<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic save PIX configuration via the outside interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/save-pix-configuration-via-the-outside-interface/m-p/315634#M551530</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to save a PIX525 configuration via the "outside" interface with ssh.&lt;/P&gt;&lt;P&gt;I have Ciscoworks LMS 2.2 (Module RME 3.5, with IDU 10.0) to do this automatically.&lt;/P&gt;&lt;P&gt;To save PIX configuration via the "outside" interface I must use "ssh" or "ipsec". With RME, we can only use ssh (SSH-1.5-CMF).&lt;/P&gt;&lt;P&gt;I have try to save the configuration with the ssh of RME but the connection stops with a error. The init and the authentication of the ssh session is ok but when ciscoworks wants to save the configuration, this message appears:&lt;/P&gt;&lt;P&gt;« crc comparison failed »&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have debug the traffic on the PIX:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1: SSH: Device opened successfully.&lt;/P&gt;&lt;P&gt;2: SSH: host key initialised&lt;/P&gt;&lt;P&gt;3: SSH0: SSH client: IP = '*******'  interface # = 0&lt;/P&gt;&lt;P&gt;4: SSH0: starting SSH control process&lt;/P&gt;&lt;P&gt;5: SSH0: Exchanging versions - SSH-1.5-Cisco-1.25&lt;/P&gt;&lt;P&gt;6: SSH0: send SSH message: outdata is NULL&lt;/P&gt;&lt;P&gt;7: SSH0: receive SSH message: 83 (83)&lt;/P&gt;&lt;P&gt;8: SSH0: client version is - SSH-1.5-CMF&lt;/P&gt;&lt;P&gt;9: SSH0: begin server key generation&lt;/P&gt;&lt;P&gt;10: SSH0: complete server key generation, elapsed time = 240 ms&lt;/P&gt;&lt;P&gt;11: SSH0: declare what cipher(s) we support: 0x00  0x00  0x00  0x04  &lt;/P&gt;&lt;P&gt;12: SSH0: send SSH message: SSH_SMSG_PUBLIC_KEY (2)&lt;/P&gt;&lt;P&gt;13: SSH0: SSH_SMSG_PUBLIC_KEY message sent&lt;/P&gt;&lt;P&gt;14: SSH0: receive SSH message: SSH_CMSG_SESSION_KEY (3)&lt;/P&gt;&lt;P&gt;15: SSH0: SSH_CMSG_SESSION_KEY message received - msg type 0x03,&lt;/P&gt;&lt;P&gt;length 112&lt;/P&gt;&lt;P&gt;16: SSH0: client requests  DES cipher: 2&lt;/P&gt;&lt;P&gt;17: SSH0: send SSH message: SSH_SMSG_SUCCESS (14)&lt;/P&gt;&lt;P&gt;18: SSH0: keys exchanged and encryption on&lt;/P&gt;&lt;P&gt;19: SSH0: receive SSH message: SSH_CMSG_USER (4)&lt;/P&gt;&lt;P&gt;20: SSH0: authentication request for userid ******&lt;/P&gt;&lt;P&gt;21: SSH(******): user authen method is 'use AAA', aaa server group ID = 5&lt;/P&gt;&lt;P&gt;22: SSH0: send SSH message: SSH_SMSG_FAILURE (15)&lt;/P&gt;&lt;P&gt;23: SSH0: receive SSH message: SSH_CMSG_AUTH_PASSWORD (9)&lt;/P&gt;&lt;P&gt;24: SSH(******): starting user authentication request, and waiting for reply from AAA server&lt;/P&gt;&lt;P&gt;25: SSH(******): user '********' is authenticated&lt;/P&gt;&lt;P&gt;26: SSH(******): user authentication request completed&lt;/P&gt;&lt;P&gt;27: SSH0: send SSH message: SSH_SMSG_SUCCESS (14)&lt;/P&gt;&lt;P&gt;28: SSH0: authentication successful for *******&lt;/P&gt;&lt;P&gt;29: SSH0: receive SSH message: SSH_CMSG_REQUEST_PTY (10)&lt;/P&gt;&lt;P&gt;30: SSH0: send SSH message: SSH_SMSG_SUCCESS (14)&lt;/P&gt;&lt;P&gt;31: SSH0: receive SSH message: SSH_CMSG_EXEC_SHELL (12)&lt;/P&gt;&lt;P&gt;32: SSH0: starting exec shell&lt;/P&gt;&lt;P&gt;33: SSH0: crc comparison failed - client 0xfc875863 host 0xad20ea70&lt;/P&gt;&lt;P&gt;34: SSH0: receive SSH message: [no message ID: variable *data is NULL]&lt;/P&gt;&lt;P&gt;35: SSH0: send SSH message: SSH_MSG_DISCONNECT (1)&lt;/P&gt;&lt;P&gt;36: SSH0: Session disconnected by SSH server - error 0x02 "packet CRC check failed"&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;I have search on the web site of cisco if I find some information &lt;/P&gt;&lt;P&gt;about « crc comparison failed » but I find nothing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody know this problem? Or does anybody know a another method to save the PIX configuration via outside interface with Ciscoworks RME ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your information:  PIX 525 with Cisco PIX Firewall Version 6.3(3)&lt;/P&gt;&lt;P&gt;(ssh version 1)&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Thank you for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 07:57:53 GMT</pubDate>
