02-07-2024 02:54 PM - edited 02-07-2024 02:54 PM
I am facing SSH connection failure between a source and destination using Public IPs over internet, It seems SSH traffic is blocked somewhere in the middle. Tried to telnet destination IP on port 22 but fails, while with some other TCP ports it's successful. SSH traffic was not reaching the other side. Source IP is a public IP that is static natted(on the cisco router) to one of the inside server private IPs. Is it possible to overcome this issue with a workaround like a GRE tunnel between source and destination, and forcing SSH traffic to pass through the tunnel. If possible, will the static NAT be a problem? Suggestions please. Thanks in advance.
02-07-2024 03:35 PM
Hello
Is ssh enabled on the destination device and is there any ACL or Control plane policing negating access to the vty lines?
If the host is behind a NAT then is port forwarding enabled for ssh for that particular device?
02-07-2024 07:45 PM
02-07-2024 11:49 PM
If the device you need to access via ssh is ASR then it can ssh port is not 22 and it use other ssh port.
Force router using port 22.
MHM
02-08-2024 12:26 AM
To make sure that your config is right, i suggest you run a packet capture at the source/destination (ideally at the edge) and confirm then where the traffic is getting dropped.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide