<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: WinSCP and FMC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4072899#M1069459</link>
    <description>&lt;P&gt;The files in question are just very short plain text files so it's much much easier to just cat them to your terminal session. Then copy and paste into a local text editor and save as the same file name.&lt;/P&gt;</description>
    <pubDate>Fri, 24 Apr 2020 03:17:05 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2020-04-24T03:17:05Z</dc:date>
    <item>
      <title>WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4055228#M1068418</link>
      <description>&lt;P&gt;Can anyone tell me how to get the rsa key file and the csr out of the FMC using WinSCP. I've seen so many video that show people using WinSCP to log into the FMC and get the .key and .csr file but they don't go into how WinSCP should be setup to get that to work.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone experience this problem with WinSCP?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 16:01:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4055228#M1068418</guid>
      <dc:creator>donald.heslop1</dc:creator>
      <dc:date>2020-03-30T16:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4055372#M1068420</link>
      <description>&lt;P&gt;Use SCP protocol (port tcp/22).&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 17:56:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4055372#M1068420</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-03-30T17:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4055392#M1068421</link>
      <description>Mauris,&lt;BR /&gt;I did and it will not connect. I get the error that I attached to my original post.&lt;BR /&gt;</description>
      <pubDate>Mon, 30 Mar 2020 18:20:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4055392#M1068421</guid>
      <dc:creator>donald.heslop1</dc:creator>
      <dc:date>2020-03-30T18:20:31Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4055455#M1068424</link>
      <description>&lt;P&gt;The user you are logging in with needs to have rights to access the FMC CLI / Linux shell.&amp;nbsp; Add your user to the Shell Access Filter under System &amp;gt; Users or log in with a user that already has access to the CLI&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="shell access.jpg" style="width: 458px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/70285i4FEBE8ABA32353C8/image-size/large?v=v2&amp;amp;px=999" role="button" title="shell access.jpg" alt="shell access.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 19:44:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4055455#M1068424</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-03-30T19:44:20Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4055463#M1068425</link>
      <description>Mauris,&lt;BR /&gt;I am using the local admin account on the FMC (6.5.0). That Shell Access Filter is under External Authentication which I am not using.&lt;BR /&gt;</description>
      <pubDate>Mon, 30 Mar 2020 19:52:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4055463#M1068425</guid>
      <dc:creator>donald.heslop1</dc:creator>
      <dc:date>2020-03-30T19:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4055469#M1068427</link>
      <description>&lt;P&gt;I am assuming that the admin account can access the CLI of the FMC?&amp;nbsp; When you log in do you get to the &amp;gt; prompt or straight to the Linux Shell (expert mode)?&amp;nbsp; If you only get to the &amp;gt; enter expert mode and then try accessing from the WinSCP.&amp;nbsp; The account needs to go directly to the Linux shell.&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 19:59:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4055469#M1068427</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-03-30T19:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4055501#M1068432</link>
      <description>&lt;P&gt;Marius,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm still getting the same issue even though I logged into the FMC via putty and entered expert mode. See attached screenshot. You will see the putty session and the error message I'm getting in WinSCP&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 20:47:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4055501#M1068432</guid>
      <dc:creator>donald.heslop1</dc:creator>
      <dc:date>2020-03-30T20:47:16Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4055521#M1068434</link>
