in PIX with SSH connection issues

Hello

I have a PIX 506 running OS 6.2 (2) which is located in a demilitarized zone known as the PIX from the outside. It's behind an another PIX506 (PIX inside). The two PIX have Ganymede + configured for authentication of the connection.

Last week the outdoor PIX crushed physically and I replaced it with a spare PIX part and he completely reconfigured.

Now I can't connect to this outside PIX using SSH, despite the list of access inside PIX is correct and can SSH and Ganymede +. However, I can telnet to it.

I use Putty to connect and when I start the session SSH from the PIX, the login window appears and disappears immediately without having the time to do anything myself.

Any help would be greatly appreciated. Thanks in advance.

A.G.

##################################################

Inside PIX config:

access-list inside allow TCP Company-Interior-Net 255.255.255.0 host outsidepix-Interior-interface eq ssh

list Company-Interior-Net 255.255.255.0 access inside permit tcp host eq telnet interface-inside-outsidepix

access-list inside allow the ICMP messages to echo DMZNet 255.255.255.192 Company-Interior-Net 255.255.255.0

access-list inside allow Company-Interior-Net icmp 255.255.255.0 DMZNet 255.255.255.192 - response to echo

dmzacl list of access allowed icmp echo host outsidepix-Interior-interface company-Interior-Net 255.255.255.0

dmzacl list of access allowed icmp host outsidepix-Interior-interface company-Interior-Net 255.255.255.0 - response to echo

access-list permits dmzacl tcp host outsidepix-Interior-interface host Ganymede-server1 eq Ganymede

access-list permits dmzacl tcp host outsidepix-Interior-interface host Ganymede-server2 eq Ganymede

The outdoor PIX config:

GANYMEDE + Protocol Ganymede + AAA-server

AAA-server GANYMEDE + (inside) host Ganymede-server1 1234 timeout 10

AAA-server GANYMEDE + (inside) host Ganymede-server2 1234 timeout 10

RADIUS Protocol RADIUS AAA server

AAA-server local LOCAL Protocol

Console telnet authentication GANYMEDE AAA +.

the AAA console ssh GANYMEDE authentication +.

AAA authentication enable console GANYMEDE +.

Telnet Company-Interior-Net 255.255.255.0 inside

Telnet timeout 5

SSH-company-Interior-Net 255.255.255.0 inside

SSH DMZNet 255.255.255.192 inside

SSH timeout 5

did you follow the steps to configure ssh? the domain name and host name is defined on it? CA has generated you any rsa... to create the encryption keys?

Tags: Cisco Security

Similar Questions

  • After you have installed face to face Service pack 2 with network connectivity issue

    Original title: How can I stop this?

    Since the download for Vista service Pack 2, I have to reset my IP addresses when I connect.  How can I stop this?

    Hello

    1 What is a wired or wireless network?
    2. What is the exact error message or error code?

    Try the following and see if it helps.

    Method 1:


    Check the proxy server settings are turned on. To do this, try the following steps:
    a. activate the proxy on Internet Explorer (IE)
    b. Click Start, type inetcpl.cpl and press to enter.
    c. click on the Connections tab, click the LAN Settings button.
    d. check "Automatically detect settings" under proxy server.
    e. click ok to apply the changes.
    f. open Internet Explorer and check if the problem persists.

     
    Method 2:
    Purge the DNS and check if it helps.

    Try the following steps and try to purge the DNS and check if it helps.

    a. Click Start. Type cmd in the search box and press ENTER.
    b. at the command prompt, type the following command and press ENTER:
    ipconfig/flushdns (there is a space between ipconfig and /).
    It will show you the message successfully empty the cache of DNS resolution.
    c. at the command prompt, type the following command and press ENTER:
    ipconfig/registerdns (there is a space between ipconfig and /).
    For reference, see the following Microsoft article:
    http://TechNet.Microsoft.com/en-us/library/cc781949 (WS.10) .aspx

    Method 3:

    How to reset the Protocol (TCP/IP) Internet: http://support.microsoft.com/kb/299357
  • Access PIX using SSH when connected remotely with VPN client

    Hello

    I think that this should be a fairly simple for someone to sort for me - I'm new to PIX configuration If Yes please excuse my stupidity!

    I changed the config on our PIX to allow only access via SSH (rather than via telnet as it was previously configured)

    Now, everything works fine when I'm in the office - I can connect to the PIX using SSH without any problem.

    However, if I work from home and connect to the office using my VPN client (IPSEC tunnel ends on the PIX firewall itself) I find that I can not connect to the PIX.

