Can't find what you need?

• Ask the Community
• Create a Case
Reset Search



S-Series : Not able to setup SSH Session between S-Series and recent EXOS (22.5)

« Go Back


TitleS-Series : Not able to setup SSH Session between S-Series and recent EXOS (22.5)
  • SSH from switch to switch fails for S-Series to EXOS after EXOS upgrade to 22.5 or higher
  • S-Series error : no kex alg
  • EXOS error: Unable to negotiate with port 22: no matching key exchange method found. Their offer: diffie-hellman-group1-sha1,diffie-hellman-group-exchange-sha1
  • S-Series
  • Firmware 8.63.03
  • EXOS
  • Firmware 22.5 or higher
  • SSH client
EXOS 22.5 was released with the OpenSSH server and client upgraded from 6.5p1 to 7.5p1
Support for key exchange algorithms diffie-hellman-group14-sha256 (2,048 bits), diffie-hellmangroup16-sha512 (4,096 bits), and diffie-hellman-group18-sha512 (8,192 bits) is added Several weaker algorithms are disabled by default and this prevents switch to switch ssh (by default) between the S-Series and EXOS switches.
Upgrade S-Series to firmware 8.63.05

This release adds the following algorithm, which uses a 2048-bit key: diffie-hellman-group14-sha1
This change applies to both the SSH Server (i.e., SSH from somewhere else to the switch) and SSH Client (i.e., SSH from the switch to somewhere else). 


Set the dh-group to weaker groups on the EXOS to get things working with S-Series

# configure ssh2 dh-group minimum 1
Notice: The configured key exchange algorithm(s), DH group 1, is/are weaker than what is recommended.
Additional notes



Was this article helpful?



Please tell us how we can make this article more useful.

Characters Remaining: 255