      <description>&lt;P&gt;Odd, I am able to connect to my FMC using WinSCP, however when I login to the CLI I get directly to the Linux Shell.&amp;nbsp; I suspect that this is your issue that when you are logging in via WinSCP you are not going directly to the Linux Shell.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Mar 2020 21:22:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4055521#M1068434</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-03-30T21:22:29Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4072798#M1069455</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;since version 6.4 (if I recall correctly), SSH login to FMC doesn't open directly with the Linux shell prompt, but into the custom CLI where you need to execute the command "expert" in order to get to the real bash.&lt;/P&gt;&lt;P&gt;Unfortunately this new feature makes impossible to use from a remote PC the command scp (or Winscp) to copy files to/from the FMC.&lt;/P&gt;&lt;P&gt;I've just spent 4 hours trying different options to be able to copy the last successful backup from my broken FMCv. One alternative that theoretically should work, I've found in the Winscp documentation: w&lt;SPAN&gt;ith&amp;nbsp;&lt;/SPAN&gt;SCP&lt;SPAN&gt;&amp;nbsp;protocol, you can specify a command as custom shell on the&amp;nbsp;&lt;/SPAN&gt;&lt;EM&gt;&lt;A href="https://winscp.net/eng/docs/ui_login_scp#shell" target="_blank" rel="noopener"&gt;SCP/Shell page&lt;/A&gt;&lt;/EM&gt;&lt;SPAN&gt;&amp;nbsp;of Advanced Site Settings dialog. I've tried replacing the value of [Shell:] with "expert", but didn't do the trick. In theory this is used when you need to execute "sudo -s" before copying the files as root.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So, I've gave up and used the scp command the other way around: execute it on the FMC and use a remote SSH server to transfer the files. As I didn't have at hand a Linux machine, I had to install the "OpenSSH SSH Server" on my notebook (if you have Windows 10 version 1803 or newer, you'll find it in the Settings app, Apps &amp;gt; Apps &amp;amp; features &amp;gt; Manage optional features).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm still curious if there is a working solution to the initial problem created by the intermediary CLI.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Apr 2020 22:20:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4072798#M1069455</guid>
      <dc:creator>Gabriel Copil</dc:creator>
      <dc:date>2020-04-23T22:20:16Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4072899#M1069459</link>
      <description>&lt;P&gt;The files in question are just very short plain text files so it's much much easier to just cat them to your terminal session. Then copy and paste into a local text editor and save as the same file name.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2020 03:17:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4072899#M1069459</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-04-24T03:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4073199#M1069472</link>
      <description>&lt;P&gt;For those particular files, you are totally right.&lt;/P&gt;&lt;P&gt;But still, for transfer of a backup file or a troubleshooting file, it will be nice to learn the workaround for using scp from remote PC to the newer versions of FMC (&amp;gt;=6.4)&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2020 09:34:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4073199#M1069472</guid>
      <dc:creator>Gabriel Copil</dc:creator>
      <dc:date>2020-04-24T09:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4073315#M1069479</link>
      <description>&lt;P&gt;FMC won't act as an SCP server but it works just fine as an SCP client.&lt;/P&gt;
&lt;P&gt;Here's a transfer from my FMC VM (version 6.6) to another Linux host running SCP server (my EVE-NG host in this example):&lt;/P&gt;
&lt;PRE&gt;root@fmc:~# scp preinstall.rpms.list root@172.31.1.13:/var/tmp
root@172.31.1.13's password: 
preinstall.rpms.list                                                                                                                                                            100%  163   369.8KB/s   00:00    
root@fmc:~#&lt;/PRE&gt;
&lt;P&gt;We can now see the transferred file on the remote host:&lt;/P&gt;
&lt;PRE&gt;root@eve-ng:/var/tmp# ls -al
total 12
drwxrwxrwt  2 root root 4096 Apr 24 15:21 .
drwxr-xr-x 12 root root 4096 Jun  9  2018 ..
-rw-r--r--  1 root root  163 Apr 24 15:21 preinstall.rpms.list
root@eve-ng:/var/tmp#&lt;/PRE&gt;
&lt;P&gt;Since the remote host does run an SCP server I can move the file onto my Windows host using the WinSCP client:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="WinSCP screenshot" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/72935iDB3514B03AF4CC7A/image-size/large?v=v2&amp;amp;px=999" role="button" title="WinSCP screenshot.PNG" alt="WinSCP screenshot" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;WinSCP screenshot&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;It's a bit of a kludge to have to go via a third host (i.e. a Linux box running SCP server) but once you have it setup it works perfectly fine. You can use this process in either direction&amp;nbsp; - to either get files from or put files onto the FMC. Here is a SCP file copy from the EVE-NG server to FMC:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;root@fmc:~# &lt;STRONG&gt;&lt;FONT color="#FF0000"&gt;scp root@172.31.1.13:/var/tmp/dcprime.cer dcprime.cer&lt;/FONT&gt;&lt;/STRONG&gt;
root@172.31.1.13's password: 
dcprime.cer                                                                                                                                                                     100%  625     1.4MB/s   00:00    
root@fmc:~# 
root@fmc:~# 
root@fmc:~# ls -al
total 748
drwx------  7 root root   4096 Apr 24 12:34 .
drwxr-xr-x 23 root root   4096 Apr  7 19:00 ..
