<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH Access denied in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ssh-access-denied/m-p/3388590#M556725</link>
    <description>Thanks It works</description>
    <pubDate>Thu, 24 May 2018 15:18:04 GMT</pubDate>
    <dc:creator>Kasun1</dc:creator>
    <dc:date>2018-05-24T15:18:04Z</dc:date>
    <item>
      <title>SSH Access denied</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-access-denied/m-p/3197955#M556715</link>
      <description>&lt;P&gt;Hi Community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you please advise me where is my problem:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When I trying to connect Cisco 881 through SSH, it answers me login and password, but deny access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is full config:&lt;/P&gt;
&lt;P&gt;!&lt;BR /&gt;! Last configuration change at 17:08:19 UTC Thu Oct 12 2017 by admin&lt;BR /&gt;version 15.2&lt;BR /&gt;no service pad&lt;BR /&gt;service timestamps debug datetime msec&lt;BR /&gt;service timestamps log datetime msec&lt;BR /&gt;service password-encryption&lt;BR /&gt;!&lt;BR /&gt;hostname blab01&lt;BR /&gt;!&lt;BR /&gt;boot-start-marker&lt;BR /&gt;boot-end-marker&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;logging buffered 51200 warnings&lt;BR /&gt;enable secret 4 Ivcw.NXKbPGnUJY1w35CDH7n2ZASu5D1k&lt;BR /&gt;!&lt;BR /&gt;aaa new-model&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa authentication login default local&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;aaa session-id common&lt;BR /&gt;memory-size iomem 10&lt;BR /&gt;!&lt;BR /&gt;crypto pki trustpoint TP-self-signed-3570458249&lt;BR /&gt; enrollment selfsigned&lt;BR /&gt; subject-name cn=IOS-Self-Signed-Certificate-3570458249&lt;BR /&gt; revocation-check none&lt;BR /&gt; rsakeypair TP-self-signed-3570458249&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto pki certificate chain TP-self-signed-3570458249&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;no ip domain lookup&lt;BR /&gt;ip domain name blrlab.com&lt;BR /&gt;ip inspect name outside_fw icmp&lt;BR /&gt;ip inspect name outside_fw http&lt;BR /&gt;ip inspect name outside_fw https&lt;BR /&gt;ip inspect name outside_fw tcp&lt;BR /&gt;ip inspect name outside_fw udp&lt;BR /&gt;ip inspect name outside_fw dns&lt;BR /&gt;ip inspect name outside_fw pptp&lt;BR /&gt;ip cef&lt;BR /&gt;no ipv6 cef&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;multilink bundle-name authenticated&lt;BR /&gt;license udi pid CISCO881-SEC-K9 sn FGL181021M3&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;username admin privilege 15 secret 4 hFK.2TEAvHhQRoMQRkWa26vz.q2Vd7U&lt;BR /&gt;username bbbadmin privilege 15 password 7 013D1312F751F6E4D&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip ftp source-interface Vlan1&lt;BR /&gt;ip ftp username cisco&lt;BR /&gt;ip ftp password 7 121A0C041104&lt;BR /&gt;ip ssh time-out 60&lt;BR /&gt;ip ssh authentication-retries 5&lt;BR /&gt;ip ssh port 5722 rotary 1&lt;BR /&gt;ip ssh logging events&lt;BR /&gt;ip ssh version 2&lt;BR /&gt;! &lt;BR /&gt;!&lt;BR /&gt;crypto isakmp policy 1&lt;BR /&gt; encr 3des&lt;BR /&gt; hash md5&lt;BR /&gt; authentication pre-share&lt;BR /&gt; group 2&lt;BR /&gt;crypto isakmp key faltecvpn address MANCH-IP no-xauth&lt;BR /&gt;crypto isakmp keepalive 120&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto ipsec transform-set 3DES-SHA esp-3des esp-md5-hmac &lt;BR /&gt; mode tunnel&lt;BR /&gt;crypto ipsec transform-set 3DES-MD5 esp-3des esp-md5-hmac &lt;BR /&gt; mode tunnel&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;crypto map outside_map 10 ipsec-isakmp &lt;BR /&gt; description SHRB -- MNCH&lt;BR /&gt; set peer MANCH-IP&lt;BR /&gt; set transform-set 3DES-MD5 &lt;BR /&gt; match address data_SHRB_MNCH&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet0&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet1&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet2&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet3&lt;BR /&gt; no ip address&lt;BR /&gt;!