<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CLI-Analyser needs ciphers added to fix this symptom? in Cisco CLI Analyzer</title>
    <link>https://community.cisco.com/t5/cisco-cli-analyzer/cli-analyser-needs-ciphers-added-to-fix-this-symptom/m-p/4791715#M575</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1443661"&gt;@MicJameson1&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;SPAN&gt;It surprises me that a mainstream commercial SSH client would have this issue.&lt;/SPAN&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I am using SecureCRT and DH is disabled by default.&amp;nbsp; If I see a message like that, I usually just put a tick in the SSH option for DH and it starts working.&lt;/P&gt;</description>
    <pubDate>Fri, 10 Mar 2023 23:42:47 GMT</pubDate>
    <dc:creator>Leo Laohoo</dc:creator>
    <dc:date>2023-03-10T23:42:47Z</dc:date>
    <item>
      <title>CLI-Analyser needs ciphers added to fix this symptom?</title>
      <link>https://community.cisco.com/t5/cisco-cli-analyzer/cli-analyser-needs-ciphers-added-to-fix-this-symptom/m-p/4790755#M570</link>
      <description>&lt;P&gt;Error shown in logs of ISR4321-K9, Version 16.06.04, when trying to use CLI-Analyser to SSH into it ...&lt;/P&gt;&lt;P&gt;Mar 9 20:32:45.675: %SSH-3-NO_MATCH: No matching kex algorithm found: client curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256 server diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1&lt;BR /&gt;--&lt;/P&gt;&lt;P&gt;ISR4321-K9#sh ip ssh&lt;BR /&gt;SSH Enabled - version 1.99&lt;BR /&gt;Authentication methods:publickey,keyboard-interactive,password&lt;BR /&gt;Authentication Publickey Algorithms:x509v3-ssh-rsa,ssh-rsa&lt;BR /&gt;Hostkey Algorithms:x509v3-ssh-rsa,ssh-rsa&lt;BR /&gt;Encryption Algorithms:aes128-ctr,aes192-ctr,aes256-ctr&lt;BR /&gt;MAC Algorithms:hmac-sha2-256,hmac-sha2-512,hmac-sha1,hmac-sha1-96&lt;BR /&gt;KEX Algorithms:diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1&lt;BR /&gt;Authentication timeout: 120 secs; Authentication retries: 1&lt;BR /&gt;Minimum expected Diffie Hellman key size : 2048 bits&lt;BR /&gt;IOS Keys in SECSH format(ssh-rsa, base64 encoded): TP-self-signed-(!! obfuscated !!)&lt;BR /&gt;ssh-rsa (!! obfuscated !!)&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Is this because CLI-analyzer is missing ciphers?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Must I update from SSH 1.99 to SSH 2.0 ?&lt;BR /&gt;&lt;STRONG&gt;Please fix this ASAP? May you please inform me here that this is fixed?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 22:19:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-cli-analyzer/cli-analyser-needs-ciphers-added-to-fix-this-symptom/m-p/4790755#M570</guid>
      <dc:creator>MicJameson1</dc:creator>
      <dc:date>2023-03-09T22:19:18Z</dc:date>
    </item>
    <item>
      <title>Re: CLI-Analyser needs ciphers added to fix this symptom?</title>
      <link>https://community.cisco.com/t5/cisco-cli-analyzer/cli-analyser-needs-ciphers-added-to-fix-this-symptom/m-p/4790771#M571</link>
      <description>&lt;P&gt;as i suggested another post - you have a cipher mismatch&amp;nbsp;&lt;/P&gt;
&lt;P&gt;read this log correctly :&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Mar 9 20:32:45.675: %SSH-3-NO_MATCH: No matching kex algorithm found: &lt;STRONG&gt;client&lt;/STRONG&gt; curve25519-sha256,curve25519-sha256@libssh.org,ecdh-sha2-nistp256,ecdh-sha2-nistp384,ecdh-sha2-nistp521,diffie-hellman-group-exchange-sha256,diffie-hellman-group16-sha512,diffie-hellman-group18-sha512,diffie-hellman-group14-sha256 &lt;STRONG&gt;server&lt;/STRONG&gt; diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;EDIT: IOS XE 16.6 is an old code try to upgrade to 17.X&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 22:47:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-cli-analyzer/cli-analyser-needs-ciphers-added-to-fix-this-symptom/m-p/4790771#M571</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-03-09T22:47:16Z</dc:date>
    </item>
    <item>
      <title>Re: CLI-Analyser needs ciphers added to fix this symptom?</title>
      <link>https://community.cisco.com/t5/cisco-cli-analyzer/cli-analyser-needs-ciphers-added-to-fix-this-symptom/m-p/4790772#M572</link>
