Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Forward ssh requests to internal PC

I'm trying to forward all ssh requests for my outside IP to a PC, named "alphapc", behind my PIX 506E firewall. Under my current configuration, all ssh requests to my outside IP timeout. My configuration is below.



: Saved


PIX Version 6.1(4)

nameif ethernet0 outside security0

nameif ethernet1 inside security100

enable password [***PASSWORD***] encrypted

passwd [***PASSWORD***] encrypted

hostname [***HOST NAME***]


fixup protocol ftp 21

fixup protocol http 80

fixup protocol h323 1720

fixup protocol rsh 514

fixup protocol rtsp 554

fixup protocol smtp 25

fixup protocol sqlnet 1521

fixup protocol sip 5060

fixup protocol skinny 2000


name alphapc

name betapc

access-list ping_acl permit ip any any

access-list OUTSIDEACL permit tcp any host eq www

pager lines 20

interface ethernet0 auto

interface ethernet1 auto

mtu outside 1500

mtu inside 1500

ip address outside [***OUTSIDE IP ADDRESS***]

ip address inside

ip audit info action alarm

ip audit attack action alarm

pdm location alphapc inside

pdm location betapc inside

pdm history enable

arp timeout 72

global (outside) 1 interface

nat (inside) 1 0 0

static (inside,outside) tcp interface 22 alphapc 22 netmask 0 0

route outside [***GATEWAY***] 1

timeout xlate 3:00:00

timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 rpc 0:10:00 h323 0:05:00 si

p 0:30:00 sip_media 0:02:00

timeout uauth 0:05:00 absolute

aaa-server TACACS+ protocol tacacs+

aaa-server RADIUS protocol radius

no snmp-server location

no snmp-server contact

snmp-server community public

no snmp-server enable traps

floodguard enable

no sysopt route dnat

telnet timeout 5

ssh outside

ssh inside

ssh timeout 60

dhcpd address inside

dhcpd dns [***PRIMARY DNS***] [***SECONDARY DNS***]

dhcpd lease 3600

dhcpd ping_timeout 750

dhcpd domain [***DOMAIN NAME***]

dhcpd enable inside

terminal width 80

New Member

Re: Forward ssh requests to internal PC

It is not allowed through your OUTSIDEACL which is also not applied to an interface.

access-group OUTSIDEACL in interface outside

Cisco Employee

Re: Forward ssh requests to internal PC


You need to define an access-list to allow SSH to the translated IP Address and apply the access-group inbound on the outside interface.

For example:

access-list OUTSIDEACL permit tcp any host x.x.x.x eq 22

access-group OUTSIDEACL in interface outside

I hope it helps.



** Please rate all helpful posts **

Re: Forward ssh requests to internal PC

Hi .. I don't think you can use the PIX's interface to redirect ssh to another hosts. You could however try by disabling ssh to the outside interface no ssh outside and the modifying the static so tat is has the piblic ip address of your PIX instead of the 'interface' keyword ..

static (inside,outside) tcp 22 alphapc 22 netmask

allow access for ssh to the Public IP of your PIX on the access-list applied to the outside interface ..i.e

access-list Outside_IN extended permit tcp any host eq 22

access-group Outside_IN in interface outside

NOTE: after modifying teh static you will need to type clear xlate for the change to take place right away however any established connections at that moment will be be forced to reconnect.

I hope it helps .. please rate if it does !!!

CreatePlease login to create content