Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

config sshd to different port in pix firewall

Posted on 2007-03-29
8
309 Views
Last Modified: 2010-04-17
I need to allow ssh and sshd through a pix firewall 515e for a internal ip mapped to an external ip

Now on sshd when I put it into the access list. I need it to go through port 70 instead of 22...how do I put into access list this way..not to good at pix firewalls

for example

access-list 101 permit tcp host 29.237.72.244host 64.177.198.293 eq sshd

how can I change the sshd to show 70 instead of the 22
0
Comment
Question by:heydorft
  • 4
  • 3
8 Comments
 
LVL 2

Expert Comment

by:learn2earn
ID: 18817627
you might want to try
access-list 101 permit tcp 29.237.72.244 255.255.255.255 64.177.198.293 255.255.255.255 eq 70 sshd
pix(config)#ip access-group 101 in interface outside
0
 
LVL 29

Expert Comment

by:Alan Huseyin Kayahan
ID: 18818014
        Command above shouldn't work. because sshd word refers the port 22. so it will be as following
access-list 101 permit tcp 29.237.72.244 255.255.255.255 64.177.198.293 255.255.255.255 eq 70 22
         which is inacceptable in my opinion.
          you should simply allow the port 70 to your internal host and set the ssh oprt as 70 in both your ssh server and client

access-list 101 permit tcp 29.237.72.244 255.255.255.255 64.177.198.293 255.255.255.255 eq 70
access-group 101 in interface outside
         If you are not used to port forwardings in PIX, things wont work so easy. If you postyour running config and tell exactly which client to where, we would suggest more accurate.
0
 

Author Comment

by:heydorft
ID: 18820676
ok did

access-list 101 permit tcp 29.237.72.244 255.255.255.255 64.177.198.293 255.255.255.255 eq 70

and it came up

access-list 101 permit tcp 29.237.72.244 255.255.255.255 64.177.198.293 255.255.255.255 eq golpher

what the ?????
0
Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

 

Author Comment

by:heydorft
ID: 18820689
gopher  not golpher
0
 

Author Comment

by:heydorft
ID: 18820705
How do I take this single line off the access list


http://en.wikipedia.org/wiki/Gopher_Protocol

0
 
LVL 29

Expert Comment

by:Alan Huseyin Kayahan
ID: 18822325
no access-list 101 permit tcp 29.237.72.244 255.255.255.255 64.177.198.293 255.255.255.255 eq golpher

will take it off
       
          If you are not used to port forwardings in PIX, things wont work so easy. If you postyour running config and tell exactly which client to where, we would suggest more accurate.
0
 

Accepted Solution

by:
heydorft earned 0 total points
ID: 18867214
I am not comfortable posted config
0
 
LVL 29

Expert Comment

by:Alan Huseyin Kayahan
ID: 18868948
         Install SecureCRT and enter CLI via SecureCRT. Then you will be able to copy paste all config.
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
ACL deny / Permit 10 22
Cisco 5508 WLC software upgrade 2 72
Deny permission ACL 16 26
CISCO ASA 5505 double Wan 8 16
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Concerto Cloud Services, a provider of fully managed private, public and hybrid cloud solutions, announced today it was named to the 20 Coolest Cloud Infrastructure Vendors Of The 2017 Cloud  (http://www.concertocloud.com/about/in-the-news/2017/02/0…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

829 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question