<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to allow SSH into Zone Based Firewall? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162318#M874720</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Toshi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First of all thanks for your suggestions. I tried what you suggested but got an error. Here is the exact copy from the router. Since it did not like the inspect command I tried pass but that did not work either. Any other suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manny-2691(config)#class-map type inspect match-all SSH &lt;/P&gt;&lt;P&gt;Manny-2691(config-cmap)#match protocol ssh &lt;/P&gt;&lt;P&gt;Manny-2691(config-cmap)#! &lt;/P&gt;&lt;P&gt;Manny-2691(config-cmap)#policy-map type inspect sdm-permit &lt;/P&gt;&lt;P&gt;Manny-2691(config-pmap)#class type inspect SSH &lt;/P&gt;&lt;P&gt;Manny-2691(config-pmap-c)#inspect &lt;/P&gt;&lt;P&gt;%Protocol ssh configured in class-map SSH cannot be configured for the self zone. Please remove the protocol and retry&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manny-2691(config-pmap-c)#&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 22 Mar 2009 18:51:04 GMT</pubDate>
    <dc:creator>mramirez</dc:creator>
    <dc:date>2009-03-22T18:51:04Z</dc:date>
    <item>
      <title>How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162316#M874718</link>
      <description>&lt;P&gt;I am stuck in trying to figure out on how to allow a ssh connection from the outside to the wan uplink on my firwall. I just recently converted to the zone based. I have tried adding all different types of ways but no luck. Can someone help me out? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's say I wanted to configure a specific ip address from the internet to access the router only thru ssh.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:08:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162316#M874718</guid>
      <dc:creator>mramirez</dc:creator>
      <dc:date>2019-03-11T15:08:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162317#M874719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi MANNY,&lt;/P&gt;&lt;P&gt;Just add commands I provided.&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;class-map type inspect match-all SSH&lt;/P&gt;&lt;P&gt; match protocol ssh&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect sdm-permit&lt;/P&gt;&lt;P&gt;class type inspect SSH&lt;/P&gt;&lt;P&gt;  inspect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You may filter hosts to access this device by adding ACLs into into the class-map.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Please let us know how things work out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Toshi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Mar 2009 18:15:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162317#M874719</guid>
      <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
      <dc:date>2009-03-22T18:15:31Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162318#M874720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Toshi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First of all thanks for your suggestions. I tried what you suggested but got an error. Here is the exact copy from the router. Since it did not like the inspect command I tried pass but that did not work either. Any other suggestions?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manny-2691(config)#class-map type inspect match-all SSH &lt;/P&gt;&lt;P&gt;Manny-2691(config-cmap)#match protocol ssh &lt;/P&gt;&lt;P&gt;Manny-2691(config-cmap)#! &lt;/P&gt;&lt;P&gt;Manny-2691(config-cmap)#policy-map type inspect sdm-permit &lt;/P&gt;&lt;P&gt;Manny-2691(config-pmap)#class type inspect SSH &lt;/P&gt;&lt;P&gt;Manny-2691(config-pmap-c)#inspect &lt;/P&gt;&lt;P&gt;%Protocol ssh configured in class-map SSH cannot be configured for the self zone. Please remove the protocol and retry&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manny-2691(config-pmap-c)#&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Mar 2009 18:51:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162318#M874720</guid>
      <dc:creator>mramirez</dc:creator>
