Administrator Guide

Table Of Contents
Version Description
7.5.1.0 Introduced on the C-Series.
pre-6.1.1.0 Introduced on the E-Series.
Example
DellEMC# show ip ssh
SSH server : enabled.
SSH server version : v2.
SSH server vrf : default.
SSH server ciphers : aes256-ctr,aes256-cbc,aes192-ctr,aes192-
cbc,aes128-ctr,aes128-cbc,3des-cbc.
SSH server macs : hmac-sha2-256,hmac-sha1,hmac-sha1-96,hmac-
md5,hmac-md5-96.
SSH server kex algorithms : diffie-hellman-group-exchange-sha1,diffie-
hellman-group1-sha1,diffie-hellman-group14-sha1.
Password Authentication : enabled.
Hostbased Authentication : disabled.
RSA Authentication : disabled.
Challenge Response Auth : enabled.
Vty Encryption HMAC Remote IP
2 aes128-cbc hmac-md5 10.16.127.141
4 aes128-cbc hmac-md5 10.16.127.141
* 5 aes128-cbc hmac-md5 10.16.127.141
DellEMC#
Related
Commands
ip ssh server configures an SSH server.
show ip ssh client-pub-keys displays the client-public keys.
ssh
Open an SSH connection specifying the hostname, username, port number, and version of the SSH client.
Syntax
ssh {hostname|ipv4 address|ipv6 address} [-c encryption cipher|-l username|-
m HMAC alogorithm|-p port-number|-v 2]
Parameters
hostname (OPTIONAL) Enter the IP address or the hostname of the remote device.
ipv4 address (OPTIONAL) Enter the IP address in dotted decimal format A.B.C.D.
ipv6
addressprefix
(OPTIONAL) Enter the IPv6 address in the x:x:x:x::x format then the prefix length
in the /x format. The range is from /0 to /128
NOTE: The :: notation specifies successive hexadecimal fields of zeros.
-c encryption
cipher
Enter the following encryption cipher to use. (For v2 clients only.)
3des-cbc: Force ssh to use 3des-cbc encryption cipher.
FIPS mode is enabled or disabled:
aes256ctr: Force ssh to use the aes256ctr encryption cipher.
aes256cbc: Force ssh to use the aes128cbc encryption cipher.
aes192ctr: Force ssh to use the aes128cbc encryption cipher.
aes192cbc: Force ssh to use the aes256cbc encryption cipher.
aes128ctr: Force ssh to use the aes256cbc encryption cipher.
aes128cbc: Force ssh to use the aes128cbc encryption cipher.
3des-cbc: Force ssh to use 3des-cbc encryption cipher.
-l username (OPTIONAL) Enter the keyword l then the user name used in this SSH session.
The default is the user name of the user associated with the terminal.
-m HMAC
algorithm
Enter one of the following HMAC algorithms to use. (For v2 clients only.):
Without the FIPS mode enabled:
FIPS Cryptography 549