<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to access device through PUTTY in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318821#M858083</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks John for clarifying.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure about the topology. I thought I posted this yesterday but may have missed to hit the post button.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;          |--ISP1--FW1--Host1&lt;/P&gt;&lt;P&gt;Internet--&lt;/P&gt;&lt;P&gt;          |---ISP2--FW2--Host2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, which device owns this IP address 216.88.36.91?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to ssh to 216.88.36.91 and it failed. I got the same message "Network error: Connection timed out".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do the inside of the two firewalls belong to the same subnet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where is the source which is trying to ssh live?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you see in the logs when you attempt this SSH and when it fails?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Sep 2009 13:21:51 GMT</pubDate>
    <dc:creator>Kureli Sankar</dc:creator>
    <dc:date>2009-09-25T13:21:51Z</dc:date>
    <item>
      <title>Unable to access device through PUTTY</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318808#M858056</link>
      <description>&lt;P&gt;When I am trying to access one of the device through putty I am getting error.&lt;/P&gt;&lt;P&gt;but when I tried to telnet with port 22 to that device ip , I can see port as open.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying with public IP , assuming it is natted in other end FW.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What would be the reason ?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:18:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318808#M858056</guid>
      <dc:creator>Mahinmitrxblr</dc:creator>
      <dc:date>2019-03-11T16:18:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access device through PUTTY</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318809#M858057</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Best is to go over your ssh implementation, take a look at this link  and compare it to your configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008069bf1b.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008069bf1b.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if still not joy post config&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Sep 2009 14:48:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318809#M858057</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-09-23T14:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access device through PUTTY</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318810#M858058</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry I think I confused you , I do not want to setup ssh in FW. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;scenario:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can  telnet 216.88.36.91 22 from cmd prompt , but I am not able to connect using putty and getting error - network error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Sep 2009 15:01:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318810#M858058</guid>
      <dc:creator>Mahinmitrxblr</dc:creator>
      <dc:date>2009-09-23T15:01:19Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access device through PUTTY</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318811#M858059</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry too..  missed understood ! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Use  SSHv2  , I just tested ssh to that address using different ssh client from yours and got error saying sshv2, once I change my client to use sshv2 worked. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[edit]&lt;/P&gt;&lt;P&gt;in your putty  ssh section select to connect using ssh protocol version 2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Sep 2009 15:15:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318811#M858059</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-09-23T15:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access device through PUTTY</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318812#M858060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Mahin,  is your problem solved or still having  issues?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Sep 2009 16:31:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318812#M858060</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-09-23T16:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access device through PUTTY</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318813#M858061</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my putty it is version 2 only,but it does not work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you attach the setup file of putty which you are using?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Sep 2009 16:35:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318813#M858061</guid>
      <dc:creator>Mahinmitrxblr</dc:creator>
      <dc:date>2009-09-23T16:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access device through PUTTY</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318814#M858062</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Primarily use SecureCRT client - see attached..  I don't use putty but just loaded a copy from another system in lab-what would the config file name be don't seem to fine one..  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In any event..  it must be your client settings -  I launch putty and also worked .. in putty under SSH  settings is configured as  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Sep 2009 17:23:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318814#M858062</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-09-23T17:23:25Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access device through PUTTY</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318815#M858063</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am getting the different error that I have attached here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I routed the traffic through another ISP(Backup ISP) and it is working.&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Sep 2009 17:39:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318815#M858063</guid>
      <dc:creator>Mahinmitrxblr</dc:creator>
      <dc:date>2009-09-23T17:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access device through PUTTY</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318816#M858065</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seem like the rsa key pair hasn't been created.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pls. follow this procedure to enable ssh on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ssh 0 0 outside&lt;/P&gt;&lt;P&gt;Crypto key generate rsa modulus 1024&lt;/P&gt;&lt;P&gt;Username Cisco password Cisco priv 15&lt;/P&gt;&lt;P&gt;Aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;Aaa authentication enable console LOCAl&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/mgaccess.html#wp1042023" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/mgaccess.html#wp1042023&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bear in mind, you can only ssh to the closest interface of the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Meaning, you cannot be on the inside and try to ssh to the outside interface IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Sep 2009 17:50:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318816#M858065</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-09-23T17:50:38Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access device through PUTTY</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318817#M858067</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Kureli, I believe Mahin is trying to ssh to an internal system running ssh not the firewall itself .. I thought that at the begining as well.. above procedure will not resolve this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[edit]&lt;/P&gt;&lt;P&gt;Mahin.. in your putty client go to SSH settings and under &lt;B&gt;Encryption cipher selection policy:&lt;/B&gt; have  AES(SSH-2only) as the first TOP choice in the order - see if that helps&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Sep 2009 18:12:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318817#M858067</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-09-23T18:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access device through PUTTY</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318818#M858070</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Let me clear the scenario once again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to ssh to 216.88.36.91.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have two ISP connection ,lets say ISP1 and ISP2.&lt;/P&gt;&lt;P&gt;ISP1 is connected to 515E FW and ISP2 is connected to another 515E FW.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can access through the second ISP2 that is our Backup ISP , but through the second ISP 1 I am getting error which I attached earlier.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need FW logs I can forward you that.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Sep 2009 09:30:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318818#M858070</guid>
      <dc:creator>Mahinmitrxblr</dc:creator>
      <dc:date>2009-09-24T09:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access device through PUTTY</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318819#M858073</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have any idea on this ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Sep 2009 12:51:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318819#M858073</guid>
      <dc:creator>Mahinmitrxblr</dc:creator>
      <dc:date>2009-09-25T12:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access device through PUTTY</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318820#M858078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Im not to clear about your setup,  so you have two PIXes one being the primary ISP1 and other PIX as secondary ISP2.. so you have two different Public IP blocks?   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is the default   route point to in the system running ssh  in relation to PIX ISP1 and ISP2. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;now what Im not to clear either is that I have tested your ssh connection using  216.88.36.91 and it worked.. so Im assuming  you have NAT setup in PIX off ISP2 using 216.88.36.91 address..  are you using different address for ISP1.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if you could provide some fw logs while you try connecting to ssh that would help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Sep 2009 12:54:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318820#M858078</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2009-09-25T12:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to access device through PUTTY</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318821#M858083</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks John for clarifying.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure about the topology. I thought I posted this yesterday but may have missed to hit the post button.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;          |--ISP1--FW1--Host1&lt;/P&gt;&lt;P&gt;Internet--&lt;/P&gt;&lt;P&gt;          |---ISP2--FW2--Host2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, which device owns this IP address 216.88.36.91?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to ssh to 216.88.36.91 and it failed. I got the same message "Network error: Connection timed out".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do the inside of the two firewalls belong to the same subnet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where is the source which is trying to ssh live?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you see in the logs when you attempt this SSH and when it fails?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Sep 2009 13:21:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-device-through-putty/m-p/1318821#M858083</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2009-09-25T13:21:51Z</dc:date>
    </item>
  </channel>
</rss>