    <dc:creator>s.fasel</dc:creator>
    <dc:date>2020-02-21T07:57:53Z</dc:date>
    <item>
      <title>save PIX configuration via the outside interface</title>
      <link>https://community.cisco.com/t5/network-security/save-pix-configuration-via-the-outside-interface/m-p/315634#M551530</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to save a PIX525 configuration via the "outside" interface with ssh.&lt;/P&gt;&lt;P&gt;I have Ciscoworks LMS 2.2 (Module RME 3.5, with IDU 10.0) to do this automatically.&lt;/P&gt;&lt;P&gt;To save PIX configuration via the "outside" interface I must use "ssh" or "ipsec". With RME, we can only use ssh (SSH-1.5-CMF).&lt;/P&gt;&lt;P&gt;I have try to save the configuration with the ssh of RME but the connection stops with a error. The init and the authentication of the ssh session is ok but when ciscoworks wants to save the configuration, this message appears:&lt;/P&gt;&lt;P&gt;« crc comparison failed »&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have debug the traffic on the PIX:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1: SSH: Device opened successfully.&lt;/P&gt;&lt;P&gt;2: SSH: host key initialised&lt;/P&gt;&lt;P&gt;3: SSH0: SSH client: IP = '*******'  interface # = 0&lt;/P&gt;&lt;P&gt;4: SSH0: starting SSH control process&lt;/P&gt;&lt;P&gt;5: SSH0: Exchanging versions - SSH-1.5-Cisco-1.25&lt;/P&gt;&lt;P&gt;6: SSH0: send SSH message: outdata is NULL&lt;/P&gt;&lt;P&gt;7: SSH0: receive SSH message: 83 (83)&lt;/P&gt;&lt;P&gt;8: SSH0: client version is - SSH-1.5-CMF&lt;/P&gt;&lt;P&gt;9: SSH0: begin server key generation&lt;/P&gt;&lt;P&gt;10: SSH0: complete server key generation, elapsed time = 240 ms&lt;/P&gt;&lt;P&gt;11: SSH0: declare what cipher(s) we support: 0x00  0x00  0x00  0x04  &lt;/P&gt;&lt;P&gt;12: SSH0: send SSH message: SSH_SMSG_PUBLIC_KEY (2)&lt;/P&gt;&lt;P&gt;13: SSH0: SSH_SMSG_PUBLIC_KEY message sent&lt;/P&gt;&lt;P&gt;14: SSH0: receive SSH message: SSH_CMSG_SESSION_KEY (3)&lt;/P&gt;&lt;P&gt;15: SSH0: SSH_CMSG_SESSION_KEY message received - msg type 0x03,&lt;/P&gt;&lt;P&gt;length 112&lt;/P&gt;&lt;P&gt;16: SSH0: client requests  DES cipher: 2&lt;/P&gt;&lt;P&gt;17: SSH0: send SSH message: SSH_SMSG_SUCCESS (14)&lt;/P&gt;&lt;P&gt;18: SSH0: keys exchanged and encryption on&lt;/P&gt;&lt;P&gt;19: SSH0: receive SSH message: SSH_CMSG_USER (4)&lt;/P&gt;&lt;P&gt;20: SSH0: authentication request for userid ******&lt;/P&gt;&lt;P&gt;21: SSH(******): user authen method is 'use AAA', aaa server group ID = 5&lt;/P&gt;&lt;P&gt;22: SSH0: send SSH message: SSH_SMSG_FAILURE (15)&lt;/P&gt;&lt;P&gt;23: SSH0: receive SSH message: SSH_CMSG_AUTH_PASSWORD (9)&lt;/P&gt;&lt;P&gt;24: SSH(******): starting user authentication request, and waiting for reply from AAA server&lt;/P&gt;&lt;P&gt;25: SSH(******): user '********' is authenticated&lt;/P&gt;&lt;P&gt;26: SSH(******): user authentication request completed&lt;/P&gt;&lt;P&gt;27: SSH0: send SSH message: SSH_SMSG_SUCCESS (14)&lt;/P&gt;&lt;P&gt;28: SSH0: authentication successful for *******&lt;/P&gt;&lt;P&gt;29: SSH0: receive SSH message: SSH_CMSG_REQUEST_PTY (10)&lt;/P&gt;&lt;P&gt;30: SSH0: send SSH message: SSH_SMSG_SUCCESS (14)&lt;/P&gt;&lt;P&gt;31: SSH0: receive SSH message: SSH_CMSG_EXEC_SHELL (12)&lt;/P&gt;&lt;P&gt;32: SSH0: starting exec shell&lt;/P&gt;&lt;P&gt;33: SSH0: crc comparison failed - client 0xfc875863 host 0xad20ea70&lt;/P&gt;&lt;P&gt;34: SSH0: receive SSH message: [no