      <dc:date>2009-03-22T18:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162319#M874721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Manny,&lt;/P&gt;&lt;P&gt;   Sorry That was my fault. It should be like this. &lt;/P&gt;&lt;P&gt;Manny-2691(config-pmap)#class type inspect SSH&lt;/P&gt;&lt;P&gt;Manny-2691(config-pmap-c)#pass &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Toshi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Mar 2009 19:03:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162319#M874721</guid>
      <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
      <dc:date>2009-03-22T19:03:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162320#M874722</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Toshi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The pass did not work either. Here is what I have in the config so far. I have attached a snapshot from SDM to see if it makes any sense. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your help by the way. I am currently studying for my CCNA Security and is bugging the heck out of me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type inspect match-all sdm-cls-VPNOutsideToInside-1&lt;/P&gt;&lt;P&gt; match access-group 103&lt;/P&gt;&lt;P&gt;class-map type inspect match-any SDM_AH&lt;/P&gt;&lt;P&gt; match access-group name SDM_AH&lt;/P&gt;&lt;P&gt;class-map type inspect match-any sdm-cls-insp-traffic&lt;/P&gt;&lt;P&gt; match protocol cuseeme&lt;/P&gt;&lt;P&gt; match protocol dns&lt;/P&gt;&lt;P&gt; match protocol ftp&lt;/P&gt;&lt;P&gt; match protocol h323&lt;/P&gt;&lt;P&gt; match protocol https&lt;/P&gt;&lt;P&gt; match protocol icmp&lt;/P&gt;&lt;P&gt; match protocol imap&lt;/P&gt;&lt;P&gt; match protocol pop3&lt;/P&gt;&lt;P&gt; match protocol netshow&lt;/P&gt;&lt;P&gt; match protocol shell&lt;/P&gt;&lt;P&gt; match protocol realmedia&lt;/P&gt;&lt;P&gt; match protocol rtsp&lt;/P&gt;&lt;P&gt; match protocol smtp extended&lt;/P&gt;&lt;P&gt; match protocol sql-net&lt;/P&gt;&lt;P&gt; match protocol streamworks&lt;/P&gt;&lt;P&gt; match protocol tftp&lt;/P&gt;&lt;P&gt; match protocol vdolive&lt;/P&gt;&lt;P&gt; match protocol tcp&lt;/P&gt;&lt;P&gt; match protocol udp&lt;/P&gt;&lt;P&gt;class-map type inspect match-all sdm-insp-traffic&lt;/P&gt;&lt;P&gt; match class-map sdm-cls-insp-traffic&lt;/P&gt;&lt;P&gt;class-map type inspect match-any SDM_ESP&lt;/P&gt;&lt;P&gt; match access-group name SDM_ESP&lt;/P&gt;&lt;P&gt;class-map type inspect match-any SDM_VPN_TRAFFIC&lt;/P&gt;&lt;P&gt; match protocol isakmp&lt;/P&gt;&lt;P&gt; match protocol ipsec-msft&lt;/P&gt;&lt;P&gt; match class-map SDM_AH&lt;/P&gt;&lt;P&gt; match class-map SDM_ESP&lt;/P&gt;&lt;P&gt;class-map type inspect match-all SDM_VPN_PT&lt;/P&gt;&lt;P&gt; match access-group 102&lt;/P&gt;&lt;P&gt; match class-map SDM_VPN_TRAFFIC&lt;/P&gt;&lt;P&gt;class-map type inspect match-any SDM-Voice-permit&lt;/P&gt;&lt;P&gt; match protocol h323&lt;/P&gt;&lt;P&gt; match protocol skinny&lt;/P&gt;&lt;P&gt; match protocol sip&lt;/P&gt;&lt;P&gt;class-map type inspect match-any SDM-Voice&lt;/P&gt;&lt;P&gt; match protocol h323&lt;/P&gt;&lt;P&gt;class-map type inspect match-any sdm-cls-icmp-access&lt;/P&gt;&lt;P&gt; match protocol icmp&lt;/P&gt;&lt;P&gt; match protocol tcp&lt;/P&gt;&lt;P&gt; match protocol udp&lt;/P&gt;&lt;P&gt;class-map type inspect match-all SSH&lt;/P&gt;&lt;P&gt; match protocol ssh&lt;/P&gt;&lt;P&gt;class-map type inspect match-all GRE&lt;/P&gt;&lt;P&gt; match access-group 104&lt;/P&gt;&lt;P&gt;class-map type inspect match-all sdm-icmp-access&lt;/P&gt;&lt;P&gt; match class-map sdm-cls-icmp-access&lt;/P&gt;&lt;P&gt;class-map type inspect match-all sdm-invalid-src&lt;/P&gt;&lt;P&gt; match access-group 101&lt;/P&gt;&lt;P&gt;class-map type inspect match-all sdm-protocol-http&lt;/P&gt;&lt;P&gt; match protocol http&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;policy-map type inspect sdm-permit-icmpreply&lt;/P&gt;&lt;P&gt; class type inspect sdm-icmp-access&lt;/P&gt;&lt;P&gt;  inspect&lt;/P&gt;&lt;P&gt; class type inspect SDM-Voice&lt;/P&gt;&lt;P&gt;  inspect&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;  pass&lt;/P&gt;&lt;P&gt;policy-map type inspect sdm-pol-VPNOutsideToInside-1&lt;/P&gt;&lt;P&gt; class