-rw-------  1 root root   3280 Apr  9 10:52 .bash_history
drwx------  2 root root   4096 Sep 27  2019 .cache
-r--------  1 root root     37 Apr  7 18:31 .erlang.cookie
drwxr-xr-x  2 root root   4096 Aug 16  2017 .oracle_jre_usage
-rw-------  1 root root   1024 Apr  9 11:06 .rnd
drwxr-xr-x  3 root root   4096 Aug 27  2017 .sqlanywhere16
drwxr-xr-x  3 root root   4096 Apr  7 18:10 .sqlanywhere17
drwx------  2 root root   4096 Aug 16  2017 .ssh
-rw-r--r--  1 root root    163 Apr 24 12:06 ?
&lt;FONT color="#FF0000"&gt;&lt;STRONG&gt;-rw-r--r--  1 root root    625 Apr 24 12:33 dcprime.cer&lt;/STRONG&gt;&lt;/FONT&gt;
-rw-r--r--  1 root root 228416 Jan 20  2017 install.log
-rw-r--r--  1 root root 227030 Apr  4 14:50 preinstall.log
-rw-r--r--  1 root root  17741 Apr  4 14:50 preinstall.packages.list
-rw-r--r--  1 root root    163 Apr  4 14:50 preinstall.rpms.list
-rw-r--r--  1 root root 115845 Jan 20  2017 strip.install.log
-rw-r--r--  1 root root 114577 Apr  4 14:50 strip.preinstall.log
root@fmc:~# 
&lt;/PRE&gt;</description>
      <pubDate>Fri, 24 Apr 2020 12:36:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4073315#M1069479</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-04-24T12:36:07Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4073343#M1069484</link>
      <description>&lt;P&gt;Thank you for the explanations, a similar solution I've used also - but without the 3rd machine I had to install Open SSH server on my notebook.&lt;BR /&gt;I have to disagree that there is no "SCP server", because scp is using the SSH protocol, and as long as you can login via SSH on the FMC, scp would work also.&lt;BR /&gt;The fact is, it was working for FMC versions &amp;lt;6.4, to prove it I've just used WinSCP to connect to an FMC v.6.2.3.10:&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="WinSCP to an FMC v.6.2.3.x.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/72941i376946A208369D9B/image-size/medium?v=v2&amp;amp;px=400" role="button" title="WinSCP to an FMC v.6.2.3.x.png" alt="WinSCP to an FMC v.6.2.3.x.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, my question still remains: how can we overcome the new intermediary CLI feature that was implemented in 6.4, if we don't want to use a 3rd device (or to install Open SSH server on our Windows computers) and we want to use the same scp/WinSCP operation that was working in all the previous versions of the FMC?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Apr 2020 13:05:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4073343#M1069484</guid>
      <dc:creator>Gabriel Copil</dc:creator>
      <dc:date>2020-04-24T13:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4073829#M1069509</link>
      <description>&lt;P&gt;LE, the below "solution" works only for FMC v.6.3.x and v.6.4.x&lt;/P&gt;&lt;P&gt;Unfortunately in v.6.5, the ability to disable the FMC CLI was deprecated, so the only possibility is to execute the scp command only directly in the FMC and use a remote SSH server to transfer files (Linux box or Open SSH for Windows).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For v.6.3 and 6.4, here is the solution for WinSCP's failure to connect with the error message:&lt;/P&gt;&lt;P&gt;&lt;FONT face="courier new,courier" size="2"&gt;Error skipping startup message. Your shell is probably incompatible with the application (BASH is recommended).&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;You need to go in the GUI of the FMC, in System &amp;gt; Configuration &amp;gt; Console Configuration and disable the option "Enable CLI Access". Then press &amp;lt;Save&amp;gt; and try to logon with a ssh client (e.g. Putty) to the FMC management IP. If after you enter the password, you get directly the Linux shell prompt (e.g. admin@test-fmc-01:~$ ), then WinSCP should work correctly also.&lt;/P&gt;&lt;P&gt;If you still get the FMC CLI ( just the symbol "&amp;gt;" ), then make sure you've pressed the &amp;lt;Save&amp;gt; button (ask me how I know ;-))&lt;/P&gt;&lt;P&gt;After I've disabled this option, I could logon to the FMC v.6.4.0.8 with WinSCP, like expected.&lt;/P&gt;&lt;P&gt;You can read here about the option "Enable CLI Access":&amp;nbsp;&amp;nbsp;&lt;A title="About the Firepower Management Center CLI" href="https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/command_line_reference.html#id_75009" target="_blank" rel="noopener"&gt;About the Firepower Management Center CLI&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Apr 2020 02:26:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4073829#M1069509</guid>
      <dc:creator>Gabriel Copil</dc:creator>