message ID: variable *data is NULL]&lt;/P&gt;&lt;P&gt;35: SSH0: send SSH message: SSH_MSG_DISCONNECT (1)&lt;/P&gt;&lt;P&gt;36: SSH0: Session disconnected by SSH server - error 0x02 "packet CRC check failed"&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;I have search on the web site of cisco if I find some information &lt;/P&gt;&lt;P&gt;about « crc comparison failed » but I find nothing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anybody know this problem? Or does anybody know a another method to save the PIX configuration via outside interface with Ciscoworks RME ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For your information:  PIX 525 with Cisco PIX Firewall Version 6.3(3)&lt;/P&gt;&lt;P&gt;(ssh version 1)&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Thank you for your help&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:57:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/save-pix-configuration-via-the-outside-interface/m-p/315634#M551530</guid>
      <dc:creator>s.fasel</dc:creator>
      <dc:date>2020-02-21T07:57:53Z</dc:date>
    </item>
    <item>
      <title>Re: save PIX configuration via the outside interface</title>
      <link>https://community.cisco.com/t5/network-security/save-pix-configuration-via-the-outside-interface/m-p/315635#M551531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi fasel,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you able to do a normal SSH from a SSH client from the LMS desktop ? try to isolate the issue, between the PIX and the LMS.. if you are able to do a normal SSH, then we need to see the config of the LMS.. else we need to concentrate on the pix side...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do let us know..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 Feb 2005 09:32:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/save-pix-configuration-via-the-outside-interface/m-p/315635#M551531</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2005-02-15T09:32:50Z</dc:date>
    </item>
    <item>
      <title>Re: save PIX configuration via the outside interface</title>
      <link>https://community.cisco.com/t5/network-security/save-pix-configuration-via-the-outside-interface/m-p/315636#M551532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have found the problem. The problem was in the LMS configuration. The ssh connection works correctly but when the LMS connects it on the pix, it was not in "enable mode". It cannot save the configuration of the pix. I have modified the "device attributes" of the pix in the inventory of the LMS. And now that's works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you for your help &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sam&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Feb 2005 07:01:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/save-pix-configuration-via-the-outside-interface/m-p/315636#M551532</guid>
      <dc:creator>s.fasel</dc:creator>
      <dc:date>2005-02-16T07:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: save PIX configuration via the outside interface</title>
      <link>https://community.cisco.com/t5/network-security/save-pix-configuration-via-the-outside-interface/m-p/315637#M551533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi SAm,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cool. please mark the case as a solved one, which might be helpful to others. rate replies if found useful..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Raj&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Feb 2005 07:25:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/save-pix-configuration-via-the-outside-interface/m-p/315637#M551533</guid>
      <dc:creator>sachinraja</dc:creator>
      <dc:date>2005-02-16T07:25:01Z</dc:date>
    </item>
  </channel>
</rss>

