07-19-2023 10:52 AM - edited 07-19-2023 10:59 AM
I am seeing issues with no matching SSH Key Exchange Algorithm (KEX) when attempting to SSH to/from an ICX with 9.0.10e and ICXs with 8.0.90k or 8.0.95g firmware. I turned on debug for ssh on both ICXs and what I found is the following....
ICX 8.0.90k SSH to ICX 9.0.10e and I get no matching key exchange method found. Their offer diffie-hellman-group14-sha1, diffie-hellman-group1-sha1
ICX 9.0.10e SSH to ICX 8.0.90k and I get SSH: KEX Algorithm no match found
I thought that FI 9.0.10e supports diffie-hellman-group14-sha1 by default?
The end result is that any non-9.0.10e ICXs can ssh to each other, and 9.0.10e ICXs can ssh to each other, but you cannot ssh between the versions because SSH KEX issue.
07-16-2024 07:35 AM
Hey Ben,
Thanks for the reply! I put this into the 10.x switch and still getting outbound connection failed. If you'd like, I can show debug results / any other command results that may help.