Configuring BSI Cloud Mode and Optional Parameters
BSI Cloud mode, which is automatically configured on the ICX device when SmartZone establishes a connection using ECDSA, can also be configured manually on the ICX device. By default, only stronger algorithms will be used for SSH, and strong cipher suites will be used for TLS. In addition, SSH encryption parameters can be configured or modified.
Perform the following steps to configure BSI Cloud mode and optional parameters.
- Enter global configuration mode on the ICX device.
- Enter the
bsicloud enablecommand. - (Optional) To create new ECDSA
(elliptical) keys, enter the
crypto key generate eccommand, followed by the identifying label and the desired size.EC Host keys with a size of 256, 384, and 521 can be created. The default is 384.The following example generates an elliptical key pair named testkey with the default size of 384 bits.
The following example generates an elliptical key pair named largekey with a size of 521 bits. - To create new RSA keys with a
key strength greater than 2048, enter the
crypto key generate rsa moduluscommand and the desired value.Valid values in BSI Cloud mode are 3072 and 4096. The default is 3072.Note: In BSI Cloud mode, keys with a size of 2048 cannot be generated. - (Optional) To set the
permissible key exchange methods, enter the
ip ssh key-exchange-methodcommand followed by key exchange methods to be allowed.device(config)# ip ssh key-exchange-method diffie-hellman-group16-sha512 diffie-hellman-group18-sha512
Valid values are curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group-exchange-sha256, diffie-hellman-group14-sha1, diffie-hellman-group14-sha256, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, ecdh-sha2-nistp256, ecdh-sha2-nistp384, and ecdh-sha2-nistp521. - (Optional) To set the permissible host key methods, enter the
ip ssh host-key-methodcommand, followed by one or more available host key methods.Valid values are ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521, rsa-sha2-512, rsa-sha2-256, ssh-ed25519, and ssh-rsa. - (Optional) To set the
permissible key encryption methods, enter the
ip ssh encryptioncommand followed by one or more methods to be allowed.Valid values are aes256-cbc, aes192-cbc, aes128-cbc, aes256-ctr, aes192-ctr, aes128-ctr, and 3des-cbc.Note: During connection, when an inbound connection is being established, either the ECDSA key or a strong RSA key must be used for communication.