Unable to access device through PUTTY

Unanswered Question
Sep 23rd, 2009

When I am trying to access one of the device through putty I am getting error.

but when I tried to telnet with port 22 to that device ip , I can see port as open.

I am trying with public IP , assuming it is natted in other end FW.

What would be the reason ?

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Mahinmitrxblr Wed, 09/23/2009 - 08:01

Sorry I think I confused you , I do not want to setup ssh in FW.


I can telnet 22 from cmd prompt , but I am not able to connect using putty and getting error - network error.

JORGE RODRIGUEZ Wed, 09/23/2009 - 08:15

Sorry too.. missed understood !

Use SSHv2 , I just tested ssh to that address using different ssh client from yours and got error saying sshv2, once I change my client to use sshv2 worked.


in your putty ssh section select to connect using ssh protocol version 2.

Mahinmitrxblr Wed, 09/23/2009 - 09:35

In my putty it is version 2 only,but it does not work.

Could you attach the setup file of putty which you are using?

JORGE RODRIGUEZ Wed, 09/23/2009 - 10:23

Primarily use SecureCRT client - see attached.. I don't use putty but just loaded a copy from another system in lab-what would the config file name be don't seem to fine one..

In any event.. it must be your client settings - I launch putty and also worked .. in putty under SSH settings is configured as

Mahinmitrxblr Wed, 09/23/2009 - 10:39

I am getting the different error that I have attached here.

I routed the traffic through another ISP(Backup ISP) and it is working.

Kureli Sankar Wed, 09/23/2009 - 10:50

Seem like the rsa key pair hasn't been created.

Pls. follow this procedure to enable ssh on the firewall.

Ssh 0 0 outside

Crypto key generate rsa modulus 1024

Username Cisco password Cisco priv 15

Aaa authentication ssh console LOCAL

Aaa authentication enable console LOCAl


Bear in mind, you can only ssh to the closest interface of the firewall.

Meaning, you cannot be on the inside and try to ssh to the outside interface IP address.

JORGE RODRIGUEZ Wed, 09/23/2009 - 11:12

Kureli, I believe Mahin is trying to ssh to an internal system running ssh not the firewall itself .. I thought that at the begining as well.. above procedure will not resolve this issue.



Mahin.. in your putty client go to SSH settings and under Encryption cipher selection policy: have AES(SSH-2only) as the first TOP choice in the order - see if that helps

Mahinmitrxblr Thu, 09/24/2009 - 02:30

Let me clear the scenario once again.

I am trying to ssh to

we have two ISP connection ,lets say ISP1 and ISP2.

ISP1 is connected to 515E FW and ISP2 is connected to another 515E FW.

I can access through the second ISP2 that is our Backup ISP , but through the second ISP 1 I am getting error which I attached earlier.

If you need FW logs I can forward you that.

JORGE RODRIGUEZ Fri, 09/25/2009 - 05:54

Im not to clear about your setup, so you have two PIXes one being the primary ISP1 and other PIX as secondary ISP2.. so you have two different Public IP blocks?

what is the default route point to in the system running ssh in relation to PIX ISP1 and ISP2.

now what Im not to clear either is that I have tested your ssh connection using and it worked.. so Im assuming you have NAT setup in PIX off ISP2 using address.. are you using different address for ISP1.

if you could provide some fw logs while you try connecting to ssh that would help.


Kureli Sankar Fri, 09/25/2009 - 06:21

Thanks John for clarifying.

I am not sure about the topology. I thought I posted this yesterday but may have missed to hit the post button.




Now, which device owns this IP address

I tried to ssh to and it failed. I got the same message "Network error: Connection timed out".

Do the inside of the two firewalls belong to the same subnet?

Where is the source which is trying to ssh live?

What do you see in the logs when you attempt this SSH and when it fails?


This Discussion