If you use OpenSSH 9.6p1 both on the client and server there is no need to use this registry parameter. IGEL OS versions 11.09.210 or higher use the latest OpenSSH 9.6p1. when you use this version or newer on the peer, they will automatically use the new "strict KEX" protocol extension.
To enable Terrapin mitigation through the registry parameter:
In IGEL Setup, go to System > Registry > network > ssh_server > enable_terrapin_mitigation.
Enable the parameter.
Click Apply or OK to save the change.
The following options vulnerable to Terrapin attack are disabled:
the ChaCha20-Poly1305 cipher
all -cbc ciphers
all -ctr ciphers
all -etm@openssh.com macs
If you want to deactivate SSH completely, follow the instructions in Disabling SSH Access.