Setting Optional Parameters
- (Optional) Specify one or more
key exchange methods. You can specify any options listed in SSHv2 Supported Features. The following example adds diffie-helman-group164-sha512 if the option has been disabled.Note: At least one algorithm must be present in the configuration. It is not possible to remove all algorithms.
- (Optional) Specify the SSH encryption algorithm or algorithms to be used.
- (Optional) Specify the host key
algorithm or algorithms to be used. By default, all are supported. You can
specify one or more of the algorithms listed in SSHv2 Supported Features.The following example enables ecdsa-sha2-nistp256 and ecdsa-sha2-nistp384 as secure host key algorithms on the ICX device.
- (Optional) Specify the message authentication code algorithm or algorithms to
be used. Note: All message authentication codes are configured by default but do not show up in running-configuration until modified. You can modify or remove one or more message authentication code algorithms, but you will not be able to delete the last algorithm. One algorithm must remain configured.
- (Optional) Assign a new port to carry SSH traffic.
The following example reassigns port 2200 for SSH traffic.
- (Optional) Specify an SSH connection timeout value from 1 through 120 seconds. The
default is 120 seconds.
The following example configures an SSH connection timeout of 60 seconds.
- (Optional) Specify an interface type to be used for the SSH connection.
The following example sets Ethernet port 1/2/4 as the SSH source interface on the RUCKUS ICX device.
- (Optional) Set the idle time for
SSH sessions. The default is 2 minutes. The following example configures SSH sessions to never time out due to inactivity.The following example configures SSH sessions to time out after 30 minutes of inactivity.
- (Optional) Configure the interval for SSH rekey exchange.
The following example sets the rekey exchange interval to 5 minutes.
- (Optional) Configure the ICX
device acting as an SSH client to prompt the user for confirmation if the client
encounters a new host key. The following example configures the ICX device to prompt the user to confirm the identity of an SSH host server when it presents a new key.
- (Optional) Configure the ICX
device to delete the known key of the SSH server and to prompt the user to
confirm the new key for the same server on the next SSH connection
attempt.The following example configures the ICX device to delete the known key and to prompt the user to confirm the new key.