type inspect sdm-cls-VPNOutsideToInside-1&lt;/P&gt;&lt;P&gt;  inspect&lt;/P&gt;&lt;P&gt; class type inspect GRE&lt;/P&gt;&lt;P&gt;  pass&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;policy-map type inspect sdm-inspect&lt;/P&gt;&lt;P&gt; class type inspect sdm-invalid-src&lt;/P&gt;&lt;P&gt;  drop log&lt;/P&gt;&lt;P&gt; class type inspect sdm-insp-traffic&lt;/P&gt;&lt;P&gt;  inspect&lt;/P&gt;&lt;P&gt; class type inspect sdm-protocol-http&lt;/P&gt;&lt;P&gt;  inspect&lt;/P&gt;&lt;P&gt; class type inspect SDM-Voice-permit&lt;/P&gt;&lt;P&gt;  inspect&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;  pass    &lt;/P&gt;&lt;P&gt;policy-map type inspect sdm-permit&lt;/P&gt;&lt;P&gt; class type inspect SDM_VPN_PT&lt;/P&gt;&lt;P&gt;  pass&lt;/P&gt;&lt;P&gt; class type inspect SDM-Voice&lt;/P&gt;&lt;P&gt;  inspect&lt;/P&gt;&lt;P&gt; class type inspect SSH&lt;/P&gt;&lt;P&gt;  pass&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;  drop log&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;zone security out-zone&lt;/P&gt;&lt;P&gt;zone security in-zone&lt;/P&gt;&lt;P&gt;zone-pair security sdm-zp-self-out source self destination out-zone&lt;/P&gt;&lt;P&gt; service-policy type inspect sdm-permit-icmpreply&lt;/P&gt;&lt;P&gt;zone-pair security sdm-zp-VPNOutsideToInside-1 source out-zone destination in-zone&lt;/P&gt;&lt;P&gt; service-policy type inspect sdm-pol-VPNOutsideToInside-1&lt;/P&gt;&lt;P&gt;zone-pair security sdm-zp-out-self source out-zone destination self&lt;/P&gt;&lt;P&gt; service-policy type inspect sdm-permit&lt;/P&gt;&lt;P&gt;zone-pair security sdm-zp-in-out source in-zone destination out-zone&lt;/P&gt;&lt;P&gt; service-policy type inspect sdm-inspect&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Mar 2009 19:15:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162320#M874722</guid>
      <dc:creator>mramirez</dc:creator>
      <dc:date>2009-03-22T19:15:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162321#M874723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Manny,&lt;/P&gt;&lt;P&gt;   When you are trying to do SSH to the router then what's the exact error you got?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Edit: What is the exact ip address you are trying to use as a source ip address to do ssh to the router?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;####################&lt;/P&gt;&lt;P&gt;access-list 105 remark VTY Access-class list&lt;/P&gt;&lt;P&gt;access-list 105 remark SDM_ACL Category=1&lt;/P&gt;&lt;P&gt;access-list 105 permit ip 10.1.1.0 0.0.0.255 any&lt;/P&gt;&lt;P&gt;access-list 105 permit ip 192.168.2.0 0.0.0.255 any&lt;/P&gt;&lt;P&gt;####################&lt;/P&gt;&lt;P&gt;For testing :&lt;/P&gt;&lt;P&gt;line vty 0 4&lt;/P&gt;&lt;P&gt; No access-class 105 in&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please let me know.&lt;/P&gt;&lt;P&gt;Toshi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Mar 2009 19:36:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162321#M874723</guid>
      <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
      <dc:date>2009-03-22T19:36:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162322#M874724</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I got the error below when I tried putting the inspect command on the router under the policy-map. It did not like the inspect, so I tried the pass but that is still not letting me ssh into the router from a remote ip address. Here was the error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%Protocol ssh configured in class-map SSH cannot be configured for the self zone. Please remove the protocol and retry.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Mar 2009 19:41:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162322#M874724</guid>
      <dc:creator>mramirez</dc:creator>
      <dc:date>2009-03-22T19:41:49Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162323#M874725</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Manny,&lt;/P&gt;&lt;P&gt;  Well, It has to be "PASS". &lt;/P&gt;&lt;P&gt;What's the exact source ip address you are trying to do ssh to the router?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let's see my previous post&lt;/P&gt;&lt;P&gt;Toshi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Mar 2009 19:46:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162323#M874725</guid>
