Fortinet white logo
Fortinet white logo

Handbook

6.0.0

Encryption strength for proxied SSH sessions

Encryption strength for proxied SSH sessions

The level of SSH encryption can be set for SSH sessions on a per-profile basis.

Encryption Level Description
compatible This level allows for a broader set of encryption algorithms to be used and is better for compatibility.
high-encryption This level will only allow AES-CTR, AES-GCM and high encryption algorithms to be used for the session.
Syntax:

config firewall ssl-ssh-profile

edit <profile name>

config ssh

set ssh-algorithm {compatible|high-encryption}

end

end

Encryption strength for proxied SSH sessions

Encryption strength for proxied SSH sessions

The level of SSH encryption can be set for SSH sessions on a per-profile basis.

Encryption Level Description
compatible This level allows for a broader set of encryption algorithms to be used and is better for compatibility.
high-encryption This level will only allow AES-CTR, AES-GCM and high encryption algorithms to be used for the session.
Syntax:

config firewall ssl-ssh-profile

edit <profile name>

config ssh

set ssh-algorithm {compatible|high-encryption}

end

end