Setup Guide
• die-hellman-group1-sha1
• die-hellman-group14-sha1
When FIPS is enabled, the default is die-hellman-group14-sha1.
Example of Conguring a Key Exchange Algorithm
The following example shows you how to congure a key exchange algorithm.
DellEMC(conf)# ip ssh server kex diffie-hellman-group-exchange-sha1 diffie-hellman-group14-sha1
Conguring the HMAC Algorithm for the SSH Server
To congure the HMAC algorithm for the SSH server, use the ip ssh server mac hmac-algorithm command in 
CONFIGURATION mode.
hmac-algorithm: Enter a space-delimited list of keyed-hash message authentication code (HMAC) algorithms supported by the SSH 
server.
The following HMAC algorithms are available:
• hmac-md5
• hmac-md5-96
• hmac-sha1
• hmac-sha1-96
• hmac-sha2-256
The default HMAC algorithms are the following:
• hmac-sha2-256
• hmac-sha1
• hmac-sha1-96
• hmac-md5
• hmac-md5-96
When FIPS is enabled, the default HMAC algorithm is hmac-sha2-256,hmac-sha1,hmac-sha1-96.
Example of Conguring a HMAC Algorithm
The following example shows you how to congure a HMAC algorithm list.
DellEMC(conf)# ip ssh server mac hmac-sha1-96 
Conguring the SSH Server Cipher List
To congure the cipher list supported by the SSH server, use the ip ssh server cipher cipher-list command in CONFIGURATION 
mode.
cipher-list-: Enter a space-delimited list of ciphers the SSH server will support.
Security
867










