Configuring BSI Cloud Mode and Optional Parameters

BSI Cloud mode, which is automatically configured on the ICX device when SmartZone establishes a connection using ECDSA, can also be configured manually on the ICX device. By default, only stronger algorithms will be used for SSH, and strong cipher suites will be used for TLS. In addition, SSH encryption parameters can be configured or modified.

Perform the following steps to configure BSI Cloud mode and optional parameters.

  1. Enter global configuration mode on the ICX device.
    device# configure terminal
    device(config)#
  2. Enter the bsicloud enable command.
    device(config)# bsicloud enable
    Note: Use the no bsicloud enable command to return the ICX device to default settings.
  3. (Optional) To create new ECDSA (elliptical) keys, enter the crypto key generate ec command, followed by the identifying label and the desired size.
    EC Host keys with a size of 256, 384, and 521 can be created. The default is 384.

    The following example generates an elliptical key pair named testkey with the default size of 384 bits.

    device(config)# crypto key generate ec label testkey
    The following example generates an elliptical key pair named largekey with a size of 521 bits.
    device(config)# crypto key generate ec label largekey size 512
  4. To create new RSA keys with a key strength greater than 2048, enter the crypto key generate rsa modulus command and the desired value.
    Valid values in BSI Cloud mode are 3072 and 4096. The default is 3072.
    device(config)# crypto key generate rsa modulus 3072
    Note: In BSI Cloud mode, keys with a size of 2048 cannot be generated.
  5. (Optional) To set the permissible key exchange methods, enter the ip ssh key-exchange-method command followed by key exchange methods to be allowed.
    device(config)# ip ssh key-exchange-method diffie-hellman-group16-sha512 diffie-hellman-group18-sha512
    Valid values are curve25519-sha256, curve25519-sha256@libssh.org, diffie-hellman-group-exchange-sha256, diffie-hellman-group14-sha1, diffie-hellman-group14-sha256, diffie-hellman-group16-sha512, diffie-hellman-group18-sha512, ecdh-sha2-nistp256, ecdh-sha2-nistp384, and ecdh-sha2-nistp521.

    Note: To disable one or more key exchange methods, enter the no form of the command followed by the list of algorithms to be disabled.

    At least one algorithm must be present in the configuration.

  6. (Optional) To set the permissible host key methods, enter the ip ssh host-key-method command, followed by one or more available host key methods.
    Valid values are ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521, rsa-sha2-512, rsa-sha2-256, ssh-ed25519, and ssh-rsa.

    Note: To disable one or more host key methods, enter the no form of the command followed by the list of algorithms to be disabled.

    device(config)# ip ssh host-key-method ecdsa-sha2-nistp384
  7. (Optional) To set the permissible key encryption methods, enter the ip ssh encryption command followed by one or more methods to be allowed.
    Valid values are aes256-cbc, aes192-cbc, aes128-cbc, aes256-ctr, aes192-ctr, aes128-ctr, and 3des-cbc.

    Note: To disable one or more key encryption methods, enter the no form of the command followed by the list of algorithms to be disabled.

    device(config)# ip ssh encryption aes256-cbc
    Note: During connection, when an inbound connection is being established, either the ECDSA key or a strong RSA key must be used for communication.