| Description | This article describes the reason why it is impossible to SSH into a managed switch from a FIPS-CC-enabled FortiOS. |
| Scope | FortiOS FIPS-CC. |
| Solution |
Unable to SSH managed FortiSwitch from FIPS-enabled FortiOS:
Unable to negotiate with 10.0.1.2: no matching key exchange method found. Their offer: curve25519-sha256@libssh.org,diffie-hellman-
FIPS-CC heavily restricts the list of allowed encryption ciphers, HMAC, and Key Exchange options available for encrypted services. In the case of SSH, AES128-CBC, and AES256-CBC are the only available options allowed by FIPS-CC/140-2. This is not a Fortinet-based limitation, but rather a limitation in the standards set by FIPS-CC/140-2 and NDcPP. Fortinet only supports Federal Information Processing Standard Publication (FIPS) 140-2 (Level 2) for the following managed FortiSwitch models:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.