<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't telnet or SSH to my Cisco PIX 506E in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483913#M733393</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Sorry man but, I am having the same issue. Whenever I reboot the firewall is does not keep the ca generate rsa key 2048. I have to run it again for the SSH to start working everytime After I reload the firewall. WHY???&amp;nbsp; I have also performed a&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (write memory before I reload the firewall).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 01 Jun 2010 16:57:39 GMT</pubDate>
    <dc:creator>Charlie Mayes</dc:creator>
    <dc:date>2010-06-01T16:57:39Z</dc:date>
    <item>
      <title>Can't telnet or SSH to my Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483904#M733380</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Any connection over the internet or trying to cnnect fails using Putty or Teraterm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface ethernet0 auto&lt;BR /&gt;interface ethernet1 100full&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nameif ethernet0 outside security0&lt;BR /&gt;nameif ethernet1 inside security100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable password $$$$$$$$$$&lt;BR /&gt;passwd $$$$$$$$&lt;BR /&gt;hostname $$$$$$&lt;BR /&gt;domain-name $$$$.local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fixup protocol dns maximum-length 512&lt;BR /&gt;fixup protocol ftp 21&lt;BR /&gt;fixup protocol h323 h225 1720&lt;BR /&gt;fixup protocol h323 ras 1718-1719&lt;BR /&gt;fixup protocol http 80&lt;BR /&gt;fixup protocol ils 389&lt;BR /&gt;fixup protocol pptp 1723&lt;BR /&gt;fixup protocol rsh 514&lt;BR /&gt;fixup protocol rtsp 554&lt;BR /&gt;fixup protocol sip 5060&lt;BR /&gt;fixup protocol sip udp 5060&lt;BR /&gt;fixup protocol skinny 2000&lt;BR /&gt;fixup protocol smtp 25&lt;BR /&gt;fixup protocol sqlnet 1521&lt;BR /&gt;fixup protocol tftp 69&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;names&lt;BR /&gt;name 10.255.255.0 mike&lt;BR /&gt;name 10.1.170.0 harry&lt;BR /&gt;name 10.10.0.0 tom&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;access-list cryptomap_$$$$_10 permit ip 10.1.17.0 255.255.255.0 $$$l 255.255.255.0&lt;BR /&gt;access-list inside_no_nat permit ip 10.1.17.0 255.255.255.0 $$$ 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list cryptomap_arc_20 permit ip 10.1.17.0 255.255.255.0 $$$ 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list cryptomap_$$_30 permit ip 10.1.17.0 255.255.255.0 $$$$ 255.255.255.0&lt;BR /&gt;access-list cryptomap_$$_30 permit ip 10.1.17.0 255.255.255.0 $$$ 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_no_nat permit ip 10.1.17.0 255.255.255.0 $$$ 255.255.255.0&lt;BR /&gt;access-list inside_no_nat permit ip 10.1.17.0 255.255.255.0 $$$ 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;icmp deny any outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;pager lines 24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mtu outside 1500&lt;BR /&gt;mtu inside 1500&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address outside 22.221.38.234 255.255.255.248&lt;BR /&gt;ip address inside 10.1.173.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip audit info action alarm&lt;BR /&gt;ip audit attack action alarm&lt;BR /&gt;pdm history enable&lt;BR /&gt;arp timeout 14400&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;global (outside) 1 interface&lt;BR /&gt;nat (inside) 0 access-list inside_no_nat&lt;BR /&gt;nat (inside) 1 0.0.0.0 0.0.0.0 0 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route outside 0.0.0.0 0.0.0.0 22.221.38.233 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;http server enable&lt;BR /&gt;http 10.1.17.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no snmp-server location&lt;BR /&gt;no snmp-server contact&lt;BR /&gt;snmp-server community public&lt;BR /&gt;no snmp-server enable traps&lt;BR /&gt;floodguard enable&lt;BR /&gt;sysopt connection permit-ipsec&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto ipsec transform-set ESP-DES-MD5 esp-des esp-md5-hmac&lt;BR /&gt;crypto map outside_map 10 ipsec-isakmp&lt;BR /&gt;crypto map outside_map 10 match address cryptomap_$$$_10&lt;BR /&gt;crypto map outside_map 10 set peer &lt;BR /&gt;crypto map outside_map 10 set transform-set ESP-DES-MD5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto map outside_map 30 ipsec-isakmp&lt;BR /&gt;crypto map outside_map 30 match address cryptomap_hq_30&lt;BR /&gt;crypto map outside_map 30 set peer &lt;BR /&gt;crypto map outside_map 30 set transform-set ESP-DES-MD5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isakmp enable outside&lt;BR /&gt;isakmp identity address&lt;BR /&gt;isakmp nat-traversal 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isakmp policy 10 authentication pre-share&lt;BR /&gt;isakmp policy 10 encryption des&lt;BR /&gt;isakmp policy 10 hash md5&lt;BR /&gt;isakmp policy 10 group 2&lt;BR /&gt;isakmp policy 10 lifetime 86400&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;isakmp key $$$$$$$$$$$$$$$$$$&amp;nbsp;&amp;nbsp;&amp;nbsp; netmask 255.255.255.255 no-xauth no-config-mode&lt;BR /&gt;isakmp key $$$$$$$$$$$$$$$$$$$$$ address X&amp;gt;X&amp;gt;X&amp;gt; netmask 255.255.255.255 no-xauth no-config-mode&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;dhcpd address 10.1.173.101-10.1.173.254 inside&lt;BR /&gt;dhcpd enable inside&lt;BR /&gt;dhcpd lease 86400&lt;BR /&gt;dhcpd ping_timeout 750&lt;BR /&gt;dhcpd dns 10.1.17.20 X&amp;gt;X&amp;gt;X&amp;gt;&lt;BR /&gt;dhcp domain $$$.local&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;BR /&gt;telnet&amp;nbsp; 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet&amp;nbsp; 0.0.0.0 0.0.0.0 inside&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:52:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483904#M733380</guid>
