cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
971
Views
0
Helpful
3
Replies

Cannot SSH into PIX

michael.ball
Level 1
Level 1

I would like to be able to use an SSH client to connect to my PIX firewall over the Internet. I can do this to my 506 PIX but not on my 515, with debug SSH on I keep seeing "invalid userid michael" even though I have put the command "user michael password michael privilege 15" into the configuration. What am I doing wrong?

1 Accepted Solution

Accepted Solutions

Patrick Iseli
Level 7
Level 7

Have you created a rsa key ?

#Generate a key:

ca generate rsa key 1024

show ca mypubkey rsa

#Save ssh key:

ca save all

#Allow incomming ssh connections:

ssh ip_address [netmask] [interface_name]

aaa authentication ssh console LOCAL

sincerely

Patrick

View solution in original post

3 Replies 3

Patrick Iseli
Level 7
Level 7

Have you created a rsa key ?

#Generate a key:

ca generate rsa key 1024

show ca mypubkey rsa

#Save ssh key:

ca save all

#Allow incomming ssh connections:

ssh ip_address [netmask] [interface_name]

aaa authentication ssh console LOCAL

sincerely

Patrick

Michael,

Have a look at this document and make sure that you have all the configuration required to allow SSH access from the outside host.

http://cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a008069bf1b.shtml#conf

If you are still having problems post the sanitized configuration and debug ssh output.

HTH

Sundar

oabduo983
Level 1
Level 1

YOU ARE MISSING:

aaa authentication ssh console LOCAL

Otherwise, use pix as username and your telnet password to access your unit!

Please rate this post if it was helpful!

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card