<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ICX w/FI 9.0.10e SSH KEX Not Matching with ICX w/FI 8.0.90k in ICX Switches</title>
    <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/63452#M4492</link>
    <description>&lt;P&gt;Hey Kenneth,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe this is expected due to upgraded SSH in 9010d and onward. I think you can enable EC (elliptical key pair) on both ends as a workaround. I am not in front of a CLI right this second, but it should be something like this:&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;crypto key gen ec (tab through this for syntax options)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jul 2023 18:50:21 GMT</pubDate>
    <dc:creator>BenBeck</dc:creator>
    <dc:date>2023-07-19T18:50:21Z</dc:date>
    <item>
      <title>ICX w/FI 9.0.10e SSH KEX Not Matching with ICX w/FI 8.0.90k</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/63447#M4490</link>
      <description>&lt;P&gt;I am seeing issues with no matching SSH Key Exchange Algorithm (KEX) when attempting to SSH to/from an ICX with 9.0.10e and ICXs with 8.0.90k or 8.0.95g firmware.&amp;nbsp; I turned on debug for ssh on both ICXs and what I found is the following....&lt;/P&gt;&lt;P&gt;ICX 8.0.90k SSH to ICX 9.0.10e and I get no matching key exchange method found. Their offer diffie-hellman-group14-sha1, diffie-hellman-group1-sha1&lt;/P&gt;&lt;P&gt;ICX 9.0.10e SSH to ICX 8.0.90k and I get SSH: KEX Algorithm no match found&lt;/P&gt;&lt;P&gt;I thought that FI 9.0.10e supports diffie-hellman-group14-sha1 by default?&lt;/P&gt;&lt;P&gt;The end result is that any non-9.0.10e ICXs can ssh to each other, and 9.0.10e ICXs can ssh to each other, but you cannot ssh between the versions because SSH KEX issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 17:59:02 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/63447#M4490</guid>
      <dc:creator>KennethDelaney</dc:creator>
      <dc:date>2023-07-19T17:59:02Z</dc:date>
    </item>
    <item>
      <title>Re: ICX w/FI 9.0.10e SSH KEX Not Matching with ICX w/FI 8.0.90k</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/63452#M4492</link>
      <description>&lt;P&gt;Hey Kenneth,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe this is expected due to upgraded SSH in 9010d and onward. I think you can enable EC (elliptical key pair) on both ends as a workaround. I am not in front of a CLI right this second, but it should be something like this:&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;crypto key gen ec (tab through this for syntax options)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 18:50:21 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/63452#M4492</guid>
      <dc:creator>BenBeck</dc:creator>
      <dc:date>2023-07-19T18:50:21Z</dc:date>
    </item>
    <item>
      <title>Re: ICX w/FI 9.0.10e SSH KEX Not Matching with ICX w/FI 8.0.90k</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/63462#M4493</link>
      <description>&lt;P&gt;I configured two ICXs with #crypto key generate ec label testkey (default size = 384).&amp;nbsp; I still cannot negotiate session between the two ICXs, one with 9.0.10f and one with 8.0.90k.&amp;nbsp; I have not done any debugging yet.&lt;/P&gt;&lt;P&gt;Can I have both an rsa and ec key pair at the same time?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 19:15:01 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/63462#M4493</guid>
      <dc:creator>KennethDelaney</dc:creator>
      <dc:date>2023-07-19T19:15:01Z</dc:date>
    </item>
    <item>
      <title>Re: ICX w/FI 9.0.10e SSH KEX Not Matching with ICX w/FI 8.0.90k</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/63463#M4494</link>
      <description>&lt;P&gt;You can. 'show ip ssh config' should confirm. Can you try removing the non-EC?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 19:17:00 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/63463#M4494</guid>
      <dc:creator>BenBeck</dc:creator>
      <dc:date>2023-07-19T19:17:00Z</dc:date>
    </item>
    <item>
      <title>Re: ICX w/FI 9.0.10e SSH KEX Not Matching with ICX w/FI 8.0.90k</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/63464#M4495</link>
      <description>&lt;P&gt;When I do "sh ip ssh config" I see two host keys (RSA 2048, ECDSA) with 9.0.10f but with 8.0.90k I see only one host key (RSA2048) even though I see "crypto key generate ec label testkey" in the running config. So, for 8.0.90k it looks like it can only have one host key.&amp;nbsp; I don't want to delete the rsa key at the moment since this is operational switch.&amp;nbsp; I may have to do further testing in a Lab unless you have other recommendations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 19:26:53 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/63464#M4495</guid>