&lt;BR /&gt;interface FastEthernet4&lt;BR /&gt; description VIDEOTRON&lt;BR /&gt; ip address EXT-IP 255.255.255.252&lt;BR /&gt; ip nat outside&lt;BR /&gt; ip inspect outside_fw out&lt;BR /&gt; ip virtual-reassembly in&lt;BR /&gt; duplex full&lt;BR /&gt; speed auto&lt;BR /&gt; crypto map outside_map&lt;BR /&gt;!&lt;BR /&gt;interface Vlan1&lt;BR /&gt; description $ETH_LAN$&lt;BR /&gt; ip address 192.168.1.1 255.255.255.0&lt;BR /&gt; ip nat inside&lt;BR /&gt; ip virtual-reassembly in&lt;BR /&gt; ip tcp adjust-mss 1452&lt;BR /&gt;!&lt;BR /&gt;ip forward-protocol nd&lt;BR /&gt;ip http server&lt;BR /&gt;ip http access-class 23&lt;BR /&gt;ip http authentication local&lt;BR /&gt;ip http secure-server&lt;BR /&gt;ip http timeout-policy idle 60 life 86400 requests 10000&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;ip nat inside source list NAT_BLAB interface FastEthernet4 overload&lt;BR /&gt;ip nat inside source static tcp 192.168.1.3 25 EXT-IP 25 extendable&lt;BR /&gt;ip nat inside source static tcp 192.168.1.25 80 EXT-IP 80 extendable&lt;BR /&gt;ip nat inside source static tcp 192.168.1.25 443 EXT-IP 443 extendable&lt;BR /&gt;ip nat inside source static tcp 192.168.1.3 1723 EXT-IP 1723 extendable&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 24.37.183.233&lt;BR /&gt;!&lt;BR /&gt;ip access-list extended NAT_BLAB&lt;BR /&gt; deny ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255&lt;BR /&gt; permit ip 192.168.1.0 0.0.0.255 any&lt;BR /&gt;ip access-list extended OUTSIDE_IN&lt;BR /&gt; permit tcp any host EXT-IP eq smtp&lt;BR /&gt; permit gre any host EXT-IP&lt;BR /&gt; permit tcp any host EXT-IP eq 1723&lt;BR /&gt; permit tcp any host EXT-IP eq www&lt;BR /&gt; permit tcp any host EXT-IP eq 443&lt;BR /&gt; permit udp any eq isakmp host EXT-IP eq isakmp&lt;BR /&gt;ip access-list extended data_SHRB_MNCH&lt;BR /&gt; remark Traffic entre SHRB et MNCH&lt;BR /&gt; permit ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255&lt;BR /&gt;!&lt;BR /&gt;no cdp run&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;control-plane&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;line con 0&lt;BR /&gt; exec-timeout 0 0&lt;BR /&gt; password 7 09625B15F5F246E&lt;BR /&gt; logging synchronous&lt;BR /&gt; no modem enable&lt;BR /&gt; speed 115200&lt;BR /&gt;line aux 0&lt;BR /&gt;line vty 0 4&lt;BR /&gt; exec-timeout 0 0&lt;BR /&gt; password 7 0228114D181D295D&lt;BR /&gt; logging synchronous&lt;BR /&gt; rotary 1&lt;BR /&gt; transport input ssh&lt;BR /&gt; transport output ssh&lt;BR /&gt;line vty 5 15&lt;BR /&gt; privilege level 15&lt;BR /&gt; password 7 0228114D5B0A5D&lt;BR /&gt; transport input all&lt;BR /&gt;!&lt;BR /&gt;!&lt;BR /&gt;end&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 18:36:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-access-denied/m-p/3197955#M556715</guid>
      <dc:creator>Chubariev88</dc:creator>
      <dc:date>2020-02-21T18:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Access denied</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-access-denied/m-p/3198065#M556719</link>
      <description>&lt;P&gt;you need to add one more line to your line vty 0 4 stanza&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;login local&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Fri, 13 Oct 2017 00:43:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-access-denied/m-p/3198065#M556719</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2017-10-13T00:43:35Z</dc:date>
    </item>
    <item>
      <title>Re: SSH Access denied</title>
      <link>https://community.cisco.com/t5/network-access-control/ssh-access-denied/m-p/3388590#M556725</link>
      <description>Thanks It works</description>
      <pubDate>Thu, 24 May 2018 15:18:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ssh-access-denied/m-p/3388590#M556725</guid>
      <dc:creator>Kasun1</dc:creator>
      <dc:date>2018-05-24T15:18:04Z</dc:date>
    </item>
  </channel>
</rss>

