Solved

Cisco ASA Connect to CentOS 6.6 Server Via SSH From Outside to DMZ

Posted on 2014-12-21
1
191 Views
Last Modified: 2014-12-22
Hello Experts:

I have one server in a DMZ60 network.  I need to make this server available to some contractors outside our network.   Therefore, I need to open ssh, http, and https from the DMZ60 to the OUTSIDE interface.  

I have been trying to get SSH working, but I still cannot get it.

This is what I have so far:


NAT:

ASA# sh nat | incl 167.192.X.X   (External address)
98 (DMZ60) to (outside) source static web-192.168.X.X-dmz -websites-167.192.X.X-OUT
ASA#
ASA#
ASA# sh nat | incl 192.168.X.X  (DMZ address)
98 (DMZ60) to (outside) source static web-192.168.X.X-dmz -websites-167.192.X.X-OUT


ASA# sh run | incl 167.192.X.X   (External address)
object network websites-167.192.X.X-OUT
 host 167.192.X.X
access-list in1 extended permit tcp any object websites-167.192.X.X-OUT eq ssh
access-list DMZ60-in extended permit tcp any object websites-167.192.X.X-OUT eq ssh
 nat (DMZ60,outside) static websites-167.192.X.X-OUT
ASA#


ASA# sh run | incl 192.168.X.X  (DMZ60 address)
object network web-192.168.X.X-dmz
 host 192.168.X.X
access-list in1 extended permit tcp any object web-192.168.X.X-dmz eq ssh
object network web-192.168.X.X-dmz
ASA#


DMZ60-in and in1 are two ACL groups that have objects inside them.  I believe that the one DMZ60-in is the one for servers inside the DMZ and the in1 is for servers in the inside interface.

I think I do not need in1, but it is just there since I have no idea how to make this work.

The attache word document shows that output of Packet Tracer that I do not know if I am using properly.  

cisco-asa-packet-tracer.docx
0
Comment
Question by:willie0-360
1 Comment
 

Accepted Solution

by:
willie0-360 earned 0 total points
ID: 40513874
All of the above configuration(s) is correct.  The problem was that I was using the wrong gateway on the Linux server.  Once I corrected that, everything started working.

Thanks.
Willie
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

When replacing some switches recently I started playing with the idea of having admins authenticate with their domain accounts instead of having local users on all switches all over the place. Since I allready had an w2k8R2 NPS running for my acc…
Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

777 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question