<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure Shell configuration using local users not working for Firepower version 6.4 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/secure-shell-configuration-using-local-users-not-working-for/m-p/4113520#M1071700</link>
    <description>Hi Marvin,&lt;BR /&gt;&lt;BR /&gt;You answer is 100% correct and its really helpful.&lt;BR /&gt;&lt;BR /&gt;Below are the steps to explain it in layman's terms :&lt;BR /&gt;On FMC -&lt;BR /&gt;Go to System -&amp;gt; Configuration -&amp;gt; Access list and add the IP address(es) for SSH and HTTPS access.&lt;BR /&gt;On FTD -&lt;BR /&gt;used CLI command "configure ssh-access-list 10.10.10.10/32, 10.10.10.11/32"&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;L.</description>
    <pubDate>Sun, 05 Jul 2020 13:24:34 GMT</pubDate>
    <dc:creator>laukik.nahar1</dc:creator>
    <dc:date>2020-07-05T13:24:34Z</dc:date>
    <item>
      <title>Secure Shell configuration using local users not working for Firepower version 6.4</title>
      <link>https://community.cisco.com/t5/network-security/secure-shell-configuration-using-local-users-not-working-for/m-p/4111832#M1071597</link>
      <description>&lt;P&gt;Dear Friends,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tried configuring the Secure Shell from Devices-&amp;gt;Platform Settings-&amp;gt;Secure Shell&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Added object with IP address for local Admin user and the interface from where it was taking access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the other users are also able to access the CLI using PUTTY.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please find the attached error message while trying to deploy the policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;URL followed for reference are -&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200701-Configuration-of-Management-access-to-FT.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200701-Configuration-of-Management-access-to-FT.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 12:40:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/secure-shell-configuration-using-local-users-not-working-for/m-p/4111832#M1071597</guid>
      <dc:creator>laukik.nahar1</dc:creator>
      <dc:date>2020-07-01T12:40:56Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Shell configuration using local users not working for Firepower version 6.4</title>
      <link>https://community.cisco.com/t5/network-security/secure-shell-configuration-using-local-users-not-working-for/m-p/4111884#M1071599</link>
      <description>&lt;P&gt;You can proceed despite that warning. It's just telling you some part of the platform settings config contains reference to the deprecated protocols.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 13:58:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/secure-shell-configuration-using-local-users-not-working-for/m-p/4111884#M1071599</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-07-01T13:58:23Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Shell configuration using local users not working for Firepower version 6.4</title>
      <link>https://community.cisco.com/t5/network-security/secure-shell-configuration-using-local-users-not-working-for/m-p/4111983#M1071607</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;- The deployment was successful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But the issue is that, we are able to log (SSH) into the device by users other than those mentioned in Secure Shell tab.&lt;/P&gt;&lt;P&gt;Please find the attached screenshot.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 16:53:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/secure-shell-configuration-using-local-users-not-working-for/m-p/4111983#M1071607</guid>
      <dc:creator>laukik.nahar1</dc:creator>
      <dc:date>2020-07-01T16:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Shell configuration using local users not working for Firepower version 6.4</title>
      <link>https://community.cisco.com/t5/network-security/secure-shell-configuration-using-local-users-not-working-for/m-p/4111985#M1071608</link>
      <description>Inshort, if the admin's IP address is 192.168.1.100, users other than admin is able to get the SSH and asks for the login prompt.</description>
      <pubDate>Wed, 01 Jul 2020 16:56:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/secure-shell-configuration-using-local-users-not-working-for/m-p/4111985#M1071608</guid>
      <dc:creator>laukik.nahar1</dc:creator>
      <dc:date>2020-07-01T16:56:24Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Shell configuration using local users not working for Firepower version 6.4</title>
      <link>https://community.cisco.com/t5/network-security/secure-shell-configuration-using-local-users-not-working-for/m-p/4112009#M1071611</link>
