When I am trying to access one of the device through putty I am getting error.
but when I tried to telnet with port 22 to that device ip , I can see port as open.
I am trying with public IP , assuming it is natted in other end FW.
What would be the reason ?
Best is to go over your ssh implementation, take a look at this link and compare it to your configuration.
if still not joy post config
Sorry I think I confused you , I do not want to setup ssh in FW.
I can telnet 18.104.22.168 22 from cmd prompt , but I am not able to connect using putty and getting error - network error.
Sorry too.. missed understood !
Use SSHv2 , I just tested ssh to that address using different ssh client from yours and got error saying sshv2, once I change my client to use sshv2 worked.
in your putty ssh section select to connect using ssh protocol version 2.
In my putty it is version 2 only,but it does not work.
Could you attach the setup file of putty which you are using?
Primarily use SecureCRT client - see attached.. I don't use putty but just loaded a copy from another system in lab-what would the config file name be don't seem to fine one..
In any event.. it must be your client settings - I launch putty and also worked .. in putty under SSH settings is configured as
Seem like the rsa key pair hasn't been created.
Pls. follow this procedure to enable ssh on the firewall.
Ssh 0 0 outside
Crypto key generate rsa modulus 1024
Username Cisco password Cisco priv 15
Aaa authentication ssh console LOCAL
Aaa authentication enable console LOCAl
Bear in mind, you can only ssh to the closest interface of the firewall.
Meaning, you cannot be on the inside and try to ssh to the outside interface IP address.
Kureli, I believe Mahin is trying to ssh to an internal system running ssh not the firewall itself .. I thought that at the begining as well.. above procedure will not resolve this issue.
Mahin.. in your putty client go to SSH settings and under Encryption cipher selection policy: have AES(SSH-2only) as the first TOP choice in the order - see if that helps
Let me clear the scenario once again.
I am trying to ssh to 22.214.171.124.
we have two ISP connection ,lets say ISP1 and ISP2.
ISP1 is connected to 515E FW and ISP2 is connected to another 515E FW.
I can access through the second ISP2 that is our Backup ISP , but through the second ISP 1 I am getting error which I attached earlier.
If you need FW logs I can forward you that.
Im not to clear about your setup, so you have two PIXes one being the primary ISP1 and other PIX as secondary ISP2.. so you have two different Public IP blocks?
what is the default route point to in the system running ssh in relation to PIX ISP1 and ISP2.
now what Im not to clear either is that I have tested your ssh connection using 126.96.36.199 and it worked.. so Im assuming you have NAT setup in PIX off ISP2 using 188.8.131.52 address.. are you using different address for ISP1.
if you could provide some fw logs while you try connecting to ssh that would help.
Thanks John for clarifying.
I am not sure about the topology. I thought I posted this yesterday but may have missed to hit the post button.
Now, which device owns this IP address 184.108.40.206?
I tried to ssh to 220.127.116.11 and it failed. I got the same message "Network error: Connection timed out".
Do the inside of the two firewalls belong to the same subnet?
Where is the source which is trying to ssh live?
What do you see in the logs when you attempt this SSH and when it fails?