      <dc:creator>Charlie Mayes</dc:creator>
      <dc:date>2019-03-11T17:52:26Z</dc:date>
    </item>
    <item>
      <title>Re: Can't telnet or SSH to my Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483905#M733381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You're not going to be able to telnet to the outside interface (this is by design).&lt;/P&gt;&lt;P&gt;But you should be able to SSH.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For SSH, besides the hostname/domain, you need to generate the RSA keys:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto key generate rsa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 May 2010 19:14:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483905#M733381</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-05-28T19:14:21Z</dc:date>
    </item>
    <item>
      <title>Re: Can't telnet or SSH to my Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483906#M733382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Is my config right To ssh to the device?&amp;nbsp;&amp;nbsp; I have already done the ca generate rsa key 1024&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 May 2010 19:26:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483906#M733382</guid>
      <dc:creator>Charlie Mayes</dc:creator>
      <dc:date>2010-05-28T19:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: Can't telnet or SSH to my Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483907#M733383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, the configuration is correct but... do you have connectivity to the outside IP?&amp;nbsp; Can you PING it?&lt;/P&gt;&lt;P&gt;Can you connect to the inside IP from the inside LAN?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 May 2010 19:31:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483907#M733383</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-05-28T19:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: Can't telnet or SSH to my Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483908#M733385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wont be able to ping because there is "icmp deny any outside" which will blocked ping to the outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also tried to SSH on the PIX outside interface, and even TCP 3 way handshake is not completed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the router in front of the PIX blocking SSH access?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 May 2010 07:25:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483908#M733385</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-05-29T07:25:59Z</dc:date>
    </item>
    <item>
      <title>Re: Can't telnet or SSH to my Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483909#M733387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In order for SSH to work on a PIX/ASA, you need to configure AAA.&amp;nbsp; &lt;SPAN class="content"&gt;Authentication controls access by requiring valid&amp;nbsp; user credentials, which are typically a username and password.&amp;nbsp; I believe you can use the username "pix" on the 506E if no username is configured.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.&amp;nbsp; &lt;STRONG class="cBold" style="font-weight: bold;"&gt;crypto key generate rsa modulus &lt;/STRONG&gt;&lt;SPAN style="color: black; font-style: italic; font-weight: normal;"&gt;modulus_size&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2.&amp;nbsp; &lt;STRONG class="cBold"&gt;ssh&lt;/STRONG&gt; &lt;EM class="cEmphasis"&gt;source_IP_address&lt;/EM&gt; &lt;EM class="cEmphasis"&gt;mask&lt;/EM&gt; &lt;EM class="cEmphasis"&gt;source_interface&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;3.&amp;nbsp;&amp;nbsp; &lt;STRONG class="cKeyword" style="font-weight: bold;"&gt;ssh timeout &lt;/STRONG&gt;&lt;SPAN style="color: black; font-style: italic; font-weight: normal;"&gt;minutes&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;4.&amp;nbsp; &lt;SPAN class="content"&gt;&lt;STRONG class="cBold" style="font-weight: bold;"&gt;ssh&amp;nbsp; version&lt;/STRONG&gt;&lt;SPAN style="color: black; font-style: oblique; font-weight: normal;"&gt; version_number&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the step I think you are missing:&lt;/P&gt;&lt;P&gt;5.&amp;nbsp; &lt;SPAN class="cExBold"&gt;&lt;STRONG&gt;aaa authentication&lt;/STRONG&gt; &lt;/SPAN&gt;{&lt;SPAN class="cExBold"&gt;telnet &lt;/SPAN&gt;| &lt;SPAN class="cExBold"&gt;ssh &lt;/SPAN&gt;| &lt;SPAN class="cExBold"&gt;http&lt;/SPAN&gt; | &lt;SPAN class="cExBold"&gt;serial&lt;/SPAN&gt;} &lt;SPAN class="cExBold"&gt;console&lt;/SPAN&gt; {&lt;SPAN class="cExBold"&gt;LOCAL&lt;/SPAN&gt; | &lt;BR /&gt;&lt;SPAN class="content"&gt;&lt;PRE&gt;&lt;EM class="cEmphasis"&gt;server_group &lt;/EM&gt;[&lt;SPAN class="cExBold"&gt;LOCAL&lt;/SPAN&gt;]}&lt;BR /&gt;&lt;/PRE&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the link to more information:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/docs/security/asa/asa70/configuration/guide/mgaccess.html#wp1056599"&gt;http://www.cisco.com/en/US/partner/docs/security/asa/asa70/configuration/guide/mgaccess.html#wp1056599&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Bob Bagheri&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 May 2010 14:20:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483909#M733387</guid>
      <dc:creator>Bob Bagheri</dc:creator>