      <description>&lt;P&gt;Do you mean users coming from an address other than the defined admin address(es)?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jul 2020 17:34:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/secure-shell-configuration-using-local-users-not-working-for/m-p/4112009#M1071611</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-07-01T17:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Shell configuration using local users not working for Firepower version 6.4</title>
      <link>https://community.cisco.com/t5/network-security/secure-shell-configuration-using-local-users-not-working-for/m-p/4112227#M1071626</link>
      <description>Yes exactly...</description>
      <pubDate>Thu, 02 Jul 2020 03:40:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/secure-shell-configuration-using-local-users-not-working-for/m-p/4112227#M1071626</guid>
      <dc:creator>laukik.nahar1</dc:creator>
      <dc:date>2020-07-02T03:40:47Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Shell configuration using local users not working for Firepower version 6.4</title>
      <link>https://community.cisco.com/t5/network-security/secure-shell-configuration-using-local-users-not-working-for/m-p/4113498#M1071697</link>
      <description>&lt;P&gt;I see the problem. The Platform settings are for ssh access to the data interface(s). See the online help which tells us the following:&lt;/P&gt;
&lt;P class="p lia-indent-padding-left-30px"&gt;&lt;EM&gt;If you want to allow SSH connections to one or more data interfaces on the &lt;SPAN class="ph"&gt;FTD&lt;/SPAN&gt; device, configure Secure Shell settings.&lt;SPAN class="ph"&gt; SSH is not supported to the Diagnostic logical interface.&lt;/SPAN&gt; The physical management interface is shared between the Diagnostic logical interface and the Management logical interface. SSH is enabled by default on the Management logical interface; however, this screen does not affect Management SSH access.&lt;/EM&gt;&lt;/P&gt;
&lt;P class="p lia-indent-padding-left-30px"&gt;&lt;EM&gt;The Management logical interface is separate from the other interfaces on the device. It is used to set up and register the device to the &lt;SPAN class="ph"&gt;Firepower Management Center&lt;/SPAN&gt;. SSH for data interfaces shares the internal&lt;SPAN class="ph"&gt; and external&lt;/SPAN&gt; user list with SSH for the Management interface. Other settings are configured separately: for data interfaces, enable SSH and access lists using this screen; SSH traffic for data interfaces uses the regular routing configuration, and not any static routes configured at setup or at the CLI.&lt;/EM&gt;&lt;/P&gt;
&lt;P class="p lia-indent-padding-left-30px"&gt;&lt;EM&gt;For the Management interface, to configure an SSH access list, see the &lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;configure ssh-access-list&lt;/SPAN&gt; &lt;/SPAN&gt; command in the &lt;A class="xref" href="https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/b_Command_Reference_for_Firepower_Threat_Defense.html" target="_blank" rel="noopener"&gt;Firepower Threat Defense Command Reference&lt;/A&gt;. To configure a static route, see the &lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;configure network static-routes&lt;/SPAN&gt; &lt;/SPAN&gt; command. By default, you configure the default route through the Management interface at initial setup.&lt;/EM&gt;&lt;/P&gt;
&lt;P class="p"&gt;I tried the above and confirmed it works.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Jul 2020 11:29:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/secure-shell-configuration-using-local-users-not-working-for/m-p/4113498#M1071697</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-07-05T11:29:12Z</dc:date>
    </item>
    <item>
      <title>Re: Secure Shell configuration using local users not working for Firepower version 6.4</title>
      <link>https://community.cisco.com/t5/network-security/secure-shell-configuration-using-local-users-not-working-for/m-p/4113520#M1071700</link>
      <description>Hi Marvin,&lt;BR /&gt;&lt;BR /&gt;You answer is 100% correct and its really helpful.&lt;BR /&gt;&lt;BR /&gt;Below are the steps to explain it in layman's terms :&lt;BR /&gt;On FMC -&lt;BR /&gt;Go to System -&amp;gt; Configuration -&amp;gt; Access list and add the IP address(es) for SSH and HTTPS access.&lt;BR /&gt;On FTD -&lt;BR /&gt;used CLI command "configure ssh-access-list 10.10.10.10/32, 10.10.10.11/32"&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;BR /&gt;L.</description>
      <pubDate>Sun, 05 Jul 2020 13:24:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/secure-shell-configuration-using-local-users-not-working-for/m-p/4113520#M1071700</guid>
      <dc:creator>laukik.nahar1</dc:creator>
      <dc:date>2020-07-05T13:24:34Z</dc:date>
    </item>
  </channel>
</rss>

