<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: need to telnet to outside int of ASA and PIX in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/need-to-telnet-to-outside-int-of-asa-and-pix/m-p/961502#M941626</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;on both you need to define a source IP that wil be cocming in to manage the device. I don't necessarily recommend telnet you should really use ssh. that being said, &lt;/P&gt;&lt;P&gt;on the PIX telnet (example) 0.0.0.0 0.0.0.0 outside this allows all devices to telnet into outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the asa same thing telnet 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;definitely want to narrow it down though. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if your SIP was 1.2.3.4 for example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet 1.2.3.4 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 29 Feb 2008 17:08:51 GMT</pubDate>
    <dc:creator>cdusio</dc:creator>
    <dc:date>2008-02-29T17:08:51Z</dc:date>
    <item>
      <title>need to telnet to outside int of ASA and PIX</title>
      <link>https://community.cisco.com/t5/network-security/need-to-telnet-to-outside-int-of-asa-and-pix/m-p/961501#M941625</link>
      <description>&lt;P&gt;I have a site to site connection setup between an ASA 5510 and a PIX 501. I have the ASA's inside 10.1.1.x network being able to access the PIX's 10.2.2.x network. That is working fine. However, I need to be able to access both the ASA and PIX's outside interfaces with telnet. I know the ASA requires a vpn, not sure about the PIX. how do I set up the vpn config to telnet to the outside address? Obviously the outside address is not part of the existing vpn config allowing the inside networks to talk, so I'm unsure of how to do that. Say my outside address on the ASA was 2.2.2.2 and the PIX was 4.4.4.4. How would I set that piece up?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:10:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-telnet-to-outside-int-of-asa-and-pix/m-p/961501#M941625</guid>
      <dc:creator>matthewmphc</dc:creator>
      <dc:date>2019-03-11T12:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: need to telnet to outside int of ASA and PIX</title>
      <link>https://community.cisco.com/t5/network-security/need-to-telnet-to-outside-int-of-asa-and-pix/m-p/961502#M941626</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;on both you need to define a source IP that wil be cocming in to manage the device. I don't necessarily recommend telnet you should really use ssh. that being said, &lt;/P&gt;&lt;P&gt;on the PIX telnet (example) 0.0.0.0 0.0.0.0 outside this allows all devices to telnet into outside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the asa same thing telnet 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;definitely want to narrow it down though. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if your SIP was 1.2.3.4 for example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet 1.2.3.4 255.255.255.255 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Feb 2008 17:08:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-telnet-to-outside-int-of-asa-and-pix/m-p/961502#M941626</guid>
      <dc:creator>cdusio</dc:creator>
      <dc:date>2008-02-29T17:08:51Z</dc:date>
    </item>
    <item>
      <title>Re: need to telnet to outside int of ASA and PIX</title>
      <link>https://community.cisco.com/t5/network-security/need-to-telnet-to-outside-int-of-asa-and-pix/m-p/961503#M941628</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;doesn't the telnet session on the ASA need to be via vpn? wouldn't there be additional commands I would need?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Feb 2008 18:57:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-telnet-to-outside-int-of-asa-and-pix/m-p/961503#M941628</guid>
      <dc:creator>matthewmphc</dc:creator>
      <dc:date>2008-02-29T18:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: need to telnet to outside int of ASA and PIX</title>
      <link>https://community.cisco.com/t5/network-security/need-to-telnet-to-outside-int-of-asa-and-pix/m-p/961504#M941630</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You cannot telnet to outside interface of pix or asa. If you want to do it through a vpn you need to add "management-access inside" and telnet to the inside interface.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Feb 2008 19:03:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-telnet-to-outside-int-of-asa-and-pix/m-p/961504#M941630</guid>
      <dc:creator>acomiskey</dc:creator>
      <dc:date>2008-02-29T19:03:59Z</dc:date>
    </item>
    <item>
      <title>Re: need to telnet to outside int of ASA and PIX</title>
      <link>https://community.cisco.com/t5/network-security/need-to-telnet-to-outside-int-of-asa-and-pix/m-p/961505#M941631</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can telnet to the outside of a pix/asa as long as it's over a vpn, and management-access outside is configured.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Feb 2008 20:15:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-telnet-to-outside-int-of-asa-and-pix/m-p/961505#M941631</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2008-02-29T20:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: need to telnet to outside int of ASA and PIX</title>
      <link>https://community.cisco.com/t5/network-security/need-to-telnet-to-outside-int-of-asa-and-pix/m-p/961506#M941632</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Actually you can. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The telnet command lets you specify which hosts can access the security appliance console with Telnet. You can enable Telnet to the security appliance on all interfaces. But, the security appliance enforces that all Telnet traffic to the outside interface be protected by IPsec. In order to enable a Telnet session to the outside interface, configure IPsec on the outside interface to include IP traffic that is generated by the security appliance and enable Telnet on the outside interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However you are correct that to telnet through the vpn you need to do what you are describing. I was under the impression that the telnet was outside of the vpn.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still should use SSH though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Feb 2008 20:44:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-telnet-to-outside-int-of-asa-and-pix/m-p/961506#M941632</guid>
      <dc:creator>cdusio</dc:creator>
      <dc:date>2008-02-29T20:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: need to telnet to outside int of ASA and PIX</title>
      <link>https://community.cisco.com/t5/network-security/need-to-telnet-to-outside-int-of-asa-and-pix/m-p/961507#M941633</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; do due to the security region u can't able to access the firewall outside interface by using the telnet. U can use the ssh for the outside access.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Mar 2008 08:22:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/need-to-telnet-to-outside-int-of-asa-and-pix/m-p/961507#M941633</guid>
      <dc:creator>onlyabhishek007</dc:creator>
      <dc:date>2008-03-07T08:22:01Z</dc:date>
    </item>
  </channel>
</rss>