      <dc:date>2010-05-29T14:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: Can't telnet or SSH to my Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483910#M733389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks Man,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I just had to generate the ca key again because the first time I guess it must have gotten corrupted. After I did that SSH worked fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 May 2010 21:33:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483910#M733389</guid>
      <dc:creator>Charlie Mayes</dc:creator>
      <dc:date>2010-05-29T21:33:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can't telnet or SSH to my Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483911#M733391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Man,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I just had to generate the ca key again because the first time I did it it must have got corrupted. After I did that SSH worked fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 29 May 2010 21:34:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483911#M733391</guid>
      <dc:creator>Charlie Mayes</dc:creator>
      <dc:date>2010-05-29T21:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: Can't telnet or SSH to my Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483912#M733392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wonderful, glad to hear it.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Re,&lt;BR /&gt;Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Jun 2010 12:35:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483912#M733392</guid>
      <dc:creator>Bob Bagheri</dc:creator>
      <dc:date>2010-06-01T12:35:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can't telnet or SSH to my Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483913#M733393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Sorry man but, I am having the same issue. Whenever I reboot the firewall is does not keep the ca generate rsa key 2048. I have to run it again for the SSH to start working everytime After I reload the firewall. WHY???&amp;nbsp; I have also performed a&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; (write memory before I reload the firewall).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Jun 2010 16:57:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483913#M733393</guid>
      <dc:creator>Charlie Mayes</dc:creator>
      <dc:date>2010-06-01T16:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Can't telnet or SSH to my Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483914#M733394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What version are you running?&lt;/P&gt;&lt;P&gt;Check with the ''sh version'' command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Jun 2010 17:02:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483914#M733394</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-06-01T17:02:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can't telnet or SSH to my Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483915#M733395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Cisco PIX Firewall Version 6.3(5)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 09:15:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483915#M733395</guid>
      <dc:creator>Charlie Mayes</dc:creator>
      <dc:date>2010-06-02T09:15:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can't telnet or SSH to my Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483916#M733396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you generate the RSA keys for SSH it works correct?&lt;/P&gt;&lt;P&gt;Then you should see such key with the command: sh cry key mypubkey rsa''&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you reload the PIX, then you're not able to SSH anymore and have to regenerate the keys?&lt;/P&gt;&lt;P&gt;After rebooting the PIX and before regenerating the keys again, do you still see the public key with the ''sh cry key mypubkey rsa'' command?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You don't have to be regenerating the keys everytime the PIX restarts, you might be hitting a bug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 13:23:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483916#M733396</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-06-02T13:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Can't telnet or SSH to my Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483917#M733397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hello Federico,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I had to use the command below for my PIX but, the keys are there. Maybe there is a bug. I will just replace that firewall with a another one because I have to access my remote sites with using the inside interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sh ca mypubkey rsa &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 14:15:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483917#M733397</guid>
      <dc:creator>Charlie Mayes</dc:creator>
      <dc:date>2010-06-02T14:15:55Z</dc:date>
    </item>
    <item>
      <title>Re: Can't telnet or SSH to my Cisco PIX 506E</title>
      <link>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483918#M733398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes.&lt;/P&gt;&lt;P&gt;I would recommend you to open a TAC case.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Federico.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jun 2010 15:23:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-telnet-or-ssh-to-my-cisco-pix-506e/m-p/1483918#M733398</guid>
      <dc:creator>Federico Coto Fajardo</dc:creator>
      <dc:date>2010-06-02T15:23:07Z</dc:date>
    </item>
  </channel>
</rss>

