SSHv2

Secure Shell version 2 (SSHv2) is allowed in FIPS mode.

The following SSH commands are affected when the FastIron device is in FIPS mode:

  • The ip ssh encryption aes-only command is disabled.
  • The ip ssh key-authentication no command is disabled.
  • The ip ssh permit-empty-passwd command is disabled.
  • The ip ssh pub-key-file tftp command is disabled.
  • The ip ssh scp command ensures that SCP is enabled to run in FIPS mode. SCP is needed for file communication and the ip ssh scp disable command is disabled in FIPS mode and displays the following message:
    FIPS Compliance: SCP needs to be enabled
  • The crypto key zeroize command removes configured SSH keys.

Note: The following encryption methods are supported in FIPS mode:
  • aes256-ctr
  • aes128-ctr

Use the show ip ssh config command to display SSH configuration information.

SSH key generation time is affected by the increased security of authentication and encryption algorithms both in and out of FIPS mode.