cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
883
Views
0
Helpful
6
Replies

SSH weak algorithm (cat4500e-IPBASEK9-M)

BernardNdale
Level 1
Level 1

Dears,

 I am having vulnerabilities issue with SSH weak algorithm.
Can someone help how to change algorithm used by SSH on Cisco Switch Cat4500

IOS : Version 15.0(2)SG

Rommon : 12.2

6 Replies 6

Reza Sharifi
Hall of Fame
Hall of Fame

Hi,

If the encryption is too weak, you can make it stronger with this command:

crypto key generate rsa modulus <360-4096>

 

Have a look at the config guide:

 

https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst4500/XE3-8-0E/15-24E/configuration/guide/xe-380-configuration/x509v3.html

HTH

balaji.bandi
Hall of Fame
Hall of Fame

I am having a vulnerabilities issue with SSH weak algorithm.  - what vulnerability you got now. Do you have SSH with version 2 ?

 

show post  - show run | in ssh and show ip ssh

 

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Yes I have disabled SSHv1 and enable SSHv2 but vulnerability still persists

Can you post the example of  "vulnerability still persists"

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

BernardNdale
Level 1
Level 1

I tried to increse the length of Key the observe next scan result.

Thanks for support !

Sure, but check the device overhead also before increasing the higher level.

BB

=====Preenayamo Vasudevam=====

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help