cancel
Showing results for 
Search instead for 
Did you mean: 

ICX High Encryption

joseph_coleman
New Contributor

Do the ICX 7450/7750 series switches support high encryption (i.e. SHA256) for SSH and NTP connections?

1 ACCEPTED SOLUTION

BenBeck
Moderator
Moderator

Hey Joseph, 

In terms of non-FIPS (normal) mode, SHA256 was added for SSH in 9000a via:

ICX(config)#ip ssh key-exchange-method dh-group14-sha256

I do not believe it is available for NTP in any release.

If you are running FIPS mode, SHA256 will be used by default for SSH. With that said, FIPS is going to lock down the box quite a bit, so I would make sure you 100% want to go down that route before enabling that mode:

https://support.ruckuswireless.com/documents/3026-fastiron-08-0-90-ga-fips-common-criteria-guide

I should note we are still recommending 8090 code stream at this time, but if you are specifically looking for SHA256 for SSH while in non-FIPS mode, you would need to run 9.x .

Ben Beck, RCNA, RCNI, Principal Technical Support Engineer
support.ruckuswireless.com/contact-us

View solution in original post

4 REPLIES 4

BenBeck
Moderator
Moderator

Hey Joseph, 

In terms of non-FIPS (normal) mode, SHA256 was added for SSH in 9000a via:

ICX(config)#ip ssh key-exchange-method dh-group14-sha256

I do not believe it is available for NTP in any release.

If you are running FIPS mode, SHA256 will be used by default for SSH. With that said, FIPS is going to lock down the box quite a bit, so I would make sure you 100% want to go down that route before enabling that mode:

https://support.ruckuswireless.com/documents/3026-fastiron-08-0-90-ga-fips-common-criteria-guide

I should note we are still recommending 8090 code stream at this time, but if you are specifically looking for SHA256 for SSH while in non-FIPS mode, you would need to run 9.x .

Ben Beck, RCNA, RCNI, Principal Technical Support Engineer
support.ruckuswireless.com/contact-us

@ben_beck 


Thank You.

It looks like v9000a does not currently support ICX7750. Are there plans to continue updating that model further?

Sorry about that! 8095 will be the last supported code stream for the ICX7750. It will be maintained for the foreseeable future.

Ben Beck, RCNA, RCNI, Principal Technical Support Engineer
support.ruckuswireless.com/contact-us

Dejeh1
New Contributor

Hello Ben, you provided the command for 9000a but will you be so kind as to provide the command for 8095