Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

enabling ssh to certain computer

I have few computers behind PIX 501. Few of them has no access to internet (access-list inside line 1 deny ip host 192.168.1.10 etc) and others have full access. Now I want to give some of those denied computers an SSH access to outside. I have tried

access-list inside line 6 permit tcp host 192.168.1.10 eq ssh any eq ssh

, but SSH-client says Connection Refused. Do I need some other access-rules or is the problem somewhere else?

1 ACCEPTED SOLUTION

Accepted Solutions
Green

Re: enabling ssh to certain computer

You need to have the permit line before the deny line.

access-list inside permit tcp host 192.168.1.10 any eq ssh

access-list inside deny ip host 192.168.1.10 any

Please rate helpful posts.

3 REPLIES

Re: enabling ssh to certain computer

Hi

Source port may not be 22, depends on the client coding. Change your ACL line to:

access-list inside line 6 permit tcp host 192.168.1.10 any eq ssh

New Member

Re: enabling ssh to certain computer

That change didn't seem to work. It seems that outbound connection works, but inbound doesnt. access-list inside line 1 deny ip host 192.168.1.10 gets hits when i try to SSH out from the computer.

Green

Re: enabling ssh to certain computer

You need to have the permit line before the deny line.

access-list inside permit tcp host 192.168.1.10 any eq ssh

access-list inside deny ip host 192.168.1.10 any

Please rate helpful posts.

428
Views
0
Helpful
3
Replies