Re: [fw-wiz] PIX denying SSH Access - until I run PDM?

From: Tichomir Kotek (tichomir.kotek_at_lynx.sk)
Date: 08/30/05

  • Next message: Greg Padden: "Re: [fw-wiz] PIX denying SSH Access - until I run PDM?"
    To: firewall-wizards@honor.icsalabs.com
    Date: Tue, 30 Aug 2005 12:48:38 +0200
    
    

    Paul Pershing wrote:
    > Hi,

    Hi,

    > The odd part is that I discovered through trial and error that if
    > access the PIX via PDM after the failed SSH attempt - even if the PDM
    > connection is not completed - I can then attach via SSH.

    I observerd the same weird behavior. Somehow I figured out that
    before connecting with ssh one must generate certificate on pix.
    ("show ca mypubkey rsa " to verify if you have any)

    BUT using pdm pix auto-generates self-signed certificate automagically
    (I think even connecting to https generates one) and after that ssh
    is working fine.
    before using ssh do not forget to "ca generate rsa key 1024"
    "ca save all" to save those keys to permanent storage.

    > This is such a bizarre problem that I've been reluctant to post it;
    > but I've encountered it so many times now that my curiousity has
    > gotten the better of me!

    hope that helps

    tk

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: Greg Padden: "Re: [fw-wiz] PIX denying SSH Access - until I run PDM?"

    Relevant Pages

    • Re: SSH connection not valid until PDM launched
      ... > I cannot connect to my PIX box via SSH. ... It seems that presentation of the certificate via trying to start ... > the PDM causes SSH to be able to connect. ...
      (comp.dcom.sys.cisco)
    • Re: Cisco PIX with SSH enabled on external port for maintenance
      ... I took the original poster as wanting to enable SSH to the PIX itself ... - PIX SSH does not support public key authentication. ... VPN fixes this by ...
      (Security-Basics)
    • Re: Cisco PIX with SSH enabled on external port for maintenance
      ... As far as the PIX goes I would try to avoid leaving the management ... I personally favor connecting to the PIX ... If you must support SSH to the "outside" interface then you should ... >> external side of my Cisco PIX firewall. ...
      (Security-Basics)
    • Re: Cisco PIX with SSH enabled on external port for maintenance
      ... network through the PIX for administration on his network. ... You can still filter with the PIX. ... Your points about the PIX SSH are noted by me, ... VPN fixes this by ...
      (Security-Basics)
    • Re: SSH
      ... I'm connecting from different network eth0 is ... Subject: SSH ... your logged in username is the same as the SSH valid username then you ... Your FC5 SSH server has users john, mary, steve, and paul. ...
      (Fedora)