Firewall Wizards mailing list archives

Re: PIX denying SSH Access - until I run PDM?


From: Tichomir Kotek <tichomir.kotek () lynx sk>
Date: Tue, 30 Aug 2005 12:48:38 +0200


Paul Pershing wrote:
Hi, 

Hi,

The odd part is that I discovered through trial and error that if
access the PIX via PDM after the failed SSH attempt - even if the PDM
connection is not completed - I can then attach via SSH.

I observerd the same weird behavior. Somehow I figured out that
before connecting with ssh one must generate certificate on pix.
("show ca mypubkey rsa " to verify if you have any)

BUT using pdm pix auto-generates self-signed certificate automagically
(I think even connecting to https generates one) and after that ssh
is working fine.
before using ssh do not forget to "ca generate rsa key 1024"
"ca save all"  to save those keys to permanent storage.

This is such a bizarre problem that I've been reluctant to post it;
but I've encountered it so many times now that my curiousity has
gotten the better of me!

hope that helps

tk



_______________________________________________
firewall-wizards mailing list
firewall-wizards () honor icsalabs com
http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


Current thread: