Unable to SSH for outside the router No. 2851

Hello

I want to SSH to the external interface of our router No. 2851.

SSH works fine on the internal interfaces.

I have install the ACL is access (1 applied to the vty line and one to the external interface).

The configuration looks like the following:

line vty 0 4

access-class 102 in

30 logout-WARNING

length 0

entry ssh transport

access list 102 permit tcp any gt 1024 any eq 22

Outside_ACL extended IP access list

permitted tcp and gt 1024 no matter what eq 22 log

Is there anything else that I should consider when setting up SSH on the external interface?

TIA,

Michael

Michael

I notice that there is a card encryption on the interface (I have would have supposed of your previous comment that you access the router via VPN) and I wonder if it is possible that SSH entering your remote address is considered to be entering the card encryption VPN traffic. Could you try the external address of some other address source SSH and see if that changes things?

Or can you provide details on what is in the card encryption - and perhaps think about putting something in the map encryption that would exclude SSH to the external interface.

HTH

Rick

Tags: Cisco Security

Similar Questions

  • Unable to SSH/telnet through the remote access VPN to ASA interface

    Hi all - im trying to SSH/telnet to my ASA in my remote access VPN tunnel but

    can't get this to work.  what Miss me?

    remote access VPN subnet: 192.168.25.0

    LAN subnet: 192.168.1.0

    config is attached.  THX-

    Please enter the command

    Private access Managament

    and you will be able to telnet/ssh to the asa on this ip 192.168.1.253

  • END point URL for the routing service BSE says not FOUND

    Hi all

    For services of routing in BSE, the WSDL link opens the fine, but the link to endpoint URI for the routing service fails with the message below the message. When I invoke the WSDL with SOAP UI, I'll be back the same error message. I tried to bounce the server, but no help. I also noticed that this slide ESB_Projects Directory gives error 404 on any browser.

    Then, when I click below url for all the routing service

    http:// < hostname >: < port > /Event/ < systemName > / < serviceGroupName > /AddressStandardizeRS

    I get the error in the browser - below

    Not found

    The URL /event/ requested < the system name > / < group name > / < Routing Service name > was not found on this server.

    Oracle-Application-Server-10g/10.1.3.1.0 Oracle-HTTP-Server Server at odevsoa.local1.wbcgp.com Port 7777
  • While trying to install a Linksys E1500 he repeats that my computer is not connected to the router.

    Computer problems and the router

    I have a windows xp 2002 with service Pack 3. While trying to install a Linksys E1500 he repeats that my computer is not connected to the router. Ive tried a new cable and it does not solve the problem. He also said that my computer does not have wireless capabilities. Any suggestions?

    You'll be much more likely to get useful (or even possible) suggestions if you provide the full text of the error messages you get, without paraphrasing.

    For example:

    He repeated to me that my computer is not connected to the router. --> What is the real error message?

    He also said that my computer lacks wireless capabilities--> what is the error message itself?

    You are "trying to connect via a cable" to the router or you're talking about your Internet service (for example, the router is connected to the Internet via a cable)?

    You think that your computer has "wireless capabilities?  Open the Device Manager (start > run > devmgmt.msc > OK), then click on the + sign next to "network adapters."  Please provide the names of any devices listed there.

    Is your computer without a name, a laptop?  There a name of brand anywhere (for example, Toshiba, HP, Dell, etc.)?

    Open System Properties (start > run > msinfo32 > OK)
    Click Edit > select all
    Click Edit > copy
    Right-click in your response here and select Paste
    Be sure to hide the "System name" or "User Name" if it makes you feel better, but please do not remove anything else.

  • Unable to connect to Homegroup Windows 7 between the Modem to the PC and the Modem to the router for PC users.

    I want to talk about WIRED computers, do not speak of wireless.

    I have 3 PC:

    -2 are connected via Modem directly to the PC.

    -1 is connected through router, and the router is connected to the modem.

    The problem, this is it, it cannot detect the homegroup that I created on the computer that is directly connected by modem.

    The 2 PC via modem are perfectly detected and connected to the homegroup, so I want to know what I would do to another PC (which is connected to the router via modem) detects the homegroup, I had already created?

    Help, please.

    A Modem can have only two ports, connect to the internet (Wide Area Network) and the second to a SINGLE local device. In most cases the internet Service Pwill provide with only an IP address so itself cannot connect to more than one at a time. In current solutions, it is very rare for a Modem to use. If as you say, you have several devices connected to this unit then he himself is a router but possibly with the Modem built in if you have ADSL ISP.

    If your second unit is also a router then that explains why you cannot connect all devices in the same residential group.

    Router 1 has created a Local Area Network including both PC and the WAN port on the Router 2. Router 2 has created another independent local network with the 3rd PC. It is very likely that the two local networks will be IPv4 and traffic can be routed between them correctly in both directions according to the two local networks subnet ranges.

    Even if they are properly configured to allow traffic that HomeGroup requires IPv6 that some home routers support fully and every Member of the residential group must be on the same LAN anyway, he will not support a routed connection.

    Remove the 3rd PC of the 2nd router and plug it into the direct 1 router, remove the router 2nd the 1st in order to free the port. 3 all PCs are now on the same local network and communicate both IPv4 and IPv6, and homegroup should work.

    If you need additional ports provided by the 2nd router for other devices is not part of this problem then consider replacing it with a switch. If you use Router 2 for other devices Wi - Fi irrelevant then you need a wireless access Point.

  • Customers unable to browse the internet on the router from Cisco 871 K9

    Hello world

    "I just bought my Version of K9 Cisco router 871 running this flash system image: c870-advsecurityk9 - mz.124 - 4.T8.bin".

    I am trying to configure this router for home use, while I can block a part of Web traffic (porn sites, sites of films because of the children), but I realized that I was unable to apply the access list Match-class version url (http host).

    My major problem is still the base of the router config. WAN has a DHCP IP assignment with the 192.168.1.0 network

    The Lan is supposed to have 192.168.3.0 network. IP addresses seem to be properly attributed but not able to ping on the internet router. Local client also cannot resolve DNS. Here is my cofig file.

    Please help.

    Richard #sh run
    Building configuration...

    Current configuration: 1727 bytes
    !
    version 12.4
    no service button
    horodateurs service debug datetime msec
    Log service timestamps datetime msec
    no password encryption service
    !
    host Richard name
    !
    boot-start-marker
    boot-end-marker
    !
    !
    No aaa new-model
    !
    resources policy
    !
    IP subnet zero
    IP cef
    No dhcp use connected vrf ip
    !
    IP dhcp pool Richard pool
    import all
    network 192.168.3.0 255.255.255.0
    default router 192.168.3.1
    domain richardedet.com
    192.168.1.1 DNS server
    Rental 2 0
    !
    !
    !
    !
    !
    !
    !
    !
    !
    !
    interface FastEthernet0
    spanning tree portfast
    !
    interface FastEthernet1
    !
    interface FastEthernet2
    !
    interface FastEthernet3
    !
    interface FastEthernet4
    DHCP IP address
    Check IP unicast accessible source - via rx allow by default 100
    no ip redirection
    no ip unreachable
    no ip proxy-arp
    NAT outside IP
    IP virtual-reassembly
    automatic speed
    full-duplex
    !
    interface Vlan1
    Description Local network VLAN
    address 192.168.3.1 IP 255.255.255.0
    !
    IP classless
    IP route 0.0.0.0 0.0.0.0 FastEthernet4
    IP route 192.168.3.0 FastEthernet4 255.255.255.0
    !
    no ip address of the http server
    no ip http secure server
    overload of IP nat inside source list 101 interface FastEthernet4
    IP nat inside source map route RMAP-NAT interface FastEthernet4 overload
    The dns server IP
    !
    recording of debug trap
    recording ease Committee.2
    access-list 100 permit udp any any eq bootpc
    access-list 100 permit tcp any one
    access-list 100 permit icmp any one
    access-list 101 permit ip 192.168.3.0 0.0.0.255 any
    !
    control plan
    !
    !
    Line con 0
    richard password
    opening of session
    no activation of the modem
    telnet output transport
    line to 0
    richard password
    opening of session
    telnet output transport
    line vty 0 3
    richard password
    opening of session
    entry ssh transport
    line vty 4
    richard password
    opening of session
    !
    max-task-time 5000 Planner
    end

    Hello

    problem is that you have changed the IP address of the interface VLAN 1 from 192.168.1.254 to 192.168.1.1
    If you need to change by default-router dhcp pool:
    Select conf t
    Richard-Edet dhcp IP pool
    no default router
    default router 192.168.1.1
    end

    NAT is also missing:
    Enable
    conf t
    IP access-list standard NAT
    permit 192.168.1.0 0.0.0.255
    output
    IP nat inside source list NAT interface SA4 overload
    end

    Also perhaps you cannot ping the router console PC because the computer's firewall blocks the ICMP protocol. In windows, I'm sure he is blocked by the firewall. Then you can try ping 192.168.1.1 from the PC and it should work.

    Try above changes and then write me if it works, or so we can make other changes.
    You can also post the output of the commands (if this will not work):
    router: ip road show
    router: ping 8.8.8.8 (it should work if your internet provider doesn´t blocks the ICMP protocol)
    PC: ipconfig/all

  • Printer Hp6700: unable to connect to the router wireless D - Link DI-514 when SSID Broadcast is set to no.

    HP6700 printer: unable to connect to the router wireless D - Link DI-514 when the router Broadcast SSID is set to no. My MAC laptop and HP laptop both work with the set SSID on no. If I change the router Wireless SSID Broadcast is YES, then the printer HP6700 can connect to the wireless router. I set up the printer it saying that the SSID and password have been, the same as both of my laptops, but it connects ever, unless I have change the router to broadcast the SSID. Help!

    Have you tried to update the firmware on the DI-514?

    You can also try to set a static IP address on the printer, and then assign the printer to the list of DHCP static in the interface of the router.
    To give a static IP address to your printer:
    -Print a the front of the printer Network Setup Page. Note the IP address of the printer.
    -Enter the IP address in a browser to reveal the internal settings of the printer.
    -Choose the network tab, then wireless along the left side, then on the IPv4 tab.
    -On this screen, you want to set a manual IP address. You must assign an IP address outside the range that the router sets automatically (called the DHCP range). If you do not know the range, change the last set of numbers (those after the last '.') 250
    -Apply the subnet 255.255.255.0 (unless you know it's different, if so, use it)
    -Enter the IP of your router (on the Page of the Network Config) for the gateway.
    -Enter for the first DNS 8.8.8.8 and 8.8.4.4 for second DNS. It's Google DNS. You can choose a different external DNS if you wish.
    -Click 'apply '.
    Now, stop the router and printer, start the router, wait, and then start printing.

    After that you remove and re - add the printer to your Mac.

    Show support by clicking on the blue Kudos star in the post that solved your problem. Doing so will help the other members of the forum their solutions also.

  • Unable to connect to the router

    -Please ignore this message: I did not wait enough to do the factory reset. It seems that launch a factory reset without waiting for 10 seconds only restarts the router.

    Hello

    Today I tried to connect to my router (I do not use it for a few years) and it didn't work at all.

    Initially, I plugged it in just 2 RJ45 cables: one for internet, one for the PC. The computer could not connect to the router (DHCP failed).

    I then restored the factory settings and tried again: same thing, the computer could not find the router via DHCP.

    I tried to force an IP address (IP: 192.168.1.5, mask: 255.255.255.0 Gateway: 192.168.1.1).

    By forcing the INVESTIGATION period, I was able to connect to the router, but when I tried connect to 192.168.1.1 with admin/password, it wouldn't let me (bad password - don't forget I restored it to factory settings, several times actually). The address http://routeurlogin.net/ is not found (404) and I was unable to go on websites (404). A curious thing is, using this connection, I was able to connect to Skype (and send/receive messages), although the sites Web could not be reached from a browser.

    I'm running out of ideas to solve the problem, but I suspect a hardware problem, so any help would be welcome.

    Yes he did.

    I couldn't find an option to delete my message, otherwise I would have done it.

  • Linksys wireless-g usb network adapter unable to detect the router using windows XP desktop PC

    I've changed in broadband Orange yesterday and since then my adapter is unable to find the network (it was working fine with TalkTalk until I changed).

    He managed to find a couple of other networks that are nearby but nothing else.

    I have a laptop (windows 7) who finds the router Orange immediately. I tested the adapter with the laptop and it finds the router Orange plus about 10 other nearby networks.

    I rang Orange who crossed their tests and not found any problems. I uninstalled and reinstalled the adapter on the windows XP desktop, but I get the same result.

    Can anyone help?

    Thank you

    Thanks for the reply.

    I got it finally work last night after a day of cleaning up!

    Even if the network does not have to be detected in the available wireless networks "choose" I tried the "New Connection Wizard" and entered all the details that came with the router. The adapter found the Orange router but nothing else in the region.

    For now, it works but there is a problem somewhere, because I don't see any networks, I can see on my laptop.

    See you soon.

  • How to configure the router Linksys DD - WRT for WVC54GCA E4200

    I don't know how to configure the router Linksys DD - WRT for WVC54GCA E4200. DD - WRT is very complcated. Help, please! Also, I used the TZO.com to the DDNS. Can I set up the DDNS for DD - WRT router? I used the DDNS to my old model router before. Thank you.

    I followed the TZO supporter last night. I can watch my WVC54GCA outside. All solution links:

    http://tzodns.com/support/tutorials/188

    http://tzodns.com/support/tutorials/190

    Hi Majekho,

    Your domain name has decided to 99.245.xx.x. If you go to www.test.tzo.com from the location of the host, you must see this IP address. If these numbers are the same, then all with TZO works correctly. I guess that it is a simple problem with ports (80, 1024) is not open in the router and forwarded to the right internal IP address of the device (for example. 192.168.1.xxx).

    In addition, if you have a DSL, you will need to call your ISP and ask them to show you how to put your modem in "bridge mode". This will disable the firewall in the modem that blocks incoming connections even if you open ports in your router.
    In addition, during the test, it is best to test on your device remotely, this is due to a common problem called loopback with most routers. For more information about looping, take a look at:

    http://helpdesk.TZO.com/cgi-bin/KB.cgi?view=140

  • Router EA4500 I can't connect into account outside the home

    I Born just this topic http://community.linksys.com/t5/Wireless-Routers/I-can-t-login-into-smart-wifi-router-outside-home/t...

    and check my email for registration - when I click on the page open link says I'm already registered.

    No idea how to solve this problem?

    Ensure that the ISP's modem has not built into the router. This can interfere with remote access to your router main host.

    Can try to disable your account Smart WIFi or see if you can remove the acocunt router then re - add again.

  • EA6500 unable to connect to the router after Time Machine

    Just got an EA6500 - updated to the latest firmware available.

    I have attached 2 x WD NAS and 1 x WD through the USB port of the device.

    Each time after I finished running Time Machine on the MacBookPro (written to one of the WD NAS), I can no more connection to the router as neither the local IP, or the cisco connect cloud. The error message I get (loosely formulated) is: unable to connect to the router. Please ensure that the router is connected to the internet.

    At this point, all the devices connected to the router (wired and wireless) still can access Internet perfectly. Only the console of the router is therefore more accessible.

    Anyone else have the issue?

    Any ideas on how to solve it?

    Contact support for Cisco and the person advised me to do a factory reset (even if the router is new with no customization!). Regardless, it now works correctly. Cisco Cloud Connect works always before, during, and after a Time Machine.

    "When in doubt, try to turn the grid and the.

  • Cant SSH from outside on Ethernet but it can if the Wifi! Help

    Thus,.

    If my SSH server is connected to the router via Wifi, I can connect inside AND outside the network with port forwarding.

    If the SSH server is on Ethernet, I can SSH connect internally in the local network, but NOT VIA the external network!

    Machines of same, the client and server. Only difference is Wifi or Ethernet.  Reproduce this problem on two SSH servers to rule out the possibility that it was my server.

    Help please.

    You adjust the port forwarding in the transition from wireless to wired?

  • How to change the encryption type M252dw printer WPA2 (WPA - PSK) for the WPA used by the router?

    We had to change the type of encryption on our WPA2 WiFi router (LAN setup origin, on which to install and successfully used our M252dw printer) and use simple WPA, to solve some other problems of connectivity.

    NOW, the HP printer, we have (M252dw) apparently does not automatically reset the encryption type.

    Apparently, he has no way to automatically start "from scratch" when connecting to the new configuration of router.

    Even with ALL the rest on the LAN works fine and speaking well, including WiFi laptops and smart phones, the HP printer sees the new name of WiFi SSD connects to the router in order to attempt a connection, accepts the new password WPA, but RETAINS THE WPA - PSK PARAMETER OF CONFIGURATION PREVIOUS.

