The following example configures the time-based rekey threshold for an SSH session to 30 minutes.
Dell(conf)#ip ssh rekey time 30
The following example configures the volume-based rekey threshold for an SSH session to 4096
megabytes.
Dell(conf)#ip ssh rekey volume 4096
Configuring the SSH Server Key Exchange Algorithm
To configure the key exchange algorithm for the SSH server, use the ip ssh server kex key-
exchange-algorithm command in CONFIGURATION mode.
key-exchange-algorithm : Enter a space-delimited list of key exchange algorithms that will be used by
the SSH server.
The following key exchange algorithms are available:
• diffie-hellman-group-exchange-sha1
• diffie-hellman-group1-sha1
• diffie-hellman-group14-sha1
The default key exchange algorithms are the following:
• diffie-hellman-group-exchange-sha1
• diffie-hellman-group1-sha1
• diffie-hellman-group14-sha1
When FIPS is enabled, the default is diffie-hellman-group14-sha1.
Example of Configuring a Key Exchange Algorithm
The following example shows you how to configure a key exchange algorithm.
Dell(conf)# ip ssh server kex diffie-hellman-group-exchange-sha1 diffie-
hellman-group14-sha1
Configuring the HMAC Algorithm for the SSH Server
To configure the HMAC algorithm for the SSH server, use the ip ssh server mac hmac-algorithm
command in CONFIGURATION mode.
hmac-algorithm: Enter a space-delimited list of keyed-hash message authentication code (HMAC)
algorithms supported by the SSH server.
The following HMAC algorithms are available:
• hmac-md5
• hmac-md5-96
• hmac-sha1
Security 803