ip ssh
key-exchange-method
Configures the key-exchange methods that
can be used to establish an SSH connection.
Syntax
ip ssh
key-exchange-method
{
diffie-hellman-group-exchange-sha256
|
diffie-hellman-group14-sha256
|
diffie-hellman-group16-sha512
|
diffie-hellman-group18-sha512
|
curve25519-sha256@libssh.org
|
diffie-hellman-group14-sha1
|
ecdh-sha2-nistp256
|
ecdh-sha2-nistp384
|
ecdh-sha2-nistp521
|
curve25519-sha256
}no ip ssh key-exchange-method
{
diffie-hellman-group-exchange-sha256
|
diffie-hellman-group14-sha256
|
diffie-hellman-group16-sha512
|
diffie-hellman-group18-sha512
|
curve25519-sha256@libssh.org
|
diffie-hellman-group14-sha1
|
ecdh-sha2-nistp256
|
ecdh-sha2-nistp384
|
ecdh-sha2-nistp521
|
curve25519-sha256
}Command Default
By default, all methods are supported but do not show up in the running-configuration unless explicitly configured.
Modes
Global configuration mode
Usage Guidelines
One or more key exchange methods can be specified per command line.
The no form of the
command deactivates the specified key-exchange method or methods.
Use the show running-config
command to verify the system configuration.
History
The
ip ssh key-exchange-method dh-group14-sha256command and default setting are available in regular ICX mode beginning with FastIron release 09.0.00a.In FIPS mode, only the
ip ssh key-exchange-method dh-group14-sha256command configuration is supported. In Common Criteria (CC) mode, only theip ssh key-exchange-method dh-group14-sha1command configuration is supported.