Boot Options
146
Basic System Configuration Guide
3HE 11010 AAAC TQZZA Edition: 01
5.1.3.2 SSH2 Approved Algorithms in FIPS-140-2 Mode
SSH1 is not supported in FIPS-140-2 mode and is therefore blocked from
configuration; only SSH2 is supported. The following algorithms, configured using
the client-cipher-list or server-cipher-list command, are available for SSH2 when
the node is running in FIPS-140-2 mode:
• aes128-cbc
•3des-cbc
• aes192-cbc
• aes256-cbc
The following algorithms are not available for SSH2 when the node is running in
FIPS-140-2 mode:
•blowfish-cbc
• cast128-cbc
• arcfour
• rijndael-cbc
Table 20 Data Path Algorithms
FIPS-140-2
Data Path
Algorithms
SSH2 IPSec NGE/L3
Encryption
SNMPv3 SCP, SFTP IGP,
BGP,
MPLS
Authentication N/A N/A N/A N/A N/A N/A
Asymmetric
Key
N/A N/A N/A N/A N/A N/A
Symmetric
Key
N/A AES-CBC
(128,192, 256)
3DES-CBC
AES-CBC
(128, 256)
N/A N/A N/A
Hash
Algorithm
N/A SHA-1 (128)
SHA-2
(256, 384, 512)
N/A N/A N/A N/A