FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kajlasunil
Staff
Staff
Article Id 344788
Description This article describes the reason why it is impossible to SSH into a managed switch from a FIPS-CC-enabled FortiOS.
Scope FortiOS FIPS-CC. 
Solution

Unable to SSH managed FortiSwitch from FIPS-enabled FortiOS:

 

4.PNG

 

Unable to negotiate with 10.0.1.2: no matching key exchange method found. Their offer: curve25519-sha256@libssh.org,diffie-hellman-
group-exchange-sha256

 

FIPS-CC heavily restricts the list of allowed encryption ciphers, HMAC, and Key Exchange options available for encrypted services. In the case of SSH, AES128-CBC, and AES256-CBC are the only available options allowed by FIPS-CC/140-2. This is not a Fortinet-based limitation, but rather a limitation in the standards set by FIPS-CC/140-2 and NDcPP.

Due to the FIPS-CC mode, it is not possible to make changes to the Cipher.

Fortinet only supports Federal Information Processing Standard Publication (FIPS) 140-2 (Level 2) for the following managed FortiSwitch models:

  • FS-424E.
  • FS-424E-FPOE.
  • FS-M426E-FPOE.
  • FS-424E-Fiber.
  • FS-448E.
  • FS-448E-FPOE.
  • FS-1048E.
  • FS-3032E.