<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Changing FTD SSH access-list in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5040912#M1109922</link>
    <description>&lt;P&gt;Hello, thanks all for your responses, so the ssh-access-list is accept tcp -- anywhere anywhere state NEW tcp dpt:ssh&lt;/P&gt;&lt;P&gt;so I can't see any issue with that.&lt;/P&gt;&lt;P&gt;I can see traffic from my management box to the management interface IP on ssh being allowed, yet I am getting a timeout.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;</description>
    <pubDate>Fri, 15 Mar 2024 14:05:09 GMT</pubDate>
    <dc:creator>mrjelly</dc:creator>
    <dc:date>2024-03-15T14:05:09Z</dc:date>
    <item>
      <title>Changing FTD SSH access-list</title>
      <link>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039065#M1109848</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Is there a way to see an FTDs ssh-access-list through the FMC and even see what's on it?&lt;BR /&gt;&lt;BR /&gt;It appears that to setup an FTDs SSH access list is to use SSH access (or from the console too?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Using the Threat Detection CLI in the FMC and selecting 'Show' then ssh-access-list give back an error saying command didn't work.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 23:10:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039065#M1109848</guid>
      <dc:creator>mrjelly</dc:creator>
      <dc:date>2024-03-13T23:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: Changing FTD SSH access-list</title>
      <link>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039070#M1109849</link>
      <description>&lt;P&gt;Not sure what is the case here to see what in ACL using CLI or ssh.&lt;/P&gt;
&lt;P&gt;Unlike ASA there are many changes in FTD probably we may not understand&amp;nbsp; as expected - until you like to spend more time and co-related to it.&lt;/P&gt;
&lt;P&gt;check command reference :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/b_Command_Reference_for_Firepower_Threat_Defense/using_the_FTD_CLI.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/b_Command_Reference_for_Firepower_Threat_Defense/using_the_FTD_CLI.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2024 23:22:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039070#M1109849</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-03-13T23:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: Changing FTD SSH access-list</title>
      <link>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039325#M1109852</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/849493"&gt;@mrjelly&lt;/a&gt; to restrict SSH access to &lt;EM&gt;Data&lt;/EM&gt; interfaces you configure a Platform Settings Policy from the FMC and deploy to the FTDs. &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/interfaces-settings-platform.html#task_42B3A06C70E8415E8C024AE76FE79774" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/device-config/720/management-center-device-config-72/interfaces-settings-platform.html#task_42B3A06C70E8415E8C024AE76FE79774&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;If using the &lt;EM&gt;Management&lt;/EM&gt; interface, you configure an SSH access list using the command &lt;STRONG&gt;&lt;SPAN class="keyword kwd"&gt;configure ssh-access-list&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;from the CLI of the FTDs.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 08:04:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039325#M1109852</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-03-14T08:04:36Z</dc:date>
    </item>
    <item>
      <title>Re: Changing FTD SSH access-list</title>
      <link>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039353#M1109855</link>
      <description>&lt;P&gt;Thank you, what I am stuck on is how to access the configure ssh-access-list command. If it's CLI but SSH is not setup what are the default settings for the ssh-access-list and is there any other way to access and configure this other than SSH.&lt;/P&gt;&lt;P&gt;I'm assuming console works but can is also be done via FMC?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 08:42:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039353#M1109855</guid>
      <dc:creator>mrjelly</dc:creator>
      <dc:date>2024-03-14T08:42:18Z</dc:date>
    </item>
    <item>
      <title>Re: Changing FTD SSH access-list</title>
      <link>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039389#M1109856</link>
      <description>&lt;P&gt;FMC is prefer method always my view.&lt;/P&gt;
&lt;P&gt;if you like to do from cli (i would not suggest) but i have given reference document how you can do (do you get chance to read ?)&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 09:25:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039389#M1109856</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-03-14T09:25:29Z</dc:date>
    </item>
    <item>
      <title>Re: Changing FTD SSH access-list</title>
      <link>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039392#M1109857</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/849493"&gt;@mrjelly&lt;/a&gt; what interfaces are you referring to? data or management?&lt;/P&gt;
&lt;P&gt;You can only configure the SSH list for the management interface via the CLI, it's open to everyone that can route to it as default.&lt;/P&gt;
&lt;P&gt;If you are referring to the data interface for SSH you have to control this using the Platform Settings policy.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 09:28:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039392#M1109857</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-03-14T09:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: Changing FTD SSH access-list</title>
