10-30-2024 07:17 AM
I read other discussion on this topic however my case might be different because of the type of hardware used. I recently upgraded the IOS on 3560CX switch to 15.2(7)E10 as recommended by the cybersecurity team. The solution I read on this topic is to update the key exchange algorithm, however it only gives two algorithm which are included on the list of Nessus being flag. Redacted show command result below. Is there a other way to disable the key exchange?
SSH Enabled - version 2.0
Encryption Algorithms:aes256-ctr,aes192-ctr,aes128-ctr
MAC Algorithms:hmac-sha2-512,hmac-sha2-256
KEX Algorithms:diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1
Authentication timeout: 60 secs; Authentication retries: 5
Minimum expected Diffie Hellman key size : 2048 bits
Solved! Go to Solution.
10-30-2024 07:28 AM
This device is too old for up-to-date algorithms.
https://community.cisco.com/t5/security-knowledge-base/guide-to-better-ssh-security/ta-p/3133344
10-30-2024 07:28 AM
This device is too old for up-to-date algorithms.
https://community.cisco.com/t5/security-knowledge-base/guide-to-better-ssh-security/ta-p/3133344
10-30-2024 07:30 AM
moved to Switching as you posted in Email Security
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide