Solved

SSH PIX

Posted on 2009-07-07
4
394 Views
Last Modified: 2013-11-16
I am trying to configure one pix version 6.3 and 7.2 to use putty and SSH login to the pix from inside the LAN from only 3 LAN ip addresses all other IP's would not be allowed login. if needed i will can provide more info. looking for the correct commands.
0
Comment
Question by:jeffsteffy
  • 3
4 Comments
 
LVL 9

Expert Comment

by:jfer0x01
Comment Utility
Hi,
make a  acl 101 deny tcp 0.0.0.0 255.255.255.255 your.sshd.ser.ver 0.0.0.0  eq 22

and a

acl 101 permit tcp 10.10.1.1-3 255.255.255.0 your.sshd.ser.ver 0.0.0.0 eq 22

where the 10.10.1.1-3 is the range of ips you want to allow, if not a range, enumerate them one by one

Jfer
0
 
LVL 2

Author Comment

by:jeffsteffy
Comment Utility
What does this part do? your.sshd.ser.ver 0.0.0.0
0
 
LVL 9

Accepted Solution

by:
jfer0x01 earned 500 total points
Comment Utility
the ip of the ssh device you are going into, and the subnet
0
 
LVL 9

Expert Comment

by:jfer0x01
Comment Utility
actually,

just try access-list 101 permit tcp 10.10.1.1-3 255.255.255.0 your.sshd.ser.ver 0.0.0.255 eq 22

the last set of numbers before the 22 is the wildcard bit for the subnet

Jfer
0

Featured Post

6 Surprising Benefits of Threat Intelligence

All sorts of threat intelligence is available on the web. Intelligence you can learn from, and use to anticipate and prepare for future attacks.

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Cisco ASA 5506 4 39
PAT's on the outside interface of a ASA 5510 3 32
ASA 5510 PAT question 1 20
Cisco ASA NAT question. 9 22
Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
This article offers some helpful and general tips for safe browsing and online shopping. It offers simple and manageable procedures that help to ensure the safety of one's personal information and the security of any devices.
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

772 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now