Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Cannot SSH into PIX

I would like to be able to use an SSH client to connect to my PIX firewall over the Internet. I can do this to my 506 PIX but not on my 515, with debug SSH on I keep seeing "invalid userid michael" even though I have put the command "user michael password michael privilege 15" into the configuration. What am I doing wrong?

1 ACCEPTED SOLUTION

Accepted Solutions

Re: Cannot SSH into PIX

Have you created a rsa key ?

#Generate a key:

ca generate rsa key 1024

show ca mypubkey rsa

#Save ssh key:

ca save all

#Allow incomming ssh connections:

ssh ip_address [netmask] [interface_name]

aaa authentication ssh console LOCAL

sincerely

Patrick

3 REPLIES

Re: Cannot SSH into PIX

Have you created a rsa key ?

#Generate a key:

ca generate rsa key 1024

show ca mypubkey rsa

#Save ssh key:

ca save all

#Allow incomming ssh connections:

ssh ip_address [netmask] [interface_name]

aaa authentication ssh console LOCAL

sincerely

Patrick

Re: Cannot SSH into PIX

Michael,

Have a look at this document and make sure that you have all the configuration required to allow SSH access from the outside host.

http://cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008069bf1b.shtml#conf

If you are still having problems post the sanitized configuration and debug ssh output.

HTH

Sundar

Bronze

Re: Cannot SSH into PIX

YOU ARE MISSING:

aaa authentication ssh console LOCAL

Otherwise, use pix as username and your telnet password to access your unit!

Please rate this post if it was helpful!

468
Views
0
Helpful
3
Replies