SSH access PIX 501

I am trying to gain access to the pix 501 ssh port and I am
getting the following message:

login as: john
Sent username "john"
john@192.168.5.1's password:
Access denied
john@192.168.5.1's password:
Access denied
john@192.168.5.1's password:


john username has privileged level 15 account and
is accessing the ssh from 192.168.5.2 and password
is also inputted correctly.

cli entries

access from 192.168.5.2.
ssh 192.168.5.2 255.255.255.255 inside
ssh timeout 60

There is not problem accessing the PDM and Telnet from
192.168.5.2
Any suggestions.

Thanks,



snoozeitAsked:
Who is Participating?
 
harbor235Commented:


Has SSH ever worked? you may need to generate the ssh RSA keys, try this;

From console access !!!
First remove any old ssh keys:

crypto key zeroize rsa

Hostname <insert_hostname>
Domain-name domainname.cisco.com
Ca gen rsa key 1024
Ssh 0.0.0.0 0.0.0.0 outside (or restrict to particular addresses)
Ssh timeout 60
Passwd cisco (or whatever)
Wr mem

harbor235 ;}
0
 
harbor235Commented:


Perhaps there has been a config change? Does this device use TACACS or RADIUS?
Maybe the TAC/RADIUS server is down.

Password recovery:

http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_password_recovery09186a008009478b.shtml

harbor235 ;}
0
 
snoozeitAuthor Commented:
There is no Radius or tac server. I can console in so I don't need to recover passwords. Any
Commands I may be missing.

Thanks,
0
Ultimate Tool Kit for Technology Solution Provider

Broken down into practical pointers and step-by-step instructions, the IT Service Excellence Tool Kit delivers expert advice for technology solution providers. Get your free copy now.

 
snoozeitAuthor Commented:
I am using pix os 6.3.5 and it does not recognize the command crypto key zeroize rsa.
Is there a way I can enable the auto complete tab feature or is it non existent in the os.

Thanks,
0
 
snoozeitAuthor Commented:
I figured it out using debugs. It uses pix as a username instead  of the username and password  inputted in the cli, pix os is weird.
The command for pix os 635 to remove old keys is ca zeroize rsa.
Still looking for the auto complete tab feature turn on button (ie command).

Thanks,

0
 
piwowarcCommented:
PIX differs from normal IOS. At first I tried Tab a lot too. Try ? after part of the command like show ? etd.

You don't have radius or tacacs. Did you w set authenticaion to be local?

pix(config)#aaa authentication ssh console LOCAL

Cheers


0
 
snoozeitAuthor Commented:
thanks
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.