ssh connection to ATP100: "no matching key exchange method found. Their offer: ..."

Options
bobrun
bobrun Posts: 1
edited April 2021 in Security
Hi, when trying to connect to my ATP100 (FW 4.55(ABPS.0)) via ssh I get:

"Unable to negotiate with x.x.x.x port 22: no matching key exchange method found. Their offer: diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1"

Apparently the ATP100 offers only outdated key exchange methods based on sha1. I could enable these in my ssh command but that's certainly an undesirable approach. How can I enable newer eg sha2 based kex methods on the ATP100?


Accepted Solution

All Replies

  • danyedinak
    danyedinak Posts: 49  Freshman Member
    First Anniversary Friend Collector First Comment
    Options
    @Zyxel_Emily will other devices also be getting this support?
  • Zyxel_Emily
    Zyxel_Emily Posts: 1,296  Zyxel Employee
    First Anniversary 10 Comments Friend Collector First Answer
    Options

    Hi @danyedinak,

    Yes. All USG/ZyWALL/ATP/VPN/USG FLEX models with firmware 4.60 supports sha2 key exchange method.

Security Highlight