cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1145
Views
0
Helpful
2
Replies

sha2 on CISCO C9200L-48T

Zhanali
Level 1
Level 1

Hello everybody!

 

We have C9200 version 16.12.4 on the network, and we cannot disable sha1 based key exchange algorithms there. And a new C9200 version 17.3.3 and there we can configure ecdh-sha2-nistp256, ecdh-sha2-nistp384 and ecdh-sha2-nistp521.


The question is, if I update C9200 from version 16.12.4 to version 17.3.3, will it be possible to disable sha1 based key exchange algorithms and enable more stable algorithms?
And how can I find out from which version of the switch sha2 will be supported?

 

Thanks!

2 Replies 2

marce1000
VIP
VIP

 

 - Ref : https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9200/software/release/17-3/configuration_guide/sec/b_173_sec_9200_cg/m9_173_sec_ssh_algorithms_cg.html#concept_hmm_gvw_xmb

  no longer mentions sha1 , presuming it is no longer present in contrast too :

         https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9200/software/release/16-12/configuration_guide/sec/b_1612_sec_9200_cg/m9_1612_sec_secure_shell_algorithms_cg.html#concept_hmm_gvw_xmb

 

  - Have a look at the fist document further , to find out , for instance how to change order of the preferred ciphers.

 

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Thanks, but I wanted to know exactly about the key exchange (KEX) algorithms. More details:

 

17.3.3 version:

Switch Ports Model              SW Version        SW Image              Mode   
------ ----- -----              ----------        ----------            ----   
     1 32    C9200-24T          17.03.03          CAT9K_LITE_IOSXE      INSTALL
*    2 32    C9200-24T          17.03.03          CAT9K_LITE_IOSXE      INSTALL


Switch 01
---------
Switch uptime                      : 6 weeks, 6 days, 18 hours, 23 minutes 

Base Ethernet MAC Address          : 
Motherboard Assembly Number        : 
Motherboard Serial Number          : 
Model Revision Number              : C1
Motherboard Revision Number        : B0
Model Number                       : C9200-24T
System Serial Number               : 
Last reload reason                 : Power Failure or Unknown
CLEI Code Number                   : 

Configuration register is 0x102
          
AHBKZSHYSWT01-02(config)#ip ssh ser al kex ?
  diffie-hellman-group14-sha1  DH_GRP14_SHA1 diffie-hellman key exchange algorithm
  ecdh-sha2-nistp256           ECDH_SHA2_P256 ecdh key exchange algorithm
  ecdh-sha2-nistp384           ECDH_SHA2_P384 ecdh key exchange algorithm
  ecdh-sha2-nistp521           ECDH_SHA2_P521 ecdh key exchange algorithm

16.12.4 version:

Switch Ports Model              SW Version        SW Image              Mode   
------ ----- -----              ----------        ----------            ----   
     1 52    C9200L-48T-4G      16.12.4           CAT9K_LITE_IOSXE      INSTALL
*    2 52    C9200L-48T-4G      16.12.4           CAT9K_LITE_IOSXE      INSTALL


Switch 01
---------
Switch uptime                      : 12 weeks, 4 days, 21 hours, 46 minutes 

Base Ethernet MAC Address          : 
Motherboard Assembly Number        : 
Motherboard Serial Number          : 
Model Revision Number              : G0
Motherboard Revision Number        : A0
Model Number                       : C9200L-48T-4G
System Serial Number               : 
Last reload reason                 : Image Install

Configuration register is 0x102

AHB-KAZ-DMZ(config)#ip ssh ser alg kex ?
  diffie-hellman-group-exchange-sha1  DH_GRPX_SHA1 diffie-hellman key exchange algorithm
  diffie-hellman-group14-sha1         DH_GRP14_SHA1 diffie-hellman key exchange algorithm

.

Review Cisco Networking for a $25 gift card