Can't find what you need?


• Ask the Community
• Create a Case
Reset Search
 

 

Article

S-Series : Not able to setup SSH Session between S-Series and recent EXOS (22.5)

« Go Back

Information

 
TitleS-Series : Not able to setup SSH Session between S-Series and recent EXOS (22.5)
Symptoms
  • SSH from switch to switch fails for S-Series to EXOS after EXOS upgrade to 22.5 or higher
  • S-Series error : no kex alg
  • EXOS error: Unable to negotiate with 10.152.40.16 port 22: no matching key exchange method found. Their offer: diffie-hellman-group1-sha1,diffie-hellman-group-exchange-sha1
Environment
  • S-Series
  • Firmware 8.63.03
  • EXOS
  • Firmware 22.5 or higher
  • SSH client
Cause
EXOS 22.5 was released with the OpenSSH server and client upgraded from 6.5p1 to 7.5p1
Support for key exchange algorithms diffie-hellman-group14-sha256 (2,048 bits), diffie-hellmangroup16-sha512 (4,096 bits), and diffie-hellman-group18-sha512 (8,192 bits) is added Several weaker algorithms are disabled by default and this prevents switch to switch ssh (by default) between the S-Series and EXOS switches.
Resolution
Under Investigation for S-Series to support stronger algorithms 

Workaround:

Set the dh-group to weaker groups on the EXOS to get things working with S-Series

 
# configure ssh2 dh-group minimum 1
Notice: The configured key exchange algorithm(s), DH group 1, is/are weaker than what is recommended.
Additional notes

Feedback

 

Was this article helpful?


   

Feedback

Please tell us how we can make this article more useful.

Characters Remaining: 255