// SSH error · Cisco, switches & routers
"no matching key exchange method found" – SSH to older devices
Trying to SSH into an older switch, router or NAS and getting this error? Here is what it means and how to fix it: with OpenSSH, with PuTTY, or with a single checkbox in Termax.
Applies to Cisco IOS, older HP/Aruba, Juniper and Netgear switches, NAS boxes and many embedded devices
// The cause
What the error means
This is how the error looks in OpenSSH (Linux, macOS and the ssh built into Windows):
Unable to negotiate with 10.0.0.2 port 22: no matching key exchange method found. Their offer: diffie-hellman-group-exchange-sha1,diffie-hellman-group14-sha1,diffie-hellman-group1-sha1
At the start of every SSH connection, client and device agree on a key exchange ("kex") algorithm. Their offer lists what the device supports. Older firmware only speaks SHA-1 based algorithms. Modern SSH clients stopped offering them years ago, because SHA-1 and the small 1024-bit group (group1) are considered weak. OpenSSH disabled diffie-hellman-group1-sha1 by default in version 7.0 (2015), and ssh-rsa signatures in version 8.8 (2021). If both sides share no algorithm, the connection is dropped right away – before you are even asked for a user name or password.
That is why the error often appears "out of nowhere": the device did not change, your SSH client was updated.
// Related errors
Same cause, different message
Depending on which step fails first, OpenSSH words the error differently. The right-hand column shows the setting that helps.
| Message (OpenSSH) | What's missing | OpenSSH setting |
|---|---|---|
no matching key exchange method found. Their offer: diffie-hellman-group1-sha1 | old key exchange | KexAlgorithms +diffie-hellman-group1-sha1 |
no matching host key type found. Their offer: ssh-rsa | old host key signature | HostKeyAlgorithms +ssh-rsa |
no matching cipher found. Their offer: aes128-cbc,3des-cbc | old encryption (CBC) | Ciphers +aes128-cbc |
no matching MAC found. Their offer: hmac-md5 | old integrity check | MACs +hmac-md5 |
Always add exactly the algorithm listed after Their offer. In Termax, one switch covers all four cases.
// Fix 1 · Termax
One checkbox per connection
Since version 0.7.1, Termax connects to older devices – on Windows, Android and in the browser.
- Open Termax and create the connection (New connection), or open an existing one via ⋯ → Edit.
- Tick Allow legacy algorithms (older devices) and click Save.
- Connect. Termax now additionally offers SHA-1 key exchange, CBC ciphers, SHA-1/MD5 MACs and
ssh-rsa/ssh-dss.
The option only applies to the connection where you turn it on. Secure algorithms always come first, so a device that supports anything newer keeps using it. If a connection fails because of outdated algorithms, Termax points you straight to the option. And if your ~/.ssh/config already contains lines like KexAlgorithms +diffie-hellman-group1-sha1, the import sets the option automatically.
Download Termax for free – for Windows and Android, no account needed.
// Fix 2 · OpenSSH
In the terminal: once or permanently
Once, for a single connection
The plus sign matters: it adds the old algorithm. Without + you replace the whole list and switch the secure algorithms off.
ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 admin@10.0.0.2
# if host key or cipher errors follow:
ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 \
-oHostKeyAlgorithms=+ssh-rsa \
-oCiphers=+aes128-cbc \
admin@10.0.0.2
Permanently, for this device only
In ~/.ssh/config (on Windows C:\Users\<name>\.ssh\config) the setting only applies to the named host – all other connections stay strict:
Host core-switch
HostName 10.0.0.2
User admin
KexAlgorithms +diffie-hellman-group1-sha1,diffie-hellman-group14-sha1
HostKeyAlgorithms +ssh-rsa
Ciphers +aes128-cbc
If you log in with an RSA key, OpenSSH 8.5 and later also needs PubkeyAcceptedAlgorithms +ssh-rsa (older versions call the option PubkeyAcceptedKeyTypes).
PuTTY
PuTTY still supports the old algorithms but treats them as insecure and asks for confirmation with a warning before connecting. You can change the order under Connection → SSH → Kex.
// Fix 3 · On the device
The safest fix: modernise the device
Newer IOS / IOS-XE releases and current firmware from other vendors support modern algorithms such as diffie-hellman-group14-sha256 or ecdh-sha2-nistp256. A firmware update is often enough – on Cisco, together with a new RSA key of at least 2048 bits. Then the client needs no exception at all. For devices that no longer receive updates, a client-side exception remains the practical way.
If a device does not speak SSH at all, or you can only reach it through its console port, Termax helps there too: with Telnet in the Windows and Android apps, and with the serial console (COM, preset 9600 8N1) on Windows, on Android with a USB OTG adapter and in the browser with Chrome or Edge. Telnet is unencrypted and belongs on your own network only.
// Said openly
How insecure is this?
The connection stays encrypted and the device's host key is still verified. The old algorithms are weaker, though: the 1024-bit group is considered within reach of attackers with very large computing resources, and SHA-1 and CBC have known theoretical weaknesses. For a device on your own, trusted network this is acceptable in practice – don't manage such devices across the open internet. What matters is to set the exception for the affected device only, never globally.
// FAQ