<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PIX failover ssh access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218676#M591490</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can access the standby via ssh, to do that you need to target the failover ip address.  If you tried that already, you may need to regen the rsa key on the other unit - the keys are not shared between the two.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you need more help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 07 Jul 2004 10:34:26 GMT</pubDate>
    <dc:creator>ehirsel</dc:creator>
    <dc:date>2004-07-07T10:34:26Z</dc:date>
    <item>
      <title>PIX failover ssh access</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218675#M591487</link>
      <description>&lt;P&gt;We have two pix515 in failover configuration and found that we can only access , via ssh , the "active" pix , and not the one in standby.&lt;/P&gt;&lt;P&gt;Is that normal ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 07:29:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218675#M591487</guid>
      <dc:creator>scolombo</dc:creator>
      <dc:date>2020-02-21T07:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: PIX failover ssh access</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218676#M591490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can access the standby via ssh, to do that you need to target the failover ip address.  If you tried that already, you may need to regen the rsa key on the other unit - the keys are not shared between the two.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you need more help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jul 2004 10:34:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218676#M591490</guid>
      <dc:creator>ehirsel</dc:creator>
      <dc:date>2004-07-07T10:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: PIX failover ssh access</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218677#M591492</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tried to access it via the failover IP but couldn't.&lt;/P&gt;&lt;P&gt;How can I regenerate the key ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jul 2004 12:05:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218677#M591492</guid>
      <dc:creator>scolombo</dc:creator>
      <dc:date>2004-07-07T12:05:23Z</dc:date>
    </item>
    <item>
      <title>Re: PIX failover ssh access</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218678#M591493</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I was under the impression that you cannot access the "standby" pix in any manner other than console b/c it is in a failover scenario.  Making a change on the standby would corrupt the failover.  It seems that the only reason you would want to access the standby would be to upgrade the code. In this case, there is established procedures for turning one of, and then the other, etc.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jul 2004 13:45:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218678#M591493</guid>
      <dc:creator>joneschw1</dc:creator>
      <dc:date>2004-07-07T13:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: PIX failover ssh access</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218679#M591494</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No, it's not normal.&lt;/P&gt;&lt;P&gt;Make sure the following conditions are met:&lt;/P&gt;&lt;P&gt;Your secondary pix has a route back to you.&lt;/P&gt;&lt;P&gt;It has a valid RSA key (most common problem) and make sure it's permanently saved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jul 2004 14:25:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218679#M591494</guid>
      <dc:creator>crojas</dc:creator>
      <dc:date>2004-07-07T14:25:41Z</dc:date>
    </item>
    <item>
      <title>Re: PIX failover ssh access</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218680#M591495</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why shouldn't I connect to the standby pix in a failover scenario ?&lt;/P&gt;&lt;P&gt;I wouldn't make any configuration change on it but I think I should have the possibility to connect to it ( ie for diagnostic ) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jul 2004 14:27:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218680#M591495</guid>
      <dc:creator>scolombo</dc:creator>
      <dc:date>2004-07-07T14:27:01Z</dc:date>
    </item>
    <item>
      <title>Re: PIX failover ssh access</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218681#M591496</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A side note:&lt;/P&gt;&lt;P&gt;When the primary fails, the 2 units will swap their IP addresses around. If you try to SSH to the secondary, you will actually land on the primary because of that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jul 2004 14:27:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218681#M591496</guid>
      <dc:creator>crojas</dc:creator>
      <dc:date>2004-07-07T14:27:32Z</dc:date>
    </item>
    <item>
      <title>Re: PIX failover ssh access</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218682#M591497</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;A side note:&lt;/P&gt;&lt;P&gt;When the primary fails, the 2 units will swap their IP addresses around. If you try to SSH to the secondary, you will actually land on the primary because of that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jul 2004 14:41:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218682#M591497</guid>
      <dc:creator>crojas</dc:creator>
      <dc:date>2004-07-07T14:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: PIX failover ssh access</title>
      <link>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218683#M591498</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;To regen an rsa key use this command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; ca generate rsa key  followed by ca save all to save it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition insure that you replicate the config from the active to the standby as the config tells the pix where the ssh session can come from (interface and ip address).  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the pix 6.3 command ref:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ca generate rsa command generates RSA key pairs for your PIX Firewall. RSA keys are generated in pairs&amp;#151;one public RSA key and one private RSA key. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ca generate rsa key modulus &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syntax Description&lt;/P&gt;&lt;P&gt; ca generate rsa key &lt;/P&gt;&lt;P&gt; Generates an RSA key for the PIX Firewall. &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;modulus &lt;/P&gt;&lt;P&gt; Defines the modulus used to generate the RSA key. This is a size measured in bits. You can specify a modulus between 512, 768, 1024, and 2048. &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note Before issuing this command, make sure your PIX Firewall host name and domain name have been configured (using the hostname and domain-name commands). If a domain name is not configured, the PIX Firewall uses a default domain of ciscopix.com. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Defaults &lt;/P&gt;&lt;P&gt;RSA key modulus default (during PDM setup) is 768. The default domain is ciscopix.com. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Command Modes &lt;/P&gt;&lt;P&gt;Configuration mode. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Usage Guidelines &lt;/P&gt;&lt;P&gt;If your PIX Firewall already has RSA keys when you issue this command, you are warned and prompted to replace the existing keys with new keys. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note The larger the key modulus size you specify, the longer it takes to generate an RSA. We recommend a default value of 768. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 07 Jul 2004 16:01:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/pix-failover-ssh-access/m-p/218683#M591498</guid>
      <dc:creator>ehirsel</dc:creator>
      <dc:date>2004-07-07T16:01:56Z</dc:date>
    </item>
  </channel>
</rss>

