<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSH access from remote VPN site in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssh-access-from-remote-vpn-site/m-p/1139263#M840812</link>
    <description>&lt;P&gt;Greetings. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see by the configs, I have a simple two-way VPN tunnel from Virginia (10.10.50.x) to Houston (192.168.40.x). The tunnel is up and all is well. What I'd like to do (but for some reason am unable) is to allow users in Virginia (10.10.50.x) to administer the Houston (192.168.40.1) ASA box via ssh. For some reason I'm missing something because it isn't working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*I can SSH to the Houston box from the Houston 192.168.40.x LAN so I know SSH does work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*I've regenerated the keys on at least three occasions in Houston as a troubleshooting technique (crypto key generate rsa modulus 1024)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*From the Virginia site I can telnet to 192.168.40.1 over port 22 so I know SSH is open and accessible. It's just that when I try to launch from Putty that I get "network error: software caused connection abort".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*I've also tried:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with no luck at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 15:35:42 GMT</pubDate>
    <dc:creator>cavemanbobby</dc:creator>
    <dc:date>2019-03-11T15:35:42Z</dc:date>
    <item>
      <title>SSH access from remote VPN site</title>
      <link>https://community.cisco.com/t5/network-security/ssh-access-from-remote-vpn-site/m-p/1139263#M840812</link>
      <description>&lt;P&gt;Greetings. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you can see by the configs, I have a simple two-way VPN tunnel from Virginia (10.10.50.x) to Houston (192.168.40.x). The tunnel is up and all is well. What I'd like to do (but for some reason am unable) is to allow users in Virginia (10.10.50.x) to administer the Houston (192.168.40.1) ASA box via ssh. For some reason I'm missing something because it isn't working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*I can SSH to the Houston box from the Houston 192.168.40.x LAN so I know SSH does work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*I've regenerated the keys on at least three occasions in Houston as a troubleshooting technique (crypto key generate rsa modulus 1024)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*From the Virginia site I can telnet to 192.168.40.1 over port 22 so I know SSH is open and accessible. It's just that when I try to launch from Putty that I get "network error: software caused connection abort".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*I've also tried:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;with no luck at all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:35:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-access-from-remote-vpn-site/m-p/1139263#M840812</guid>
      <dc:creator>cavemanbobby</dc:creator>
      <dc:date>2019-03-11T15:35:42Z</dc:date>
    </item>
    <item>
      <title>Re: SSH access from remote VPN site</title>
      <link>https://community.cisco.com/t5/network-security/ssh-access-from-remote-vpn-site/m-p/1139264#M840818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try adding the command "management-access inside"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 May 2009 16:42:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-access-from-remote-vpn-site/m-p/1139264#M840818</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2009-05-22T16:42:16Z</dc:date>
    </item>
    <item>
      <title>Re: SSH access from remote VPN site</title>
      <link>https://community.cisco.com/t5/network-security/ssh-access-from-remote-vpn-site/m-p/1139265#M840821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks so much for the reply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I forgot to mention that I'd already tried that command, too, with no luck. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll keep digging...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 May 2009 16:44:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-access-from-remote-vpn-site/m-p/1139265#M840821</guid>
      <dc:creator>cavemanbobby</dc:creator>
      <dc:date>2009-05-22T16:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: SSH access from remote VPN site</title>
      <link>https://community.cisco.com/t5/network-security/ssh-access-from-remote-vpn-site/m-p/1139266#M840823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try by removing the inside_acl on the houston ASA. If that works then you need to tweak the ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 May 2009 18:44:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-access-from-remote-vpn-site/m-p/1139266#M840823</guid>
      <dc:creator>mvsheik123</dc:creator>
      <dc:date>2009-05-22T18:44:49Z</dc:date>
    </item>
    <item>
      <title>Re: SSH access from remote VPN site</title>
      <link>https://community.cisco.com/t5/network-security/ssh-access-from-remote-vpn-site/m-p/1139267#M840825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;try simply turning on plain jane telnet&lt;/P&gt;&lt;P&gt;and see if that works-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;houston#&lt;/P&gt;&lt;P&gt;telnet 10.10.50.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;try telneting from a windows box plain telnet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if this works, switch your ssh client&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 May 2009 19:50:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-access-from-remote-vpn-site/m-p/1139267#M840825</guid>
      <dc:creator>joe19366</dc:creator>
      <dc:date>2009-05-22T19:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: SSH access from remote VPN site</title>
      <link>https://community.cisco.com/t5/network-security/ssh-access-from-remote-vpn-site/m-p/1139268#M840826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Because you're actually trying to SSH to the inside interface IP, you'll need...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh 10.10.50.0 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if you try to SSH with just that, the log will indicate the connection was dropped by the TCP intercept at the outside interface. Therefore, you also need...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh 10.10.50.0 255.255.255.0 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I have had situations where, after doing this on an ASA 5510 running version 7, it did not work until after I saved the config and rebooted the ASA.  Then it worked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, put in your SSH lines then save and reboot the ASA.  Let me know.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 May 2009 16:58:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-access-from-remote-vpn-site/m-p/1139268#M840826</guid>
      <dc:creator>jeremyault</dc:creator>
      <dc:date>2009-05-23T16:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSH access from remote VPN site</title>
      <link>https://community.cisco.com/t5/network-security/ssh-access-from-remote-vpn-site/m-p/1139269#M840831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;BINGO!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As you indicated, it *did* require the reboot in order for it to take place. I added the config statements without the reboot originally and it did not work. But the reboot did it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It never occurred to me that you'd have to place that subnet on the outside. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a million, man. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 May 2009 13:07:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-access-from-remote-vpn-site/m-p/1139269#M840831</guid>
      <dc:creator>cavemanbobby</dc:creator>
      <dc:date>2009-05-26T13:07:46Z</dc:date>
    </item>
  </channel>
</rss>

