<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to SSH Management Interface Cisco 1120 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-ssh-management-interface-cisco-1120/m-p/5149948#M1114565</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/342299"&gt;@kleemisch&lt;/a&gt; if using FTD image you use the command "&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;configure ssh-access-list&lt;/SPAN&gt;&lt;/SPAN&gt;" from the CLI to restrict/permit access to SSH to the management interface.&lt;/P&gt;</description>
    <pubDate>Wed, 24 Jul 2024 13:56:21 GMT</pubDate>
    <dc:creator>Rob Ingram</dc:creator>
    <dc:date>2024-07-24T13:56:21Z</dc:date>
    <item>
      <title>Unable to SSH Management Interface Cisco 1120</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-management-interface-cisco-1120/m-p/5149884#M1114562</link>
      <description>&lt;P&gt;Can someone let me know where the settings are located to ssh into the management interface? I can SSH from my desktop (10.250.3.x subnet) but can't from the server subnet.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 13:34:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-management-interface-cisco-1120/m-p/5149884#M1114562</guid>
      <dc:creator>kleemisch</dc:creator>
      <dc:date>2024-07-24T13:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to SSH Management Interface Cisco 1120</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-management-interface-cisco-1120/m-p/5149920#M1114563</link>
      <description>&lt;P&gt;it seems you're having trouble accessing the management interface of your Cisco FPR-1120 firewall via SSH from a specific subnet. Here are some suggestions to troubleshoot to resolve this issue:&lt;/P&gt;
&lt;P&gt;Check SSH access list&lt;BR /&gt;Connect to the firewall's CLI via console or from a working SSH connection. Run the command show ssh-access-list to view the current SSH access configuration,Ensure that the server subnet is included in the access list. also are this server in a different subnet if you in that case you have to allow (define access-list in order to connect ssh to server) in ASA command is like this (ssh 10.60.0.0 255.255.0.0 inside)&lt;/P&gt;
&lt;P&gt;Verify user accounts:&lt;BR /&gt;Use the command show user to check the configured user accounts Make sure the account you're using has the necessary privileges for SSH access. Review platform settings in FMC: If you're managing the device through Firepower Management Center (FMC), check the platform settings for SSH configuration&lt;BR /&gt;&lt;BR /&gt;Ensure that SSH is enabled for the management interface and the correct IP ranges are allowed.&lt;/P&gt;
&lt;P&gt;Check routing:&lt;BR /&gt;Verify that there's a valid route from the server subnet to the management interface. You may need to add a static route using the configure network static-routes command if it's not already in place&lt;BR /&gt;&lt;BR /&gt;Firewall rules:&lt;BR /&gt;Although SSH access doesn't typically require an explicit access rule, double-check that there are no firewall rules blocking SSH traffic from the server subnet to the management interface.&lt;/P&gt;
&lt;P&gt;Interface configuration:&lt;BR /&gt;Confirm that the management interface is properly configured with the correct IP address and subnet mask. Use the show interface command to verify the interface status and configuration.&lt;BR /&gt;SSH version and ciphers: Ensure that the SSH client on the server is compatible with the firewall's SSH configuration.&lt;BR /&gt;The firewall supports specific encryption, integrity, and key exchange methods&lt;BR /&gt;.&lt;BR /&gt;Network connectivity:&lt;BR /&gt;Try pinging the management interface from the server to ensure basic network connectivity.&lt;BR /&gt;Diagnostic interface vs. Management interface:&lt;BR /&gt;Be aware that the diagnostic interface and management interface are different. SSH access via the diagnostic interface is not supported from FTD 6.1 onwards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 13:49:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-management-interface-cisco-1120/m-p/5149920#M1114563</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2024-07-24T13:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to SSH Management Interface Cisco 1120</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-management-interface-cisco-1120/m-p/5149941#M1114564</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/342299" target="_self"&gt;&lt;SPAN class=""&gt;kleemisch&lt;/SPAN&gt;&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;Please go through the following link under &lt;STRONG&gt;step 3,&amp;nbsp;&lt;/STRONG&gt; you can find ssh settings:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200701-Configuration-of-Management-access-to-FT.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/200701-Configuration-of-Management-access-to-FT.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Best regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;*******&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;If This Helps, Please Rate&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;*******&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 13:54:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-management-interface-cisco-1120/m-p/5149941#M1114564</guid>
      <dc:creator>Blue_Bird</dc:creator>
      <dc:date>2024-07-24T13:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to SSH Management Interface Cisco 1120</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-management-interface-cisco-1120/m-p/5149948#M1114565</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/342299"&gt;@kleemisch&lt;/a&gt; if using FTD image you use the command "&lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;configure ssh-access-list&lt;/SPAN&gt;&lt;/SPAN&gt;" from the CLI to restrict/permit access to SSH to the management interface.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 13:56:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-management-interface-cisco-1120/m-p/5149948#M1114565</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-07-24T13:56:21Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to SSH Management Interface Cisco 1120</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-management-interface-cisco-1120/m-p/5149950#M1114566</link>
      <description>&lt;P&gt;The GW if you not config it for mgmt interface then it can not reply to any subnet outside it subnet'&lt;/P&gt;
&lt;P&gt;This GW can be FW itself or any l3 device&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 13:56:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-management-interface-cisco-1120/m-p/5149950#M1114566</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-07-24T13:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to SSH Management Interface Cisco 1120</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-management-interface-cisco-1120/m-p/5149970#M1114570</link>
      <description>&lt;P&gt;Thank you, that is my issue - I have an access list only allowing certain computers; found this by doing the ssh-access-list command.&amp;nbsp; What is the command to add another computer?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 14:04:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-management-interface-cisco-1120/m-p/5149970#M1114570</guid>
      <dc:creator>kleemisch</dc:creator>
      <dc:date>2024-07-24T14:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to SSH Management Interface Cisco 1120</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-management-interface-cisco-1120/m-p/5149986#M1114573</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="21.PNG" style="width: 590px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/224293i9BCEC6337B38E9ED/image-size/large?v=v2&amp;amp;px=999" role="button" title="21.PNG" alt="21.PNG" /&gt;&lt;/span&gt;Check this link will put you in right direction to fix the issue&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/network-security/ftd-management-access-restriction-does-not-work-for-management/td-p/3781668" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/network-security/ftd-management-access-restriction-does-not-work-for-management/td-p/3781668&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2024 14:13:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-management-interface-cisco-1120/m-p/5149986#M1114573</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2024-07-24T14:13:47Z</dc:date>
    </item>
  </channel>
</rss>

