Setting Optional Parameters

Perform any of the following steps if necessary to change optional SSH parameters.
  1. (Optional) Specify one or more key exchange methods. You can specify any options listed in SSHv2 Supported Features.
    The following example adds diffie-helman-group16-sha512 if the option has been disabled.
    device(config)# ip ssh key-exchange-method diffie-hellman-group16-sha512
    Note: At least one algorithm must be present in the configuration. It is not possible to remove all algorithms.
  2. (Optional) Specify the SSH encryption algorithm or algorithms to be used.
    device(config)# ip ssh encryption aes128-cbc aes256-cbc
  3. (Optional) Specify the host key algorithm or algorithms to be used. By default, all are supported. You can specify one or more of the algorithms listed in SSHv2 Supported Features.
    The following example enables ecdsa-sha2-nistp256 and ecdsa-sha2-nistp384 as secure host key algorithms on the ICX device.
    device(config)# ip ssh host-key-method ecdsa-sha2-nistp256 ecdsa-sha2-nistp384
  4. (Optional) Specify the message authentication code algorithm or algorithms to be used.
    Note: All message authentication codes are configured by default but do not show up in running-configuration until modified. You can modify or remove one or more message authentication code algorithms, but you will not be able to delete the last algorithm. One algorithm must remain configured.
    device(config)# ip ssh message-authentication-code  hmac-sha2-256 hmac-sha2-512
  5. (Optional) Specify an SSH login timeout value from 1 through 120 seconds. The default is 120 seconds.
    The following example configures an SSH login timeout of 60 seconds.
    device(config)# ip ssh timeout 60
    
  6. (Optional) Set the idle time for SSH sessions. The default is 2 minutes.
    Note: In Korean CC mode, the cli timeout command setting controls CLI and SSH sessions.
    The following example configures SSH sessions to never time out due to inactivity.
    device(config)# cli timeout 0
    
    The following example configures SSH sessions to time out after 30 minutes of inactivity.
    device(config)# cli timeout 30
    Note: For security, it is recommended that you configure a non-zero value so that a timeout occurs any time the system is idle.
  7. (Optional) Configure the interval for SSH rekey exchange.
    The following example sets the rekey exchange interval to 5 minutes.
    device(config)# ip ssh rekey time 5