The older SH1 diffie/hellman group ciphers are not strong enough. However various networking appliances still (only) use them.
$ ssh email@example.com
Unable to negotiate with 10.0.1.7 port 22: no matching key exchange method found. Their offer: diffie-hellman-group-exchange-sha1,diffie-hellman-group1-sha1,diffie-hellman-group14-sha1
Add the key temporarily.
$ ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 firstname.lastname@example.org