SSHv2 Supported Features

Secure Shell version 2 protocol (SSHv2) provides an SSH server and an SSH client. The SSH server allows secure remote access management functions on a RUCKUS device.

RUCKUS SSHv2 supports the following options.

  • The following key exchange methods are supported for establishing an SSH connection:
    • diffie-hellman-group14-sha1
    • diffie-hellman-group-exchange-sha256
    • diffie-hellman-group14-sha256
    • diffie-hellman-group16-sha512
    • diffie-hellman-group18-sha512
    • curve25519-sha256@libssh.org
    • ecdh-sha2-nistp256
    • ecdh-sha2-nistp384
    • ecdh-sha2-nistp521
    • curve25519-sha256

    To change active support, use the ip ssh key-exchange-method command as described in Setting Optional Parameters.

  • The following host key algorithms are supported:
    • ecdsa-sha2-nistp256
    • ecdsa-sha2-nistp384
    • rsa-sha2-256
    • rsa-sha2-512
    • ssh-rsa
    • ecdsa-sha2-nistp521
    • ssh-ed25519

    Use the ip ssh host-key-method command to manage the available algorithms as described in Setting Optional Parameters.

  • The following forms of encryption are supported:
    • 3des-cbc
    • aes128-cbc
    • aes192-cbc
    • aes256-cbc
    • aes128-ctr
    • aes192-ctr
    • aes256-ctr

    Use the ip ssh encryption command to manage the encryption options as described in Setting Optional Parameters.

    AES encryption has been adopted by the U.S. Government as an encryption standard.

    Per SME comment during FI 10.0.10d review that the disable-hmac-sha1 option is deprecated, I have removed the following bullet:
    • Data integrity is ensured with hmac-sha1 by default.
      Note: To disable HMAC-SHA1, enter the ip ssh message-authentication-code disable-hmac-sha1 command in global configuration mode. Use the no form of the command to re-enable HMAC-SHA1.
  • The following message authentication codes are supported:
    • umac-64-etm@openssh.com
    • umac-128-etm@openssh.com
    • hmac-sha2-256-etm@openssh.com
    • hmac-sha2-512-etm@openssh.com
    • hmac-sha1-etm@openssh.com
    • umac-64@openssh.com
    • umac-128@openssh.com
    • hmac-sha2-256
    • hmac-sha2-512
    • hmac-sha1

      Note: By default, all the message-authentication-codes mentioned above are enabled. To enable a specific message authentication code, enter the ip ssh message-authentication-code command and specify the desired message-authentication-code in the global configuration mode. This command will automatically disable all other message-authentication-codes. Use the no form of the command to disable a specific message-authentication-code.

  • Supported authentication methods are password, interactive, and key authentication.
  • Supported SSH security options ip ssh stricthostkeycheck ask and ip ssh delete-known-host-key.
  • Five simultaneous inbound SSH connections are supported.
  • Five simultaneous outbound SSH connections are supported.