SSHv2
The following SSH commands are affected when the FastIron device is in FIPS mode:
- In FIPS mode, the aes192-ctr,
aes192-cbc, and 3des-cbc options are not supported in the
ip ssh encryptioncommand. ip ssh encryption aes256-cbcip ssh encryption aes128-cbcip ssh encryption aes256-ctrip ssh encryption aes128-ctr- The
ip ssh key-authentication nocommand is disabled. - The
ip ssh scpcommand ensures that SCP is enabled to run in FIPS mode. SCP is needed for file communication, and theip ssh scp disablecommand is disabled in FIPS mode and displays the following message:FIPS Compliance: SCP needs to be enabled
- The
crypto key zeroizecommand removes configured SSH keys.
Note: The following public key algorithms are supported in FIPS mode:
Note: The following key exchange methods are supported in FIPS mode:
Use the
show ip ssh config command to display SSH configuration information.
SSH key generation time is affected by the increased security of authentication and encryption algorithms both in and out of FIPS mode.