    I have configured the PIX to access ssh on the office LAN subnet and the client pool of IP addresses used for VPN connections by using the following commands:

    SSH 172.64.10.0 255.255.255.0 inside

    SSH 192.28.161.0 255.255.255.0 inside

    where the 1st line is reference to the office's LAN, which works very well, and the 2nd line denotes the IP address pool configured on the PIX for VPN access.

    Can someone tell me how to fix this? I have the feeling that its something pressing!

    Thank you

    Neil

    Try the command "management-access to the Interior.

  • Pavilion g6: Atheros connection issues with Arris Modem

    Hi, I had the same problem with my laptop and Atheros network card, windows 7, it can not connect to the network with Arris modem but it works with other modems. I downdoaded the driver from the link you provided here, and it worked, my laptop connected to the network without problems, but after a month it stopped connecting to the network, I downloaded the driver again, but it did not work.

    @s_z,

    Hello and thanks for posting back.  Here is a link to a solution to problems of common connection to the problems of Atheros WLAN Driver and connection.

    Atheros WLAN Driver corrects connection issues with many new routers (Linksys, Netgear, D-Link, etc...)

    Please let me know how things are going.  Thanks again for posting and have a great day.

  • Internet - connection drops with my Toshibha laptop/internet connectivity issues arrives and stops randomly

    Original title: Internet connectivity

    my computer toshiba laptop windows 7 just started to fall sharply internet all in a show that is to connect to the internet all my other devices all always online - internet comes back randomly and goes off randomly - tried all settings to make sure that everything looks good.

    Hello

    Welcome to the Microsoft community.

    I understand that you have a problem with internet connectivity. We apologize for the inconvenience caused to you. We also indicate the steps you did.

    I would like to know the details below to help you better.

    1. What is the model number of the laptop you are using?
    2. Do you have a code error message when connecting to internet?
    3. You did changes to the computer before the show?
    4. You are connected to an internet connection wired or wireless?

    I ask you to run the Network Troubleshooter utility first to see if it can help diagnose and solve your problem. Open the utility of network troubleshooter by right-clicking the network icon in the notification area, and then click troubleshoot.

    You can also run the troubleshooter of Internet connections by:

    1. By clicking on the Start button, and then clicking Control Panel.
    2. In the search box, type Troubleshooting, and then click Troubleshooting.
    3. Under network and Internet, click connect to the Internet.

    If the problem persists, try to perform the steps of troubleshooting mentioned below in Microsoft Help article and check if that helps.

    Why can't I connect to the Internet?

    http://Windows.Microsoft.com/en-us/Windows/cant-connect-Internet#1TC=Windows-7

    Keep us updated on the issue to help you better.

  • How activate/connect with SSH?

    For Beta3 release notes say is a new feature ' secure connection: you can now connect to the Tablet using Secure Shell (SSH) and download files from your application using SCP and SFTP.

    The simulator of listening on port 22 (the SSH standard) or any other port for SSH connections, with or without active development mode does not have a vanilla installation.

    I found the blackberry connect program in the SDK bin folder and tried this after creating a RSA2 key:

    c:\>blackberry-connect -targetHost 192.168.7.172 -devicePassword x
    PROGRESS: Connecting to target 192.168.7.172:4455
    PROGRESS: Authenticating with target 192.168.7.172:4455
    PROGRESS: Encryption parameters verified
    PROGRESS: Authenticating with target credentials.
    PROGRESS: Successfully authenticated with target credentials.
    PROGRESS: Sending ssh key to target 192.168.7.172:4455
    Connection refused: Invalid ssh key contents.
    The target actively refused the connection. Please ensure that qconnDoor is running on the target.
    PROGRESS: Unable to send ssh key to target
    

    The fichier.ssh/id_rsa.pub is generated as a SSH-1 using PuttyGen key.  I also tried a file SSH-2 RSA with the same results.

    The fact that he said that he "succesfully authenticated" it suggests successfully connected... probably using port 443 (https) the way I guess that deploy blackberry is.  However, after that he seems to say my key is not valid (not sure, I believe that), but also actively target "connection refused" (I think that... qconn is not listening on port 8000 or another).

    Any who have knowledge of this area, or wild guess I can try?

    OK, I am able to connect through SSH.  It's a little complicated at the moment but I'll simplify and post a recipe as soon as I can.

    For anyone technical enough to follow with minimal intervention:

    1. I generated a 4096-bit RSA key using 'ssh-keygen - b 4096' on a Linux machine, recording in the format 'test_rsa' and 'test_rsa.pub '.
    2. I transferred those to my Windows box.
    3. I called "blackberry-connect targetHost - PCMGM - devicePassword x - test_rsa.pub sshPublicKey."

