<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to Putty to External Interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284957#M858905</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, it's a bit early and i'm still trying to catch up on coffee &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is this line doing exactly - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outsissh Proxy-IP 255.255.255.240 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, i'm assuming you have created your crypto keys and saved them ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 06 Jul 2009 08:44:48 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2009-07-06T08:44:48Z</dc:date>
    <item>
      <title>How to Putty to External Interface</title>
      <link>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284954#M858891</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;We have setup a ASA 5505 at a remote remote that VPNs into our core ASA5520.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The 5505 is connect by a static IP to standard broadband.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everyting works well extent that we can't Putty onto the external interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is our config - does anyone know why this might not be working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:51:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284954#M858891</guid>
      <dc:creator>asmith1972</dc:creator>
      <dc:date>2019-03-11T15:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to Putty to External Interface</title>
      <link>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284955#M858897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What actually happens when you try - do you see anything ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also you have these lines in your config - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh Proxy-IP 255.255.255.240 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh Proxy-IP 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh Proxy-IP 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;but you haven't defined PROXY-IP in your config - is that for security reasons ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jul 2009 08:16:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284955#M858897</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-07-06T08:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: How to Putty to External Interface</title>
      <link>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284956#M858903</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just put Proxy-IP onto in for security reason. In the real config it has our IP info in there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we try and Putty we just get a connection timeout on Putty. On our main ASA we get these messages:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Built {inbound|outbound} TCP connection_id for &lt;/P&gt;&lt;P&gt;interface:real-address/real-port (mapped-address/mapped-port) to &lt;/P&gt;&lt;P&gt;interface:real-address/real-port (mapped-address/mapped-port)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Teardown TCP connection id for &lt;/P&gt;&lt;P&gt;interface:real-address/real-port to interface:real-address/real-port duration &lt;/P&gt;&lt;P&gt;hh:mm:ss bytes bytes [reason]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't seam to see any message on the remote ASA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jul 2009 08:26:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284956#M858903</guid>
      <dc:creator>asmith1972</dc:creator>
      <dc:date>2009-07-06T08:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to Putty to External Interface</title>
      <link>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284957#M858905</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry, it's a bit early and i'm still trying to catch up on coffee &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is this line doing exactly - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outsissh Proxy-IP 255.255.255.240 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, i'm assuming you have created your crypto keys and saved them ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jul 2009 08:44:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284957#M858905</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-07-06T08:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: How to Putty to External Interface</title>
      <link>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284958#M858908</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm not sure what this line does, it was auto created when we did the site to site vpn wizard.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I thought that the lines ssh Proxy-IP 255.255.255.240 outside and all the ssh lines gaves us putty access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried to remove the crypto map outside_map interface outside line and we just lost vpn access. So I guess its important&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jul 2009 09:46:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284958#M858908</guid>
      <dc:creator>asmith1972</dc:creator>
      <dc:date>2009-07-06T09:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to Putty to External Interface</title>
      <link>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284959#M858912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto map outside_map interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes that line is important - it applies the crypto map to the outside interface. Without it your VPN's won't work as you found out &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My confusion was that the line in your config seemed to be "rypto map outside_map interface outsissh Proxy-IP 255.255.255.240 outside" - guess it was just the way it appeared in the text file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh Proxy-IP 255.255.255.255 outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;should indeed allow ssh to the outside interface. So things to check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) you have created crypto keys and saved them&lt;/P&gt;&lt;P&gt;2) You are not blocking ssh anywhere in the path from your remote site &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jul 2009 10:42:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284959#M858912</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2009-07-06T10:42:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to Putty to External Interface</title>
      <link>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284960#M858914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jon&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have saved he crpto keys and I don't think we are blocking ssh. We casn certainly ssh out to other IPs in from our main ASA. Is there anyway to check if its is being blocked?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jul 2009 12:18:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284960#M858914</guid>
      <dc:creator>asmith1972</dc:creator>
      <dc:date>2009-07-06T12:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to Putty to External Interface</title>
      <link>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284961#M858916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When you say you've saved the keys, did you generate your keys on the ASA? Try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto key generate rsa general mod 1024&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to ssh into it again. I ran into this problem last week.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jul 2009 16:03:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284961#M858916</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2009-07-06T16:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to Putty to External Interface</title>
      <link>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284962#M858918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thansk John&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We've tried this command and still no joy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other ideas any one?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Jul 2009 13:27:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-putty-to-external-interface/m-p/1284962#M858918</guid>
      <dc:creator>asmith1972</dc:creator>
      <dc:date>2009-07-07T13:27:50Z</dc:date>
    </item>
  </channel>
</rss>

