// SSH error · Cisco, switches & routers

"no matching key exchange method found" – SSH to older devices

Trying to SSH into an older switch, router or NAS and getting this error? Here is what it means and how to fix it: with OpenSSH, with PuTTY, or with a single checkbox in Termax.

Applies to Cisco IOS, older HP/Aruba, Juniper and Netgear switches, NAS boxes and many embedded devices


// The cause

What the error means

This is how the error looks in OpenSSH (Linux, macOS and the ssh built into Windows):

Unable to negotiate with 10.0.0.2 port 22: no matching key exchange method found.
Their offer: diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1

At the start of every SSH connection, client and device agree on a key exchange ("kex") algorithm. Their offer lists what the device supports. Older firmware only speaks SHA-1 based algorithms. Modern SSH clients stopped offering them years ago, because SHA-1 and the small 1024-bit group (group1) are considered weak. OpenSSH disabled diffie-hellman-group1-sha1 by default in version 7.0 (2015), and ssh-rsa signatures in version 8.8 (2021). If both sides share no algorithm, the connection is dropped right away – before you are even asked for a user name or password.

That is why the error often appears "out of nowhere": the device did not change, your SSH client was updated.


// Related errors

Same cause, different message

Depending on which step fails first, OpenSSH words the error differently. The right-hand column shows the setting that helps.

Message (OpenSSH)What's missingOpenSSH setting
no matching key exchange method found. Their offer: diffie-hellman-group1-sha1old key exchangeKexAlgorithms +diffie-hellman-group1-sha1
no matching host key type found. Their offer: ssh-rsaold host key signatureHostKeyAlgorithms +ssh-rsa
no matching cipher found. Their offer: aes128-cbc,3des-cbcold encryption (CBC)Ciphers +aes128-cbc
no matching MAC found. Their offer: hmac-md5old integrity checkMACs +hmac-md5

Always add exactly the algorithm listed after Their offer. In Termax, one switch covers all four cases.


// Fix 1 · Termax

One checkbox per connection

Since version 0.7.1, Termax connects to older devices – on Windows, Android and in the browser.

  1. Open Termax and create the connection (New connection), or open an existing one via ⋯ → Edit.
  2. Tick Allow legacy algorithms (older devices) and click Save.
  3. Connect. Termax now additionally offers SHA-1 key exchange, CBC ciphers, SHA-1/MD5 MACs and ssh-rsa/ssh-dss.

The option only applies to the connection where you turn it on. Secure algorithms always come first, so a device that supports anything newer keeps using it. If a connection fails because of outdated algorithms, Termax points you straight to the option. And if your ~/.ssh/config already contains lines like KexAlgorithms +diffie-hellman-group1-sha1, the import sets the option automatically.

Download Termax for free – for Windows and Android, no account needed.


// Fix 2 · OpenSSH

In the terminal: once or permanently

Once, for a single connection

The plus sign matters: it adds the old algorithm. Without + you replace the whole list and switch the secure algorithms off.

ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 admin@10.0.0.2

# if host key or cipher errors follow:
ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 \
    -oHostKeyAlgorithms=+ssh-rsa \
    -oCiphers=+aes128-cbc \
    admin@10.0.0.2

Permanently, for this device only

In ~/.ssh/config (on Windows C:\Users\<name>\.ssh\config) the setting only applies to the named host – all other connections stay strict:

Host core-switch
    HostName 10.0.0.2
    User admin
    KexAlgorithms +diffie-hellman-group1-sha1,diffie-hellman-group14-sha1
    HostKeyAlgorithms +ssh-rsa
    Ciphers +aes128-cbc

If you log in with an RSA key, OpenSSH 8.5 and later also needs PubkeyAcceptedAlgorithms +ssh-rsa (older versions call the option PubkeyAcceptedKeyTypes).

PuTTY

PuTTY still supports the old algorithms but treats them as insecure and asks for confirmation with a warning before connecting. You can change the order under Connection → SSH → Kex.


// Fix 3 · On the device

The safest fix: modernise the device

Newer IOS / IOS-XE releases and current firmware from other vendors support modern algorithms such as diffie-hellman-group14-sha256 or ecdh-sha2-nistp256. A firmware update is often enough – on Cisco, together with a new RSA key of at least 2048 bits. Then the client needs no exception at all. For devices that no longer receive updates, a client-side exception remains the practical way.

If a device does not speak SSH at all, or you can only reach it through its console port, Termax helps there too: with Telnet in the Windows and Android apps, and with the serial console (COM, preset 9600 8N1) on Windows, on Android with a USB OTG adapter and in the browser with Chrome or Edge. Telnet is unencrypted and belongs on your own network only.


// Said openly

How insecure is this?

The connection stays encrypted and the device's host key is still verified. The old algorithms are weaker, though: the 1024-bit group is considered within reach of attackers with very large computing resources, and SHA-1 and CBC have known theoretical weaknesses. For a device on your own, trusted network this is acceptable in practice – don't manage such devices across the open internet. What matters is to set the exception for the affected device only, never globally.


// FAQ

Frequently asked questions

What does "no matching key exchange method found" mean?
The SSH client and the device found no key exchange algorithm they both support. Usually an older device only offers SHA-1 algorithms such as diffie-hellman-group1-sha1, which current SSH clients no longer use by default. The connection is dropped before you are asked for a password.
Why did it work before?
Because your SSH client changed, not the device. OpenSSH disabled diffie-hellman-group1-sha1 by default in version 7.0 (2015) and ssh-rsa signatures in version 8.8 (2021). After a system update these algorithms are suddenly missing.
How do I fix it permanently in OpenSSH?
Add an entry for this device only to ~/.ssh/config and add the algorithms with a plus sign, for example "KexAlgorithms +diffie-hellman-group1-sha1". Without the plus you replace the list and switch the secure algorithms off.
Is it dangerous to allow the old algorithms?
They are weaker than modern algorithms, but the connection stays encrypted. Set the exception only for the affected device and only on your own, trusted network. The safest fix is a firmware update, if the device still gets one.
Does this work in Termax on Android and in the browser too?
Yes. The option "Allow legacy algorithms (older devices)" is available since version 0.7.1 in the Windows and Android apps and in the web app (signed in). It only applies to the connection where it is turned on.