      <link>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039408#M1109858</link>
      <description>&lt;P&gt;Yes this is the management interface I want to configure&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 09:53:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039408#M1109858</guid>
      <dc:creator>mrjelly</dc:creator>
      <dc:date>2024-03-14T09:53:33Z</dc:date>
    </item>
    <item>
      <title>Re: Changing FTD SSH access-list</title>
      <link>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039410#M1109859</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/849493"&gt;@mrjelly&lt;/a&gt; like I said - For the Management interface, to configure an SSH access list from the CLI of the FTD use the&lt;STRONG&gt; &lt;SPAN class="keyword kwd"&gt;configure ssh-access-list&lt;/SPAN&gt; &lt;/STRONG&gt; command, reference &lt;SPAN class="ph"&gt;&lt;A class="xref" href="https://www.cisco.com/c/en/us/td/docs/security/firepower/command_ref/b_Command_Reference_for_Firepower_Threat_Defense.html" target="_blank" rel="noopener"&gt;Cisco Secure Firewall Threat Defense Command Reference&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 09:57:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039410#M1109859</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-03-14T09:57:52Z</dc:date>
    </item>
    <item>
      <title>Re: Changing FTD SSH access-list</title>
      <link>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039468#M1109862</link>
      <description>&lt;P&gt;The FMC platform settings will only show the access-list for SSH access using data interface.&amp;nbsp; For the management interface you would need to login to the CLIto see it and configure it.&lt;/P&gt;
&lt;P&gt;show ssh-access-list&lt;/P&gt;
&lt;P&gt;configure ssh-access-list &amp;lt;values&amp;gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 11:08:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039468#M1109862</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2024-03-14T11:08:06Z</dc:date>
    </item>
    <item>
      <title>Re: Changing FTD SSH access-list</title>
      <link>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039478#M1109863</link>
      <description>&lt;P&gt;I will try that in my Lab and inform you the steps&amp;nbsp;&lt;BR /&gt;""after I return home""&lt;/P&gt;
&lt;P&gt;thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 11:15:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039478#M1109863</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-14T11:15:40Z</dc:date>
    </item>
    <item>
      <title>Re: Changing FTD SSH access-list</title>
      <link>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039507#M1109867</link>
      <description>&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-security/ftd-management-access-restriction-does-not-work-for-management/td-p/3781668" target="_blank"&gt;FTD Management Access Restriction does not work for Management interface - Cisco Community&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;this link help you&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 14 Mar 2024 11:45:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5039507#M1109867</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-14T11:45:39Z</dc:date>
    </item>
    <item>
      <title>Re: Changing FTD SSH access-list</title>
      <link>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5040912#M1109922</link>
      <description>&lt;P&gt;Hello, thanks all for your responses, so the ssh-access-list is accept tcp -- anywhere anywhere state NEW tcp dpt:ssh&lt;/P&gt;&lt;P&gt;so I can't see any issue with that.&lt;/P&gt;&lt;P&gt;I can see traffic from my management box to the management interface IP on ssh being allowed, yet I am getting a timeout.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 14:05:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5040912#M1109922</guid>
      <dc:creator>mrjelly</dc:creator>
      <dc:date>2024-03-15T14:05:09Z</dc:date>
    </item>
    <item>
      <title>Re: Changing FTD SSH access-list</title>
      <link>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5040924#M1109923</link>
      <description>&lt;P&gt;Ok this is solved, the Management interface IP address was not the right one. Tracing the traffic coming out of the management interface, I could see two other IP addresses which were the firepower management IP addresses.&lt;BR /&gt;I was obviously reading the FMC settings incorrectly.&lt;/P&gt;&lt;P&gt;I looked at the device interfaces then the management interface settings and got the IP address from there. It was one bit higher than that.&lt;/P&gt;&lt;P&gt;Thank you all for your help and apologies.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 14:14:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5040924#M1109923</guid>
      <dc:creator>mrjelly</dc:creator>
      <dc:date>2024-03-15T14:14:54Z</dc:date>
    </item>
    <item>
      <title>Re: Changing FTD SSH access-list</title>
      <link>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5040926#M1109924</link>
      <description>&lt;P&gt;To exclude any issues with the mgmt interface or FTD itself, place a PC on the same subnet as the mgmt interface and then try to SSH to it.&amp;nbsp; If the SSH session is successful then we know there is an issue somewhere between the FTD and the original PC.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Mar 2024 14:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changing-ftd-ssh-access-list/m-p/5040926#M1109924</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2024-03-15T14:16:08Z</dc:date>
    </item>
  </channel>
</rss>

