<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ssh/telnet from pix outside interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssh-telnet-from-pix-outside-interface/m-p/417354#M529748</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to access your PIX from the outside use SSH, to configure SSH access on the PIX do (in config mode): &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ca generate rsa key 1024 &lt;/P&gt;&lt;P&gt;ca save all &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To view your SSH key issue: show ca mypubkey rsa &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your PIX config you&amp;#146;ll need to allow the appropriate IP addresses that are allowed to connect to the PIX via SSH, you can do two things here, either allow any source IP address or you can tie it down to a specific IP address i.e. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(in config mode) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh 0 0 outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above will allow anyone to SSH onto your PIX (as long they know your PIX public IP address); make sure that your passwords are STRONG. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also tie it down so that only specific public IP addresses are allowed to SSH onto your PIX i.e. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh &lt;PUBLIC_IP&gt; 255.255.255.255 outside &lt;/PUBLIC_IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can download free SSH client &amp;#150; i.e. putty.exe &amp;#150; just do a search on Google for it! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember the SSH login is - pix - and then use your PIX password's to log onto your device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Dec 2005 17:20:35 GMT</pubDate>
    <dc:creator>jmia</dc:creator>
    <dc:date>2005-12-08T17:20:35Z</dc:date>
    <item>
      <title>ssh/telnet from pix outside interface</title>
      <link>https://community.cisco.com/t5/network-security/ssh-telnet-from-pix-outside-interface/m-p/417353#M529747</link>
      <description>&lt;P&gt;without the use of VPN, a way to form telnet/ssh connection into Pix from outside network with a ssh client. &lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 08:34:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-telnet-from-pix-outside-interface/m-p/417353#M529747</guid>
      <dc:creator>r.saklani</dc:creator>
      <dc:date>2020-02-21T08:34:57Z</dc:date>
    </item>
    <item>
      <title>Re: ssh/telnet from pix outside interface</title>
      <link>https://community.cisco.com/t5/network-security/ssh-telnet-from-pix-outside-interface/m-p/417354#M529748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you want to access your PIX from the outside use SSH, to configure SSH access on the PIX do (in config mode): &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ca generate rsa key 1024 &lt;/P&gt;&lt;P&gt;ca save all &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To view your SSH key issue: show ca mypubkey rsa &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your PIX config you&amp;#146;ll need to allow the appropriate IP addresses that are allowed to connect to the PIX via SSH, you can do two things here, either allow any source IP address or you can tie it down to a specific IP address i.e. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(in config mode) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh 0 0 outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above will allow anyone to SSH onto your PIX (as long they know your PIX public IP address); make sure that your passwords are STRONG. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also tie it down so that only specific public IP addresses are allowed to SSH onto your PIX i.e. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh &lt;PUBLIC_IP&gt; 255.255.255.255 outside &lt;/PUBLIC_IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can download free SSH client &amp;#150; i.e. putty.exe &amp;#150; just do a search on Google for it! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember the SSH login is - pix - and then use your PIX password's to log onto your device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Dec 2005 17:20:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-telnet-from-pix-outside-interface/m-p/417354#M529748</guid>
      <dc:creator>jmia</dc:creator>
      <dc:date>2005-12-08T17:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: ssh/telnet from pix outside interface</title>
      <link>https://community.cisco.com/t5/network-security/ssh-telnet-from-pix-outside-interface/m-p/417355#M529749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;just a quick comment.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;before the rsa key can be generated, a hostname and a domain need to be configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g.&lt;/P&gt;&lt;P&gt;hostname pix&lt;/P&gt;&lt;P&gt;domain-name yourcompany.com&lt;/P&gt;&lt;P&gt;ca generate rsa key 1024&lt;/P&gt;&lt;P&gt;ca save all&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Dec 2005 22:38:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-telnet-from-pix-outside-interface/m-p/417355#M529749</guid>
      <dc:creator>jackko</dc:creator>
      <dc:date>2005-12-08T22:38:51Z</dc:date>
    </item>
  </channel>
</rss>