      <dc:creator>KennethDelaney</dc:creator>
      <dc:date>2023-07-19T19:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: ICX w/FI 9.0.10e SSH KEX Not Matching with ICX w/FI 8.0.90k</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/64253#M4538</link>
      <description>&lt;P&gt;With 8.0.9x firmware I zeroized the RSA key so there should only now be the EC key, even though it doesn't display under #sh ip ssh config, and whenever I try to ssh between 8.0.9x and 9.0.10e/f it never connects because the 8.0.9x ssh negotiation is looking for RSA, not EC.&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 13:40:09 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/64253#M4538</guid>
      <dc:creator>KennethDelaney</dc:creator>
      <dc:date>2023-07-24T13:40:09Z</dc:date>
    </item>
    <item>
      <title>Re: ICX w/FI 9.0.10e SSH KEX Not Matching with ICX w/FI 8.0.90k</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/64260#M4543</link>
      <description>&lt;P&gt;Hey Kenneth,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I checked on this. It is a known limitation. We upgraded to openssh in 9+ (different SSH prior to this). This actually breaks switch-to-switch SSH capability if going between 8.x and 9+. In order to do switch-to-switch, you will need to be on all 8.x or all 9+. With that said, you should have no problem using a regular SSH client (putty, teraterm, etc.) to manage your switches.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Jul 2023 14:23:08 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/64260#M4543</guid>
      <dc:creator>BenBeck</dc:creator>
      <dc:date>2023-07-24T14:23:08Z</dc:date>
    </item>
    <item>
      <title>Re: ICX w/FI 9.0.10e SSH KEX Not Matching with ICX w/FI 8.0.90k</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/72765#M5040</link>
      <description>&lt;P&gt;Hi KennethDelaney&lt;/P&gt;&lt;P&gt;Adding to the post. The outbound SSH connection problem between 8095 and 9010 and above version is fixed in version 9010j and 10.0.10c&lt;/P&gt;&lt;P&gt;Please note there is no need for you to upgrade any devices which are running 8095 version but you might have to wait to upgrade the 8200 switches to 10.0.10c version or if you have devices running on 9010 versions they would be fixed in 9010j version&lt;/P&gt;&lt;P&gt;You might have to wait for release of 10.0.10c and 9010j version.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Dec 2023 10:26:34 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/72765#M5040</guid>
      <dc:creator>Chandini</dc:creator>
      <dc:date>2023-12-08T10:26:34Z</dc:date>
    </item>
    <item>
      <title>Re: ICX w/FI 9.0.10e SSH KEX Not Matching with ICX w/FI 8.0.90k</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/88990#M6012</link>
      <description>&lt;P&gt;Hi Chandini,&lt;/P&gt;&lt;P&gt;Just ran into this issue and found this thread. I upgraded a switch to 10.0.10c and still can't SSH between 10.0.10c and 8.0.95h. Strangely, the "debug ip ssh" command isn't even a usable command on the switch running 10.0.10c, and the "show who" command doesn't even show my ssh connection. Any ideas?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 18:42:58 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/88990#M6012</guid>
      <dc:creator>belsbree</dc:creator>
      <dc:date>2024-07-15T18:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: ICX w/FI 9.0.10e SSH KEX Not Matching with ICX w/FI 8.0.90k</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/88992#M6013</link>
      <description>&lt;P&gt;Hey there,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the 10.x switch, you will need to allow the connection and add these commands:&lt;/P&gt;
&lt;P&gt;ICX(config)#ip ssh host-key-method ssh-rsa&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jul 2024 19:03:24 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/88992#M6013</guid>
      <dc:creator>BenBeck</dc:creator>
      <dc:date>2024-07-15T19:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: ICX w/FI 9.0.10e SSH KEX Not Matching with ICX w/FI 8.0.90k</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/89458#M6027</link>
      <description>&lt;P&gt;Hey Ben,&lt;/P&gt;&lt;P&gt;Thanks for the reply! I put this into the 10.x switch and still getting outbound connection failed. If you'd like, I can show debug results / any other command results that may help.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jul 2024 14:35:24 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/ICX-w-FI-9-0-10e-SSH-KEX-Not-Matching-with-ICX-w-FI-8-0-90k/m-p/89458#M6027</guid>
      <dc:creator>belsbree</dc:creator>
      <dc:date>2024-07-16T14:35:24Z</dc:date>
    </item>
  </channel>
</rss>

