<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH through a PIX to a Unix Server in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821247#M958331</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will this effect any of the other access-lists that I currently have?  (I know it probably won't but I am allow voice traffic through the PIX as well so I definitely do not want thing to mess that up.)  Appreciate the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 28 Dec 2007 14:10:19 GMT</pubDate>
    <dc:creator>asmith252</dc:creator>
    <dc:date>2007-12-28T14:10:19Z</dc:date>
    <item>
      <title>SSH through a PIX to a Unix Server</title>
      <link>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821245#M958328</link>
      <description>&lt;P&gt;I need to setup a PIX to allow ssh traffic to a Unix server on our network.  I need suggestions on how to do this.  I tried an access list and I don't think port forwarding is an option with the PIX.  Need help.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 00:52:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821245#M958328</guid>
      <dc:creator>asmith252</dc:creator>
      <dc:date>2019-03-13T00:52:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSH through a PIX to a Unix Server</title>
      <link>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821246#M958329</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;static (i,o) tcp interface 22 192.168.1.10 22 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;access-list test permit tcp any interface eq 22 log&lt;/P&gt;&lt;P&gt;access-group test in interface outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where 192.168.1.10 is the ip address of the unix server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Easy right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CCIE security&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 19 Dec 2007 23:12:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821246#M958329</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2007-12-19T23:12:33Z</dc:date>
    </item>
    <item>
      <title>Re: SSH through a PIX to a Unix Server</title>
      <link>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821247#M958331</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Will this effect any of the other access-lists that I currently have?  (I know it probably won't but I am allow voice traffic through the PIX as well so I definitely do not want thing to mess that up.)  Appreciate the help.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2007 14:10:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821247#M958331</guid>
      <dc:creator>asmith252</dc:creator>
      <dc:date>2007-12-28T14:10:19Z</dc:date>
    </item>
    <item>
      <title>Re: SSH through a PIX to a Unix Server</title>
      <link>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821248#M958333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;that solution will work as long as you dont want to be able to ssh to the outside interface of your pix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you need to add that acl entry to whatever your outside-2-inside acl is.  he was just showing you an example.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2007 14:25:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821248#M958333</guid>
      <dc:creator>srue</dc:creator>
      <dc:date>2007-12-28T14:25:00Z</dc:date>
    </item>
    <item>
      <title>Re: SSH through a PIX to a Unix Server</title>
      <link>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821249#M958334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok, after I add the acl entry to the outside-2-inside acl, will it allow ssh from outside the network?  the whole reason i'm doing this is so a vendor can connect to a server on our network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2007 14:39:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821249#M958334</guid>
      <dc:creator>asmith252</dc:creator>
      <dc:date>2007-12-28T14:39:11Z</dc:date>
    </item>
    <item>
      <title>Re: SSH through a PIX to a Unix Server</title>
      <link>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821250#M958336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it will.  As a test, you can do this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list test permit tcp any interface eq 22 log&lt;/P&gt;&lt;P&gt;access-list test permit ip any any log&lt;/P&gt;&lt;P&gt;access-group test in interface outside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that will make sure you don't break anything&lt;/P&gt;&lt;P&gt;along the way.  Once you know everything&lt;/P&gt;&lt;P&gt;works, you can start locking down your stuffs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The example I gave you, it means that you will&lt;/P&gt;&lt;P&gt;NOT be able to ssh to the Pix itself from&lt;/P&gt;&lt;P&gt;the outside interface.  This is one of many&lt;/P&gt;&lt;P&gt;things I do not like about Pix.  With other &lt;/P&gt;&lt;P&gt;firewalls vendors such as Checkpoint or &lt;/P&gt;&lt;P&gt;Juniper, you can change the ssh port on the&lt;/P&gt;&lt;P&gt;firewall itself to something other than 22.&lt;/P&gt;&lt;P&gt;For example, on the checkpoint firewall,&lt;/P&gt;&lt;P&gt;I can change the ssh port on the checkpoint&lt;/P&gt;&lt;P&gt;firewall from 22 to 222 so that from the &lt;/P&gt;&lt;P&gt;outside, I can ssh to both the Unix and the&lt;/P&gt;&lt;P&gt;firewall at the same time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, that should work for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CCIE security&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2007 14:45:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821250#M958336</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2007-12-28T14:45:57Z</dc:date>
    </item>
    <item>
      <title>Re: SSH through a PIX to a Unix Server</title>
      <link>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821251#M958337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you can change the port forwarding to be 222---&amp;gt;22 to the server. just have your vendor change ports on their SSH session and keep the fw admin happy &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2007 22:20:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821251#M958337</guid>
      <dc:creator>palomoj</dc:creator>
      <dc:date>2007-12-28T22:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: SSH through a PIX to a Unix Server</title>
      <link>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821252#M958338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I entered those commands into the CLI.  It didn't like the eq 22 statement so I just put in interface 22.  Now, when the vendor tries to ssh into the server he gets a time out message.  Also, he said he only sees port 1723 open for the Windows VPN.  He has the right public IP so right now I am kind of stumped.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2007 22:35:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821252#M958338</guid>
      <dc:creator>asmith252</dc:creator>
      <dc:date>2007-12-28T22:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: SSH through a PIX to a Unix Server</title>
      <link>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821253#M958339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What does your static look like? It should be...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;static (inside,outside) tcp interface 222 192.168.1.10 22 netmask 255.255.255.255 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is your ACL open for?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...permit tcp any interface outside eq 222&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Dec 2007 23:47:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821253#M958339</guid>
      <dc:creator>palomoj</dc:creator>
      <dc:date>2007-12-28T23:47:24Z</dc:date>
    </item>
    <item>
      <title>Re: SSH through a PIX to a Unix Server</title>
      <link>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821254#M958340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I entered the acl command is as it is above and it will not accept the first line.  I took out the eq 22 and just used interface 22 log and then is said that interface 22 does not exist.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jan 2008 18:45:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821254#M958340</guid>
      <dc:creator>asmith252</dc:creator>
      <dc:date>2008-01-02T18:45:53Z</dc:date>
    </item>
    <item>
      <title>Re: SSH through a PIX to a Unix Server</title>
      <link>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821255#M958341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ACL should be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list test permit tcp any interface outside eq 222 log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jan 2008 19:05:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-through-a-pix-to-a-unix-server/m-p/821255#M958341</guid>
      <dc:creator>cisco24x7</dc:creator>
      <dc:date>2008-01-02T19:05:37Z</dc:date>
    </item>
  </channel>
</rss>