      <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
      <dc:date>2009-03-22T19:46:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162324#M874726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok here is the updated config. I have list the source IP in the access-list 105 for the VTY. It starts off with 99.xxxx.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Mar 2009 19:57:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162324#M874726</guid>
      <dc:creator>mramirez</dc:creator>
      <dc:date>2009-03-22T19:57:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162325#M874727</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Manny,&lt;/P&gt;&lt;P&gt;  Without using Zone Base Firewall. Did you ever access the router by using SSH protocol?  I've not seen any crypto key generated by the router.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pleas let me know&lt;/P&gt;&lt;P&gt;Toshi&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Mar 2009 20:02:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162325#M874727</guid>
      <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
      <dc:date>2009-03-22T20:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162326#M874728</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Toshi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I have verified that the crypto keys are generate using the command "sh crypto key mypubkey rsa" or using the SDM. I have not been able to SSH using this configuration. If I use a simple config from scratch, I can. But when I start adding  all the policys and class maps that's when I can't get back in.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Mar 2009 20:10:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162326#M874728</guid>
      <dc:creator>mramirez</dc:creator>
      <dc:date>2009-03-22T20:10:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162327#M874729</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many,&lt;/P&gt;&lt;P&gt;  Here is my last hope. let's try this first&lt;/P&gt;&lt;P&gt;  !&lt;/P&gt;&lt;P&gt;  policy-map type inspect sdm-permit&lt;/P&gt;&lt;P&gt;  no class type inspect SSH&lt;/P&gt;&lt;P&gt;  !&lt;/P&gt;&lt;P&gt;  ip access-list extended SSH&lt;/P&gt;&lt;P&gt;  permit tcp any any eq 22&lt;/P&gt;&lt;P&gt;  !&lt;/P&gt;&lt;P&gt;  class-map type inspect match-any SSH&lt;/P&gt;&lt;P&gt;  match access-group name SDM_SSH&lt;/P&gt;&lt;P&gt;  !&lt;/P&gt;&lt;P&gt;  !&lt;/P&gt;&lt;P&gt;  policy-map type inspect sdm-permit&lt;/P&gt;&lt;P&gt;  class type inspect SSH&lt;/P&gt;&lt;P&gt;  pass&lt;/P&gt;&lt;P&gt;  !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;   !&lt;/P&gt;&lt;P&gt;  policy-map type inspect sdm-permit&lt;/P&gt;&lt;P&gt;  no class type inspect SSH&lt;/P&gt;&lt;P&gt;  !&lt;/P&gt;&lt;P&gt;  ip access-list extended SSH&lt;/P&gt;&lt;P&gt;  permit tcp any any eq 22&lt;/P&gt;&lt;P&gt;  !&lt;/P&gt;&lt;P&gt;  class-map type inspect match-any SSH&lt;/P&gt;&lt;P&gt;  match access-group name SSH&lt;/P&gt;&lt;P&gt;  !&lt;/P&gt;&lt;P&gt;  class-map type inspect match-any access-to-router&lt;/P&gt;&lt;P&gt;  match class-map SSH&lt;/P&gt;&lt;P&gt;  !&lt;/P&gt;&lt;P&gt;  policy-map type inspect sdm-permit&lt;/P&gt;&lt;P&gt;  class type inspect access-to-router&lt;/P&gt;&lt;P&gt;  inspect&lt;/P&gt;&lt;P&gt;  !&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Toshi&lt;/P&gt;&lt;P&gt;   &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Mar 2009 20:20:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162327#M874729</guid>
      <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
