SSH configuration on PIX Firewall
Encrypted remote sessions to PIX Firewalls with SSH.
Secure SHell (SSH) provides encrypted terminal sessions, along with a lot of other neat features.
www.cisco.com has configuration examples for practically everything under the planet, including the start for this one.
To configure a Cisco PIX Firewall to support SSH, enter the following commands:
ca gen rsa key 1024
ssh 172.18.124.114 255.255.255.255 inside
ssh timeout 60
ca save all
This configuration allows ssh from the 172.18.124.114 address on the inside interface. Change this address to something that makes sense for your network. If desired, you can use this line to allow access from any address on the outside interface:
ssh 0.0.0.0 0.0.0.0 outside
The “ca save all” is important. This command saves the rsa keys.
How do I connect? First, get an SSH client. PuttY isa popular one for Microsoft Windows, and SSH clients are packaged with most Linux distributions.
For Linux, the command line (for a pix at IP address 188.8.131.52) is:
ssh -1 -c des firstname.lastname@example.org
For Solaris (from Cisco’s website):
./ssh -c 3des -1 pix -v
Follow the reactions below and share your own thoughts.