Setting Optional Parameters
- (Optional) Specify one or more
key exchange methods. You can specify any options listed in SSHv2 Supported Features. The following example adds diffie-helman-group16-sha512 if the option has been disabled.Note: At least one algorithm must be present in the configuration. It is not possible to remove all algorithms.
- (Optional) Specify the SSH encryption algorithm or algorithms to be used.
- (Optional) Specify the host key
algorithm or algorithms to be used. By default, all are supported. You can
specify one or more of the algorithms listed in SSHv2 Supported Features.The following example enables ecdsa-sha2-nistp256 and ecdsa-sha2-nistp384 as secure host key algorithms on the ICX device.
- (Optional) Specify the message
authentication code algorithm or algorithms to be used. Note: All message authentication codes are configured by default but do not show up in running-configuration until modified. You can modify or remove one or more message authentication code algorithms, but you will not be able to delete the last algorithm. One algorithm must remain configured.
- (Optional) Specify an SSH login
timeout value from 1 through 120 seconds. The default is 120 seconds. The following example configures an SSH login timeout of 60 seconds.
- (Optional) Set the idle time for
SSH sessions. The default is 2 minutes. The following example configures SSH sessions to never time out due to inactivity.The following example configures SSH sessions to time out after 30 minutes of inactivity.Note: For security, it is recommended that you configure a non-zero value so that a timeout occurs any time the system is idle.
- (Optional) Configure the
interval for SSH rekey exchange. The following example sets the rekey exchange interval to 5 minutes.