SSH and PIX 515

Posted on 2003-03-18
Medium Priority
Last Modified: 2013-11-16
I am trying to figure out how to give access to outside vendors to inside servers through SSH. I have been able to coonct to the PIX using SSH but how do I configure the PIX to allow outside clients to get to inside resouses using SSH?
Question by:trath
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2

Expert Comment

ID: 8161785
If you're trying to give outside folks access to your servers and such inside the firewall, you will need to add a static translation to your NAT table, giving those internal devices external IPs.  Once the internal device is reachable by the outside world, you'll then set your rules.  You'll want to allow SSH (preferably only from specific IPs) and disallow all else, to maintain the highest level of security possible.


Shawn Preston, CISSP
Founder, SecureThinking

"Where Information Security Evolves"

Author Comment

ID: 8168345
I am looking for the exact commands on how to do a static traslation on a PIX. I appreciate yuor help
LVL 79

Expert Comment

ID: 8175251
Assuming that you have a pool of IP addresses to choose from, make sure that the static global addresses are removed from the nat pool. We'd have to see your complete config to make many more detailed recommendations:

PIX#config t
PIX(config)# static (inside,outside)<global ip> <local ip> netmask
LVL 79

Accepted Solution

lrmoore earned 750 total points
ID: 8187905
You also have to allow ssh access from the outside interface

PIX(config)#ssh outside
or limit to specific IP addresses
PIX(config)#ssh outside

Featured Post

On Demand Webinar: Networking for the Cloud Era

Ready to improve network connectivity? Watch this webinar to learn how SD-WANs and a one-click instant connect tool can boost provisions, deployment, and management of your cloud connection.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses

764 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question