cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
411
Views
0
Helpful
5
Replies

PIX behind Cisco 1841 - Need SSH access

molinek
Level 1
Level 1

Hello, trying to allow SSH access to PIX for a few external clinets/hosts.

What are the correct Acl's I need?

1 Accepted Solution

Accepted Solutions

Exactly correct ..

1.- On the router you need to allow incoming TCP 22 (ssh) to your PIX on the outside interface of the router and also allow the return traffic from the PIX on the inside interface of the router.

2.- On the PIX you need to generate the rsa keys and save them.

ca generate rsa key 1024

ca save all

3.- On the pix you need to allow ssh acccess to te outside interface

ssh outside

Rate it if you find it helpful

View solution in original post

5 Replies 5

sebastan_bach
Level 4
Level 4

hi there for ssh. all u need to do is generate the rsa keys. and ssh specify the ip address fo the hosts or their subnet and they will get access. u don't need to have any access-list cause u are connecting to the pix and not through the pix. hope this helps. pls rate if it does.

sebastan

How about Acl's on the 1841 router to access the PIX?

The Pix is behind the router and I want to gain access to it from the internet.

Yeah, the PIX won't need anything but how is going to connect via SSH Like:

SSH 12.152.XXX.XXX 255.255.255.255 OUTSIDE

Exactly correct ..

1.- On the router you need to allow incoming TCP 22 (ssh) to your PIX on the outside interface of the router and also allow the return traffic from the PIX on the inside interface of the router.

2.- On the PIX you need to generate the rsa keys and save them.

ca generate rsa key 1024

ca save all

3.- On the pix you need to allow ssh acccess to te outside interface

ssh outside

Rate it if you find it helpful

Could you please provide me some examples ofthe Acl's that I'll need on the 1841? Then I will rate it.

Thanks Fernando.

dude i guess people have helped u a lot out here . if u are not even clear to work with acls. then sorry we can't help u . and pls don't ask for favours just to get to rate them

sebastan

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card