    We know, because after that the printer fails to connect, print the network SHOWS Test report this known problem in the paragraph of the resolution of the problems, but worthless advice said to "run the setup of wireless network for re - enter your network WPA wireless security password. The WPA authentication on your HP printer has been changed from the default setting. This can cause problems connecting to your wireless network, if your wireless router does not use the same breed of WPA authentication.

    Well, DUH.

    Mind you, there is NOTHING in the post above that says:
    1) go to "this" menu item.

    2) click "this" option to change the encryption method.

    (3) select the method (SSID, WEP, WPA, WPA2) that corresponds to your router.

    ... because... There seems to be NO option ANYWHERE in ANY menu that offers this choice.

    HE DIDN'T THERE HAS NO BUTTON, OPTION, SELECTION, OR ADVICE IN THE MANUAL TO RESET OR CHOOSE WPA!

    There is a checklist wonderfully unnecessary, repeated throughout your manuals and on the site, basically saying

    ' Check the type of printer encryption (WEP, WPA, WPA2, etc.) corresponds to the router.

    Well well... What do you do when you KNOW that it IS NOT?

    Thanks to try at least, I appreciate it.

    Unfortunately, it did not work;

    but it leads to find the answer for later use.

    Summary -

    After selecting
    Printer flow treatment and deleted the saved connection data, an IPv4, subnet mask and default gateway address (router address IPv4) and IPv6 turned power on.

    Then... I did this:

    (1) Went back to and IPv6 turned to back, leaving only ON IPv4.

    2) went back to and returned once again the preferred settings.
    Address: 192.168.254.250

    Mask: 255.255.255.0

    Default gateway: 192.168.254.254

    3) reinforced by the "Wizard" where he immediately found the SSID of the wireless router.

    (4) select the SSID of the router

    (5) when it is asked for the password (which is actually just a 'word' with WPA pass) I got that.

    (6) given the printer attempts to connect and failed.

    WPA - PSK same listed, even noted on the test report from network once more.

    Therefore, no chance after Restore Defaults.

    It really would have been nice if HP had made sure this option actually actually reset * ALL * default settings, including the wiping WPA2 security type.

    (Just for reference, the DHCP range is set to 192.168.254.15 - 192.168.254.47, so that the fixed IP addresses assigned, like this printer, you can assign DHCP to be defined to ensure no changes outside.

    This printer is the FIRST device assigned a fixed IP address, to make sure that nothing else can come into conflict with the IP address and eliminate it as a cause as possible.)

    OK - so after your suggestion, I am inspired to re - enter the menu and look at it again.

    I had already looked through what I have and not able to find the submenu I thought that has been included by HP...

    .. .or I would expect a user was manually choose method/type of security encryption (SSID, WEP, WPA, WPA2)

    .. .or at least handed to "REMOVE/RESET/nothing: Please ask the next router you are trying to connect to use"

    One thing I found there is the option that resembled what I wanted now:

    That seemed to be the best thing after trying to 'Network Defaults' so I did.

    Then did a not through all the steps above, 1-6...

    * SUCCESS *.

    ALSO: The printer is already running on each PC had to be "retired" in Windows

    -According to the right

    -Then follow up

    -Waited for printer not found, click it, and then select

    Thank you HP - I just needed to find out who Reset was correct.


    Now - I humbly suggest stating that in the manual.

    Under the line "Verify encryption type corresponds to router", you could add something simple like:

    "IF it isn't, then select and your printer will automatically ask the next router you are trying to connect with and correspond to this type of encryption."

  • How the router can understand protocols such as SSH or telnet

    How the router can understand protocols such as SSH or telnet
    and device for layer 3 router

    second question, I found this accessory of CCNA security book Keith Barker
    wrote it router look at application layer information how?

    Thank you in advance.

    Hello

    I think that confuse you routing process.

    Router; route packages using their layer 3 address.

    This means not router cannot understand the upper layer protocols. There just transmission by addressess of layer 3.

    for example: we can define Access-list for tcp and udp layer 4 packets. router can decide whether to permit or refuse even if these lists filter by glance in the section layer 4 of the package.

    In an SSH or Telnet session, role of the router is terminal.

    Intermediate device belongs in the the router routing process.

    Best regards.

Maybe you are looking for