Setting Optional Parameters

Perform any of the following steps if necessary to change optional SSH parameters.
  1. (Optional) Specify one or more key exchange methods. You can specify any options listed in SSHv2 Supported Features.
    The following example adds diffie-helman-group164-sha512 if the option has been disabled.
    device(config)# ip ssh key-exchange-method diffie-hellman-group164-sha512
    Note: At least one algorithm must be present in the configuration. It is not possible to remove all algorithms.
  2. (Optional) Specify the SSH encryption algorithm or algorithms to be used.
    device(config)# ip ssh encryption aes128-cbc aes256-cbc
  3. (Optional) Specify the host key algorithm or algorithms to be used. By default, all are supported. You can specify one or more of the algorithms listed in SSHv2 Supported Features.
    The following example enables ecdsa-sha2-nistp256 and ecdsa-sha2-nistp384 as secure host key algorithms on the ICX device.
    device(config)# ip ssh host-key-method ecdsa-sha2-nistp256 ecdsa-sha2-nistp384
  4. (Optional) Assign a new port to carry SSH traffic.
    The following example reassigns port 2200 for SSH traffic.
    device(config)# ip ssh port 2200
    
    Note: If you change the SSH port number, RUCKUS recommends that you change it to a port number greater than 1024.
  5. (Optional) Specify an SSH connection timeout value from 1 through 120 seconds. The default is 120 seconds.
    The following example configures an SSH connection timeout of 60 seconds.
    device(config)# ip ssh timeout 60
    
  6. (Optional) Specify an interface type to be used for the SSH connection.
    The following example sets Ethernet port 1/2/4 as the SSH source interface on the RUCKUS ICX device.
    device(config)# ip ssh source interface ethernet 1/2/4
  7. (Optional) Set the idle time for SSH sessions. The default is 2 minutes.
    Note: The cli timeout command setting controls CLI, rconsole (remote console), Telnet, and SSH sessions.
    The following example configures SSH sessions to never time out due to inactivity.
    device(config)# cli timeout 0
    
    The following example configures SSH sessions to time out after 30 minutes of inactivity.
    device(config)# cli timeout 30
    
  8. (Optional) Configure the interval for SSH rekey exchange.
    The following example sets the rekey exchange interval to 5 minutes.
    device(config)# ip ssh rekey time 5
  9. (Optional) Configure the ICX device acting as an SSH client to prompt the user for confirmation if the client encounters a new host key.
    The following example configures the ICX device to prompt the user to confirm the identity of an SSH host server when it presents a new key.
    device# configure terminal
    device(config)# ip ssh stricthostkeycheck ask
  10. (Optional) Configure the ICX device to delete the known key of the SSH server and to prompt the user to confirm the new key for the same server on the next SSH connection attempt.
    The following example configures the ICX device to delete the known key and to prompt the user to confirm the new key.
    device# configure terminal
    device(config)# ip ssh delete-known-host-key 10.10.10.10