In SGOS versions 6.5.x and 6.2.x, you cannot make changes to SSH ciphers and HMAC algorithms. In SGOS 126.96.36.199, two commands were introduced to allow you to manage these ciphers and algorithms.
To manage SSH ciphers, from configure mode, type:#(config)ssh-console#(config ssh-console)ciphers
To manage HMAC algorithms, from configure mode, type:#(config)ssh-console#(config ssh-console)hmacs
SSH cipher and HMACs support is updated when the appliance is in FIPS mode:
- AES-CBC ciphers (aes128-cbc and aes256-cbc) are unsupported.
- AES-GCM ciphers ([email protected] and [email protected]) are supported.
- hmac-sha1-96 is unsupported.
- hmac-sha2-256 and hmac-sha2-512 are supported.