12-09-2021 02:35 PM
Do the ICX 7450/7750 series switches support high encryption (i.e. SHA256) for SSH and NTP connections?
Solved! Go to Solution.
12-09-2021 02:52 PM
Hey Joseph,
In terms of non-FIPS (normal) mode, SHA256 was added for SSH in 9000a via:
ICX(config)#ip ssh key-exchange-method dh-group14-sha256
I do not believe it is available for NTP in any release.
If you are running FIPS mode, SHA256 will be used by default for SSH. With that said, FIPS is going to lock down the box quite a bit, so I would make sure you 100% want to go down that route before enabling that mode:
https://support.ruckuswireless.com/documents/3026-fastiron-08-0-90-ga-fips-common-criteria-guide
I should note we are still recommending 8090 code stream at this time, but if you are specifically looking for SHA256 for SSH while in non-FIPS mode, you would need to run 9.x .
12-09-2021 02:52 PM
Hey Joseph,
In terms of non-FIPS (normal) mode, SHA256 was added for SSH in 9000a via:
ICX(config)#ip ssh key-exchange-method dh-group14-sha256
I do not believe it is available for NTP in any release.
If you are running FIPS mode, SHA256 will be used by default for SSH. With that said, FIPS is going to lock down the box quite a bit, so I would make sure you 100% want to go down that route before enabling that mode:
https://support.ruckuswireless.com/documents/3026-fastiron-08-0-90-ga-fips-common-criteria-guide
I should note we are still recommending 8090 code stream at this time, but if you are specifically looking for SHA256 for SSH while in non-FIPS mode, you would need to run 9.x .
12-09-2021 10:06 PM
Thank You.
It looks like v9000a does not currently support ICX7750. Are there plans to continue updating that model further?
12-09-2021 10:51 PM
Sorry about that! 8095 will be the last supported code stream for the ICX7750. It will be maintained for the foreseeable future.
06-17-2024 08:33 AM
Hello Ben, you provided the command for 9000a but will you be so kind as to provide the command for 8095