Explains the OpenSSH-based Cisco implementation, including post-quantum key exchange, implementation differences, restrictions, operating recommendations, and session-event messages for secure router management.
CiscoSSH is an OpenSSH-based secure-shell implementation that
-
uses the Linux TCP/IP stack on management Ethernet and line-card interfaces
-
supports FIPS operation, X.509 certificates, MPP, ACLs, and VRFs, and
-
preserves most Cisco IOS XR SSH commands while adding OpenSSH security and interoperability.
CiscoSSH replaces the older Cisco IOS XR SSH implementation beginning with Cisco IOS XR Software Release 7.3.2.
| Feature Name | Release Information | Feature Description |
|---|---|---|
| CiscoSSH | Release 7.3.2 |
This release introduces CiscoSSH, a newer implementation of SSH on this platform. CiscoSSH leverages OpenSSH implementation, by using the Linux TCP/IP stack to transmit and receive SSH packets over the management Ethernet interface and line card interfaces on the router. CiscoSSH provides additional security features like FIPS compliance and X.509 digital certification. It supports packet path features like MPP, ACL and VRF support, and ensures interoperability with various existing SSH implementations.
|