    This operation transfers the public key in the device by connecting through qconn (port 4455) using unknown protocols.  The output looks like this:

    PROGRESS: Connecting to target 192.168.7.172:4455
    PROGRESS: Authenticating with target 192.168.7.172:4455
    PROGRESS: Encryption parameters verified
    PROGRESS: Authenticating with target credentials.
    PROGRESS: Successfully authenticated with target credentials.
    PROGRESS: Sending ssh key to target 192.168.7.172:4455
    PROGRESS: ssh key successfully transfered.
    PROGRESS: Succesfully Connected
    

    Blackberry connect program continues to run, and as long as it is running at this point the Simulator will be listening for SSH connections on port 22.

    At this point, I had to take the test_rsa (the private key) file and import it into Puttygen using Conversions-> import menu button.  Save the private key, and load the key in the pageant.

    Finally, normally connect using PuTTY at the address PCMGM and sign in as "devuser".  This was discovered by looking in the /accounts folder using a primitive file browser application, where I found two subfolders, 1000 / and devuser.

  • is it possible to connect with SSH from router to router?

    is it possible to connect with SSH (1.0 or 2.0) to a CISCO-router/Switch to another CISCO-router/Switch?

    I think that an SSH connection to a router/switch is no longer possible to a women (Windows/Linux/Unix)

    is it not?

    I don't know if Cisco Compatible SSH 2.0, but there IOS - s that support ssh 1.0 and you can connect with ssh 1.0 from a cisco device (if it supports) to any device with

    Router # ssh?

    Select encryption algorithm - c

    -l Log in using that username

    options to specify o

    p connect to this port

    Address WORD IP or hostname of a remote system

    Router # ssh x.x.x.x

  • SSH version pix 6.3.3 is the name of user pix, you can connect to?

    I test the SSH version 1 connections in a 515 6.3.3 I configuration of usernames within the pix and ssh allows connections via running ip address. THS problem is I can only connect to the PIX via the username "pix" and it will only allow one connection at a time.

    Does anyone know why not accept logings via SSH using user names defined in the device?

    Thanks in advance. Mike

    Enter the commands 'aaa-server protocol LOCAL local' and 'ssh LOCAL console aaa authentication. "

    You will then be able to connect using the local usernames on the Pix.

  • Database MS SQL Server with AIX server connectivity issues

    Hi all

    I am confronted with the below with the AIX server connectivity issues.

    Operating system: AIX 64 bit

    DB: SQL Server 2005

    EPM Version: Hyperion 11.1.1.4

    Error creating socket to host and port 1433. Reason: Connection timed out: could be due to an invalid address

    Tired of Solution

    (1) checked the properties of TCP/IP, its permitted.

    (2) ping the source and target servers both ends all works fine

    (3) firewall is DISABLED in DB Server

    Hi all

    My apologies, its number of firewall & network. Resolved by the Unix administrator.

    Thank you

  • PIX and SSH - access to PIX via SSH

    Need help with PIX and SSH

    Objective: Connect to PIX via SSH from the 10.1.1.50 IP address behind inside the interface on the PIX using local aaa on PIX.

    Current settings:

    hostname pix1

    example.com domain name

    CA generates the key rsa 1024

    example username password abc123 privileges 15

    include authentication AAA ssh inside 10.1.1.50 255.255.255.255 local

    SSH 10.1.1.50 255.255.255.255 inside

    Thanks for any help!

    Try this:

    AAA-server local LOCAL Protocol

    the ssh LOCAL console AAA authentication

  • Cann't open web access, ssh connection between host and bridged the VM in network mode

    I have a VMware workstartion 7.0 is installed on a machine XP 64 (192.168.2.44). I have the following virtual machines.

    1 ESX 4.0 (192.168.2.42)

    2 ESX 3.5 (192.168.2.38)

    3. windows server 2003 with vCenter installed. (192.168.2.100)

    4. Windows server 2003 with the roles of DNS and DC. (192.168.2.101)

    I am trying to connect to vCenter or ESX VM of the XP hosting web interface. However I can't get through. but I can ping and I can also telnet to ports 443, 80. Even I can't ssh connection. When I use putty, it is actually connected but no response from the ssh server. Looks like the network connection is there, somehow the server process responds simply not properly once the connection is established.

    BTW, all of them use bridged network, they all 192.168.2.x IPs. I can connect to vCenter, ESX web interface from another computer without problem.

    Just wonder if anyone else has experienced this before. I have tried to search the forum, did not find a similar question.

    Thank you!

    Tong

    Your host, try to disable (temporarily) a "discharge" for the NIC settings.

    http://KB.VMware.com/kb/1015940

    If this solves the problem, other threads on this issue have mentioned that a fix for this will be included in the next version of the 'point' of Workstation 7 (as 7.1, etc).