      <dc:date>2020-04-25T02:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4151625#M1073943</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;as you can see from the follwing output the default cli has changed:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;admin@fmc:~$ more /etc/passwd&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;root:x:0:0:Operator:/root:/bin/sh&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;bin:x:1:1:bin:/bin:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;daemon:x:2:2:daemon:/sbin:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;mysql:x:27:27:MySQL:/var/lib/mysql:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;nobody:x:99:99:nobody:/:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sshd:x:33:33:sshd:/:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;www:x:67:67:HTTP server:/var/www:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sfrna:x:88:88:SF RNA User:/Volume/home/sfrna:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;snorty:x:90:90:Snorty User:/Volume/home/snorty:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sfsnort:x:95:95:SF Snort User:/Volume/home/sfsnort:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sfremediation:x:103:103::/Volume/home/remediations:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;admin:x:100:100::/Volume/home/admin:/usr/bin/clish&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;casuser:x:101:104:CiscoUser:/var/opt/CSCOpx:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;lamplighter:x:110:110::/var/opt/lamplighter:/bin/sh&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;monetdb:x:111:111::/Volume/lib/monetdb:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;fatjon:x:1000:201::/Volume/home/fatjon:/usr/bin/clish&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can modify the default cli of a user by using the following command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;root@fmc:/Volume/home/admin# &lt;STRONG&gt;usermod --shell /bin/bash admin&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;now you will be able to use winscp or an sftp client.&lt;/P&gt;&lt;P&gt;after you've finished remeber to rollback:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;root@fmc:/Volume/home/admin# &lt;STRONG&gt;usermod --shell /usr/bin/clish admin&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;KR&lt;/P&gt;&lt;P&gt;f&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 20:21:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4151625#M1073943</guid>
      <dc:creator>Fatjon.Celaj</dc:creator>
      <dc:date>2020-09-15T20:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4151630#M1073944</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;first connect in ssh then reach the expert mode:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Cisco Firepower Management Center for VMWare v6.6.0.1 (build 7)&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&amp;gt; expert&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;as you can see from the follwing output the default cli has changed:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;admin@fmc:~$ more /etc/passwd&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;root:x:0:0:Operator:/root:/bin/sh&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;bin:x:1:1:bin:/bin:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;daemon:x:2:2:daemon:/sbin:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;mysql:x:27:27:MySQL:/var/lib/mysql:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;nobody:x:99:99:nobody:/:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sshd:x:33:33:sshd:/:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;www:x:67:67:HTTP server:/var/www:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sfrna:x:88:88:SF RNA User:/Volume/home/sfrna:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;snorty:x:90:90:Snorty User:/Volume/home/snorty:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sfsnort:x:95:95:SF Snort User:/Volume/home/sfsnort:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sfremediation:x:103:103::/Volume/home/remediations:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;admin:x:100:100::/Volume/home/admin:/usr/bin/clish&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;casuser:x:101:104:CiscoUser:/var/opt/CSCOpx:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;lamplighter:x:110:110::/var/opt/lamplighter:/bin/sh&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;monetdb:x:111:111::/Volume/lib/monetdb:/sbin/nologin&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;fatjon:x:1000:201::/Volume/home/fatjon:/usr/bin/clish&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you can modify the default cli of a user by using the following command:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;A href="mailto:admin@fmc:~$" target="_blank"&gt;admin@fmc:~$&lt;/A&gt; sudo su&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;A href="mailto:root@fmc:/Volume/home/admin$" target="_blank"&gt;root@fmc:/Volume/home/admin$&lt;/A&gt; &lt;STRONG&gt;usermod --shell /bin/bash admin&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;now you will be able to use winscp or an sftp client.