Access Security Guide K/KA/KB.15.15

aes192-cbc
aes256-cbc
aes128-ctr
aes192-ctr
aes256-ctr
Default: All cipher types are available.
NOTE: For the 3800, 5400zl, and 8200zl switches, when the switch is in
enhanced secure mode, there are fewer cipher options. The ciphers 3des-cbc is not
available. See “Secure Mode (3800, 5400zl, and 8200zl Switches)” (page 498).
Use the no form of the command to disable a cipher type.
[filetransfer]
Enable/disable secure file transfer capability. SCP and SFTP secure file transfer will
not function unless SSH is also enabled.
[ ip-version <4 | 6 | 4or6> ]
Select the IP mode to run in. The mode "ip-version 4" only accepts connections from
IPv4 clients. The mode "ip-version 6" only accepts connections from IPv6 clients.
The mode "ip-version 4or6" accepts connections from both IPv4 and IPv6 clients.
Default: ip-version 4 or 6
[ mac <mactype> ]
Allows configuration of the set of MACs that can be selected. Valid types are:
hmac-md5
hmac-sha1
hmac-sha1-96
hmac-md5-96
Default: All MAC types are available.
NOTE: For the 3800, 5400zl, and 8200zl switches, when the switch is in
enhanced secure mode, there are fewer cipher options. The ciphers 3des-cbc is not
available. See “Secure Mode (3800, 5400zl, and 8200zl Switches)” (page 498).
Use the no form of the command to disable a MAC type.
[ port <1-65535 | default> ]
The TCP port number for SSH connections.
Default: 22.
[ timeout <5-120> ]
Sets the maximum length of time (in seconds) allowed for initial protocol negotiation
and authentication.
Default: 120 seconds
234 Secure Shell (SSH)