delete-known-host-key. - Five simultaneous inbound SSH connections are supported.
- Five simultaneous outbound SSH connections are supported.
ip ssh message-authentication-code disable-hmac-sha1command in global configuration mode. Use thenoform of the command to re-enable HMAC-SHA1.