Specifications

Alcatel-Lucent Page 31
OmniSwitch 6850 Series
SSHv2 4.1.2
SSHv2 for secure CLI session with PKI is also
supported
The OmniSwitch Secure Shell feature provides a secure mechanism that allows you to log in to a
remote switch, to execute commands on a remote device, and to move files from one device to another.
Secure Shell provides secure, encrypted communications even when your transmission is between two
untrusted hosts or over an un-secure network.
The OmniSwitch includes both client and server components of the Secure Shell interface and the
Secure Shell FTP file transfer protocol. SFTP is a subsystem of the Secure Shell protocol. All Secure
Shell FTP data are encrypted through a Secure Shell channel.
Secure Shell protects against a variety of security risks including the following:
• IP spoofing
• IP source routing
• DNS spoofing
• Interception of clear-text passwords and other data by intermediate hosts
• Manipulation of data by users on intermediate hosts
Note. The OmniSwitch supports Secure Shell Version 2 only.
Algorithm and key Exchange:
One or several host-specific DSA keys identify the OmniSwitch Secure Shell server. Both the client
and server process the key exchange to choose a common algorithm for encryption, signature, and
compression. This key exchange is included in the Secure Shell transport layer protocol. It uses a key
agreement to produce a shared secret that cannot be determined by either the client or the server alone.
The key exchange is combined with a signature and the host key to provide host authentication. Once
the exchange is completed, the client and the server turn encryption on using the selected algorithm
and key. The following elements are supported:
Host key Type: DSA
Cipher Algorithms; AES, Blowfish, Cast, 3DES, Arcfour, and Rijndael
Signature Algorithms: MD5, and SHA1
Compression Algorithms: None-supported
Key Exchange Algorithms:
Diffie-hellman-group-exchange-shal
Diffie-hellman-group1-shal
When used as an SSH Server, the following SSH Software is supported:
OpenSSH: Sun Solaris, Win NT + Cygwin, Mac OSX, Linux Red Hat
F-Secure: Sun Solaris, Win 2000, Win NT, Win XP, Mac OS9
SSH-Communication: Sun Solaris, Win 2000, Win NT, Win XP, Linux Red Hat
PuTTY: Win 2000, Win NT, Win XP, Mac OS9
MAC-SSH: Mac OS9, Mac OSX
When used as an SSH Client, the following SSH Software is supported:
OpenSSH: Sun Solaris, Win NT + Cygwin, Linux Red Hat, AOS
F-Secure: Sun Solaris, Win 2000, Win NT
SSH-Communication: Sun Solaris, Win 2000, Win NT, Win XP, Linux Red Hat