<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AIP-SSM AAA Authentication? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/aip-ssm-aaa-authentication/m-p/777129#M86787</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"you can only ssh into the module from the local subnet that the AIP-SSM interface is configured on. "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thats not true. You can access AIP-SSM module from any network. All you need is access-list entries on the AIP-SSM module permitting the access and proper gateway IP configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authentication of usernames using AAA is not available though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 10 May 2007 18:24:24 GMT</pubDate>
    <dc:creator>vitripat</dc:creator>
    <dc:date>2007-05-10T18:24:24Z</dc:date>
    <item>
      <title>AIP-SSM AAA Authentication?</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-aaa-authentication/m-p/777126#M86772</link>
      <description>&lt;P&gt;I was wondering if the AIP-SSM module on a ASA 5510 or 5540 can authenticate users against a Tacacs+ server?  If so can you configure it so you can use ssh to login on to the device with authentication through Tacacs+?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have my ASA set up so I can ssh into it and then I can session 1 into the AIP-SSM module.  But, can you ssh directly into the device?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 10:35:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-aaa-authentication/m-p/777126#M86772</guid>
      <dc:creator>bkhickman</dc:creator>
      <dc:date>2019-03-10T10:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM AAA Authentication?</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-aaa-authentication/m-p/777127#M86780</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The IPS software on the AIP-SSM does not support TACACS+ for authentication.&lt;/P&gt;&lt;P&gt;All usernames and passwords for IPS AIP-SSM module have to be stored locally on the module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can ssh directly to the management IP Address of the IPS AIP-SSM.  You would just need to use a username that was created locally on the IPS AIP-SSM instead of a TACACS+ account.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 08 May 2007 17:40:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-aaa-authentication/m-p/777127#M86780</guid>
      <dc:creator>marcabal</dc:creator>
      <dc:date>2007-05-08T17:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM AAA Authentication?</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-aaa-authentication/m-p/777128#M86784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the response.  I did manage to talk with a Cisco engineer on this and they confirmed what you are saying.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In addition they said that you can only ssh into the module from the local subnet that the AIP-SSM interface is configured on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interesting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 16:28:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-aaa-authentication/m-p/777128#M86784</guid>
      <dc:creator>bkhickman</dc:creator>
      <dc:date>2007-05-10T16:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM AAA Authentication?</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-aaa-authentication/m-p/777129#M86787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;"you can only ssh into the module from the local subnet that the AIP-SSM interface is configured on. "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thats not true. You can access AIP-SSM module from any network. All you need is access-list entries on the AIP-SSM module permitting the access and proper gateway IP configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authentication of usernames using AAA is not available though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 10 May 2007 18:24:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-aaa-authentication/m-p/777129#M86787</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-05-10T18:24:24Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM AAA Authentication?</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-aaa-authentication/m-p/777130#M86792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks, for that response.  But, how would you configure that?  I don't seem to be able to get it working.  I am trying to connect from the 172.30.4.0 network.  And, I can ssh to other devices in the 172.30.8.0 network.  This is my testing AIP-SSM configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! Version 5.1(1)&lt;/P&gt;&lt;P&gt;! Current configuration last modified Tue May 08 10:58:18 2007&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service interface&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service analysis-engine&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service authentication&lt;/P&gt;&lt;P&gt;attemptLimit 3&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service event-action-rules rules0&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service host&lt;/P&gt;&lt;P&gt;network-settings&lt;/P&gt;&lt;P&gt;host-ip 172.30.15.66/28,172.30.15.65&lt;/P&gt;&lt;P&gt;host-name RecMgtSensor&lt;/P&gt;&lt;P&gt;telnet-option disabled&lt;/P&gt;&lt;P&gt;access-list 172.30.4.0/23&lt;/P&gt;&lt;P&gt;access-list 172.30.8.0/23&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;time-zone-settings&lt;/P&gt;&lt;P&gt;offset -300&lt;/P&gt;&lt;P&gt;standard-time-zone-name GMT-05:00&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;summertime-option recurring&lt;/P&gt;&lt;P&gt;offset 60&lt;/P&gt;&lt;P&gt;summertime-zone-name GMT-05:00&lt;/P&gt;&lt;P&gt;start-summertime&lt;/P&gt;&lt;P&gt;month march&lt;/P&gt;&lt;P&gt;week-of-month second&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;end-summertime&lt;/P&gt;&lt;P&gt;month november&lt;/P&gt;&lt;P&gt;week-of-month first&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service logger&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service network-access&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service notification&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service signature-definition sig0&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service ssh-known-hosts&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service trusted-certificates&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;! ------------------------------&lt;/P&gt;&lt;P&gt;service web-server&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help would be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brian&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 17:35:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-aaa-authentication/m-p/777130#M86792</guid>
      <dc:creator>bkhickman</dc:creator>
      <dc:date>2007-05-11T17:35:04Z</dc:date>
    </item>
    <item>
      <title>Re: AIP-SSM AAA Authentication?</title>
      <link>https://community.cisco.com/t5/network-security/aip-ssm-aaa-authentication/m-p/777131#M86794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure ..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;host-ip 172.30.15.66/28,172.30.15.65 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per the above line, 172.30.15.66 is the IP address on management port on SSM and 172.30.15.65 is the gateway for SSM module. If this 172.30.15.65 is a router or some other device, please make sure 172.30.4.0/23 network is reachable from 172.30.15.65. Also, make sure there is noting in between 172.30.15.66 and 172.30.4.0/23 network which may block the traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vibhor.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 May 2007 19:35:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/aip-ssm-aaa-authentication/m-p/777131#M86794</guid>
      <dc:creator>vitripat</dc:creator>
      <dc:date>2007-05-11T19:35:58Z</dc:date>
    </item>
  </channel>
</rss>

