Skip to main content
kajlasunil
Staff
Staff
September 27, 2024

Technical Tip: Unable to SSH into managed Switch from FIPS-CC enabled FortiOS

  • September 27, 2024
  • 0 replies
  • 1025 views
Description This article describes the reason why it is impossible to SSH into a managed switch from a FIPS-CC-enabled FortiOS.
Scope FortiOS FIPS-CC. 
Solution

Unable to SSH managed FortiSwitch from FIPS-enabled FortiOS:

 

4.PNG

 

Unable to negotiate with 10.0.1.2: no matching key exchange method found. Their offer: curve25519-sha256@libssh.org,diffie-hellman-
group-exchange-sha256

 

FIPS-CC heavily restricts the list of allowed encryption ciphers, HMAC, and Key Exchange options available for encrypted services. In the case of SSH, AES128-CBC, and AES256-CBC are the only available options allowed by FIPS-CC/140-2. This is not a Fortinet-based limitation, but rather a limitation in the standards set by FIPS-CC/140-2 and NDcPP.

Due to the FIPS-CC mode, it is not possible to make changes to the Cipher.

Fortinet only supports Federal Information Processing Standard Publication (FIPS) 140-2 (Level 2) for the following managed FortiSwitch models:

  • FS-424E.
  • FS-424E-FPOE.
  • FS-M426E-FPOE.
  • FS-424E-Fiber.
  • FS-448E.
  • FS-448E-FPOE.
  • FS-1048E.
  • FS-3032E.