Description | This article describes how to configure the SSH key exchange method to resolve an error stating no matching key exchange was found. |
Scope | FortiGate. |
Solution |
To diagnose SSH key exchange issues on FortiGate, use the following debug commands:
diagnose debug console timestamp enable
The following error will appear in the debug logs when there are compatibility issues between the SSH client and FortiGate: 2024-10-25 10:39:39 SSH: Forked child 22343. Note:
config system global
For v7.4.4 and later, the command has been moved from config system global to config system ssh-config:
The algorithm options are different based on the strong encryption setting.
strong-crypto enabled, ssh-kex-algo could be:
strong-crypto disabled, ssh-kex-algo could be:
Choose the proper SSH key exchange method. SSH from FortiGate to other devices should work.
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.