ip ssh key-exchange-method

Configures the key-exchange methods that can be used to establish an SSH connection.
Syntax
ip ssh key-exchange-method { diffie-hellman-group-exchange-sha256 | diffie-hellman-group14-sha256 | diffie-hellman-group16-sha512 | diffie-hellman-group18-sha512 | curve25519-sha256@libssh.org | diffie-hellman-group14-sha1 | ecdh-sha2-nistp256 | ecdh-sha2-nistp384 | ecdh-sha2-nistp521 | curve25519-sha256 }
no ip ssh key-exchange-method { diffie-hellman-group-exchange-sha256 | diffie-hellman-group14-sha256 | diffie-hellman-group16-sha512 | diffie-hellman-group18-sha512 | curve25519-sha256@libssh.org | diffie-hellman-group14-sha1 | ecdh-sha2-nistp256 | ecdh-sha2-nistp384 | ecdh-sha2-nistp521 | curve25519-sha256 }
Command Default

By default, all methods are supported but do not show up in the running-configuration unless explicitly configured.

Modes

Global configuration mode

Usage Guidelines

One or more key exchange methods can be specified per command line.

The no form of the command deactivates the specified key-exchange method or methods.

Use the show running-config command to verify the system configuration.

Examples

The following example makes available diffie-hellman-group14-sha256 as a key-exchange method.

device(config)# ip ssh key-exchange-method diffie-hellman-group14-sha256
History
Release version Command history
08.0.30f This command was introduced.
09.0.00a This command was modified to add the SHA-256 option in regular ICX mode. Previously, the option was available only in FIPS mode.
09.0.10b This command was modified to remove the dh-group1-sha1 option.
10.0.10c This command was modified to use the following set of configurable options:

diffie-hellman-group-exchange-sha256, diffie-hellman-group14-sha256, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, curve25519-sha256@libssh.org, diffie-hellman-group14-sha1, ecdh-sha2-nistp256, ecdh-sha2-nistp384, ecdh-sha2-nistp521, curve25519-sha256