Technical Tip: Unable to SSH into managed Switch from FIPS-CC enabled FortiOS
| Description | This article describes the reason why it is impossible to SSH into a managed switch from a FIPS-CC-enabled FortiOS. |
| Scope | FortiOS FIPS-CC. |
| Solution | Unable to SSH managed FortiSwitch from FIPS-enabled FortiOS:
Unable to negotiate with 10.0.1.2: no matching key exchange method found. Their offer: curve25519-sha256@libssh.org,diffie-hellman-
FIPS-CC heavily restricts the list of allowed encryption ciphers, HMAC, and Key Exchange options available for encrypted services. In the case of SSH, AES128-CBC, and AES256-CBC are the only available options allowed by FIPS-CC/140-2. This is not a Fortinet-based limitation, but rather a limitation in the standards set by FIPS-CC/140-2 and NDcPP. Fortinet only supports Federal Information Processing Standard Publication (FIPS) 140-2 (Level 2) for the following managed FortiSwitch models:
|