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;after you've finished remeber to rollback:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;root@fmc:/Volume/home/admin# &lt;STRONG&gt;usermod --shell /usr/bin/clish admin&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;KR&lt;/P&gt;&lt;P&gt;f&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Sep 2020 20:24:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4151630#M1073944</guid>
      <dc:creator>Fatjon.Celaj</dc:creator>
      <dc:date>2020-09-15T20:24:37Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4474835#M1084014</link>
      <description>&lt;P&gt;Thank you. Running veersion 6.5.0 ant your trick did the job.&lt;/P&gt;&lt;P&gt;In my case, as admin user in FMC, I used sudo for those commands.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt; 27/09/2021   17:37.11   /home/mobaxterm  scp -P 22 admin@10.1.1.120:/var/sf/backup/FMC-2021-05-25T19-05-57.tar .&lt;BR /&gt;admin@10.1.1.120's password:&lt;BR /&gt;FMC-2021-05-25T19-05-57.tar 100% 309MB 5.3MB/s 00:58&lt;BR /&gt;✔&lt;/P&gt;&lt;P&gt; 27/09/2021   17:48.14   /home/mobaxterm &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Keep in mind you can change cli shell like this as well:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;You may need to use "sudo" before the command or log in as a root with:
$ sudo su 
Password:
# 

- This will tell you shells available
cat /etc/shells
/bin/sh
/bin/bash
/bin/rbash
/bin/tcsh
/sbin/nologin
/usr/bin/clish --&amp;gt; by default you will have this (the one that needs "expert" command first)

- Change shell for the user:
admin@FMC:~$ chsh
Password: 
Changing the login shell for admin
Enter the new value, or press ENTER for the default
        Login Shell [/usr/bin/clish]: /bin/bash --&amp;gt; We would need bash to avoid "non expert" part.

- Check if change has been done:
admin@FMC:~$ cat /etc/passwd
[...]
admin:x:100:100::/Volume/home/admin:/bin/bash
[...]
&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 23 Feb 2022 17:11:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4474835#M1084014</guid>
      <dc:creator>pzkqx6000</dc:creator>
      <dc:date>2022-02-23T17:11:46Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4584586#M1088881</link>
      <description>&lt;P&gt;Hi, How can I transfer files to the FMC with WinSCP, I desperatly need to upgrade an old FMC and sensor but the GUI upload won't work. I can connect to the FMC with WinSCP and I located the updates folder in /Volume/6.1.0/sf/updates on the FMC but when I try to upload it just gives me&amp;nbsp;scp: /Volume/6.1.0/sf/updates/Sourcefire_3D_Defense_Center_S3_Upgrade-6.2.3-113.sh: Permission denied. I can elivate to expert and sudo su in CLI. I can also download files from the FMC with WinSCP but in this case I want to upload the sensor and FMC 6.2.3 patch. This is an old 6.1.2.57 if that matters. Maybe trying to upload to /Volume/6.1.0/sf/updates is the wrong way to go about this?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2022 17:14:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4584586#M1088881</guid>
      <dc:creator>jgustafzon</dc:creator>
      <dc:date>2022-04-03T17:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4585188#M1088897</link>
      <description>&lt;P&gt;When you connect to FMC with scp, use the root user (or temporarily chmod the target directory to allow write by all users).&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2022 12:27:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4585188#M1088897</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-04-04T12:27:22Z</dc:date>
    </item>
    <item>
      <title>Re: WinSCP and FMC</title>
      <link>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4665780#M1092498</link>
      <description>&lt;P&gt;You can also set the Shell inside the WinSCP session options to expert. With this option you can directly connect via WinSCP to FMC.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV id="tinyMceEditor_b2438d0c83a961alfredthyri_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Aug 2022 15:02:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/winscp-and-fmc/m-p/4665780#M1092498</guid>
      <dc:creator>alfred.thyri</dc:creator>
      <dc:date>2022-08-08T15:02:41Z</dc:date>
    </item>
  </channel>
</rss>