  • Anyone having problems with WiFi connectivity after upgrade to Sierra?

    I was wondering if anyone else knows issues with WiFi connectivity since the upgrade to Sierra 10.12? I have not had any problems with connectivity WiFi previously on El Capitan. Now I have regular randomly loose connectivity. My internet is cable and when it is connected I have a 100% connection. My details of iMac and I have used only 10% of my storage.

    No problem with my iphone 6.

    Hello AspDesigns,

    I understand that, since the upgrade to Mac OS Sierra, your Mac seems to have trouble staying connected to Wi - Fi. Fortunately the diagnosis built-in wireless can help identify the source of so much trouble.

    Search for Wi - Fi using your Mac problems

    See you soon!

  • Siri does not (problems with the connection)

    Hello

    I installed macOS Sierra yesterday. Everything seems to work fine, except Siri. With Siri I always get an error message "I am having some problems with the connection. Please try again in a moment. ». But this seems to appear every time. The network connection works fine, I can't access the Internet without problem.

    No idea how solve the problem?

    I use an iMac (27 inch, mid-2011). Internal microphone is connected, I also see the 'waves' change while I am speaking.

    Concerning

    Thomas

    Hey, thochstrasser. Thank you for using communities of Apple Support.

    It seems that Siri is reluctant to make his debut on your iMac after upgrade to Mac OS Sierra. I want to make sure that you get the benefit of this new feature on a Mac.

    1 try safe mode if your Mac does not start -even if your iMac to market, safe mode makes sure it starts successfully.

    2. How to test a question in an another user account on your Mac - since this is most likely a software problem, test to another user will indicate if it is right to your user account or throughout your system.

    3. use Time Machine to back up or restore your Mac - if it seems to be systemic, the next step should not cause problems. But it is always better "to have" a backup to the "need".

    4. on OS X Recovery - the issue as part of the operating system, reinstall should do.

    Have a great weekend!

  • connectivity issues mobile iPhone 7

    I have a new iPhone 7 jet black, so far I'm in love. But yesterday, I noticed an annoying problem. The phone loses the network connection (cell to the & t) and he no reconnect, it will remain just it saying no service. I have to go in airplane mode and outside to force it to look for the network connection.

    everyone knows this? and everybody understand what it could be?

    I already missed messages and a phone call. This could worsen as boring to become a problem. If anyone has any idea what this could be please give me a heads up!

    OH! Another thing I noticed, when the iPhone is connected my signal strength went from-102 to my 6 sec to-86 on my 7! Then when I am connected I am connected!

    Hello jpgraphx,

    Thank you for using communities Support from Apple. I know have a cell connection issue on your new iPhone, it's not what you expect. The good news are the following steps will help to solve your problem with loss of cellular data and see no Service and get your new iPhone works properly again.

    If you cannot connect to a cellular network or cellular data

    See you soon!

  • Mac pro wi - fi connectivity issues

    I have the same problem, it seems that many people have with Wi - Fi connectivity issues.  I just bought the Macbook Pro in December 2015.  My computer goes to sleep and when I open the hood it looks like I'm connected to wireless, but I'm really not!  I'm going to websites, and they won't open.  I disconnect my wi - fi and reconnect and sometimes it works, but sometimes I actually have to restart my computer.  For the moment, at the end of the day I'll stop my computer, then restart the morning I guess.  It sometimes seems to lose its connection during the day too, I guess because he falls asleep.  Very frustrated.  Just got this computer in December and have had this problem since I use the computer out of the box.  I was told it's because I haven't had my update of El Capitan, did, but it wasn't the problem.  Technical support suggested a few other things we also went through and those who did nothing either.  Don't know what the problem is or how to solve this problem, or even if I can if so many others have this problem.  I think it's a matter of Apple and the wish that they would be admitting the problem and try to find a solution.  Apple of love, but right now quite disappointed.  Quite expensive computer for issues that I am.  I went from a Dell for an Apple thinking it was the best thing since shirt pockets, hmmm...  I don't think it's any problem with our modem, wireless, router, etc., because we have other laptops, iPads, iPhones in this House and have NO problem.  So, I hope that everyone is not running out to buy new routers and modems because no doubt this is the problem at all.  PLEASE APPLE, DO SOMETHING TO FIX THIS!

    Hold down the Option key while you click on the wireless icon in the menu bar. You get a screen similar to the following:

    what you get for channel and mode PHY?

    What CISOS or the signal strength?

    What emission rates?

    very important and how many other networks do you see?

Maybe you are looking for