      <dc:date>2009-03-22T20:20:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162328#M874730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Toshi! You are a genius dude! The second option worked beautifully! I really appreciate your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a book/resource that you used to learn this? I am going thu my CCNA security exam and it doesn't go to much into detail on Zone firewalls. I did buy the Cisco Deploying Zone-Based Firewalls book, but did not show an example of ssh access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now all that is left is allowing webserver/mail/ftp. Do you have any quick examples of that? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Manny&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Mar 2009 20:42:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162328#M874730</guid>
      <dc:creator>mramirez</dc:creator>
      <dc:date>2009-03-22T20:42:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162329#M874731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Manny,&lt;/P&gt;&lt;P&gt;  Please check this link out. It may helps you.&lt;/P&gt;&lt;P&gt;  &lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/sw/secursw/ps1018/prod_white_papers_list.html" target="_blank"&gt;http://www.cisco.com/en/US/products/sw/secursw/ps1018/prod_white_papers_list.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;I'm now sleepy head. (grin)@4am.&lt;/P&gt;&lt;P&gt;Toshi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Mar 2009 21:06:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162329#M874731</guid>
      <dc:creator>Thotsaphon Lueangwattanaphong</dc:creator>
      <dc:date>2009-03-22T21:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162330#M874732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks again!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 22 Mar 2009 21:11:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162330#M874732</guid>
      <dc:creator>mramirez</dc:creator>
      <dc:date>2009-03-22T21:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162331#M874733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does this also count for snmp because it seems that snmp is also blocked by default&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Mar 2009 11:36:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162331#M874733</guid>
      <dc:creator>FredDenHeijer</dc:creator>
      <dc:date>2009-03-23T11:36:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162332#M874734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Fred,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess it depends if your using snmp in the inside or outside?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Mar 2009 12:48:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162332#M874734</guid>
      <dc:creator>mramirez</dc:creator>
      <dc:date>2009-03-23T12:48:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162333#M874735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm trying to get it working from the outside. I wasn't able to connect with the Cisco 871 from the outside with ssh but that is functioning know due to your solution. I was wondering if this also the case with monitoring from the outside because we want to monitor customers remotely.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Mar 2009 14:10:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162333#M874735</guid>
      <dc:creator>FredDenHeijer</dc:creator>
      <dc:date>2009-03-23T14:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162334#M874736</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will try it later on tonight and let you know. I am fairly new to Zone-Based Firewalls. I would think to follow the same concept of ssh as in th example above. Post your config and maybe Toshi can comment on it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Mar 2009 14:16:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162334#M874736</guid>
      <dc:creator>mramirez</dc:creator>
      <dc:date>2009-03-23T14:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to allow SSH into Zone Based Firewall?</title>
      <link>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162335#M874737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;here is my config;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Mar 2009 14:55:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/how-to-allow-ssh-into-zone-based-firewall/m-p/1162335#M874737</guid>
      <dc:creator>FredDenHeijer</dc:creator>
      <dc:date>2009-03-23T14:55:25Z</dc:date>
    </item>
  </channel>
</rss>