      <description>&lt;P&gt;Wait .... The error message means the SSH client is not Deffie-Hellman but the router is expecting DH.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is not a code issue, this is an issue with the SSH client-side.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 22:49:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-cli-analyzer/cli-analyser-needs-ciphers-added-to-fix-this-symptom/m-p/4790772#M572</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2023-03-09T22:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: CLI-Analyser needs ciphers added to fix this symptom?</title>
      <link>https://community.cisco.com/t5/cisco-cli-analyzer/cli-analyser-needs-ciphers-added-to-fix-this-symptom/m-p/4791234#M573</link>
      <description>&lt;LI-CODE lang="markup"&gt;This is not a code issue, this is an issue with the SSH client-side. &lt;/LI-CODE&gt;
&lt;P&gt;I was not suggesting to upgrade IOS due to this issue, since i saw old IOS, so suggesting to upgrade to latest.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 11:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-cli-analyzer/cli-analyser-needs-ciphers-added-to-fix-this-symptom/m-p/4791234#M573</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-03-10T11:50:11Z</dc:date>
    </item>
    <item>
      <title>Re: CLI-Analyser needs ciphers added to fix this symptom?</title>
      <link>https://community.cisco.com/t5/cisco-cli-analyzer/cli-analyser-needs-ciphers-added-to-fix-this-symptom/m-p/4791543#M574</link>
      <description>&lt;P&gt;It surprises me that a mainstream commercial SSH client would have this issue.&lt;/P&gt;&lt;P&gt;Shouldn't a commercial SSH client just hold every reasonable cypher preference a mainstream box might require, such as&amp;nbsp;&lt;SPAN&gt;diffie-hellman-group-exchange-sha1, and diffie-hellman-group14-sha1 ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 15:54:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-cli-analyzer/cli-analyser-needs-ciphers-added-to-fix-this-symptom/m-p/4791543#M574</guid>
      <dc:creator>MicJameson1</dc:creator>
      <dc:date>2023-03-10T15:54:37Z</dc:date>
    </item>
    <item>
      <title>Re: CLI-Analyser needs ciphers added to fix this symptom?</title>
      <link>https://community.cisco.com/t5/cisco-cli-analyzer/cli-analyser-needs-ciphers-added-to-fix-this-symptom/m-p/4791715#M575</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1443661"&gt;@MicJameson1&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;SPAN&gt;It surprises me that a mainstream commercial SSH client would have this issue.&lt;/SPAN&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I am using SecureCRT and DH is disabled by default.&amp;nbsp; If I see a message like that, I usually just put a tick in the SSH option for DH and it starts working.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Mar 2023 23:42:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-cli-analyzer/cli-analyser-needs-ciphers-added-to-fix-this-symptom/m-p/4791715#M575</guid>
      <dc:creator>Leo Laohoo</dc:creator>
      <dc:date>2023-03-10T23:42:47Z</dc:date>
    </item>
    <item>
      <title>Re: CLI-Analyser needs ciphers added to fix this symptom?</title>
      <link>https://community.cisco.com/t5/cisco-cli-analyzer/cli-analyser-needs-ciphers-added-to-fix-this-symptom/m-p/4791823#M576</link>
      <description>&lt;P&gt;Due to security reasons some of the old ciphers fade&amp;nbsp; (one side people asking to move to the next level of security, once asking legacy cipher in the network ) - so one needs to make a decision on what needs to be used for their use case.&lt;/P&gt;
&lt;P&gt;As I mentioned earlier in another post - the CLI analyzer stopped releasing a new version, and it ended in&amp;nbsp;&lt;STRONG&gt;2021&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;I have also suggested some steps they recommend to ignore the options in the CLI analyser&amp;nbsp; - have you tried them?&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;(Note : I do not remember, there is some where option you can do, but try to download cli analyser - giving me error - will try again and let you know if I come across any findings)&lt;/P&gt;</description>
      <pubDate>Sat, 11 Mar 2023 10:45:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/cisco-cli-analyzer/cli-analyser-needs-ciphers-added-to-fix-this-symptom/m-p/4791823#M576</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2023-03-11T10:45:50Z</dc:date>
    </item>
  </channel>
</rss>

