cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
19005
Views
5
Helpful
11
Replies

To disable SSH Server CBC Mode Ciphers

WIN PHYO AUNG
Level 1
Level 1

 

Hi,

We use SSH v2 to login and manage the cisco switches.

But recently our internal security team did VA scan and found out the switches are using SSH Server CBC Mode Ciphers.

And they suggest to disable SSH Server CBC Mode Ciphers and enable CTR or GCM cipher mode encryption.

What is the default encryption mode cisco's ssh using?

Can anyone share if it is possible to disable and enable as they suggest?

 

 

Thanks

 

11 Replies 11

jchen20071024
Level 1
Level 1

Hi w.phyoaung,

I have the same question/problem as you but I noticed no one has offered a solution.  Were you able to find out how to disable the CBC mode cipher encryption and enable CTR or GCM?

 

Thanks

This question hasn't been answered yet??

It is available in newer IOS code. Here is my setting:
 ip ssh server algorithm encryption aes256-ctr aes192-ctr aes128-ctr

Great!  Thank you, Ted.  I understand the process now.

Wiley Winter

Dear Team,

 

How to fix this?

 

"disable CBC mode cipher encryption, and enable CTR or GCM cipher mode encryption"

 

Thanks,

Shoaib

@ted.schwind Will i loose my ssh connection if i add below command. Pls help

 

 ip ssh server algorithm encryption aes256-ctr aes192-ctr aes128-ctr

I didn't lose my connection.

@ted.schwind Thank you buddy for replying. Basically im going to apply this command on Cisco Asa and i believe both asa and switch have same ssh working mechanism.

@ted.schwind Can you pls help me regarding my query

Alvaro Rugama
Level 1
Level 1

I also have the same question.

 

Cannot find any information about this.

 

Best Regards.

enablecomp
Level 1
Level 1

I'm having the same issue for the same reason.  Anyone found anything on this?

Review Cisco Networking products for a $25 gift card