data:image/s3,"s3://crabby-images/b4cb4/b4cb4abb915cf367433be76b913923d3f06ccc06" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Configuration Manual Download Page 525"
23-3
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 23 Configuring Management Access
Allowing SSH Access
Configuring SSH Access
To configure SSH access to the FWSM, perform the following steps:
Step 1
To generate an RSA key pair, which is required for SSH, see the
“Generating Key Pairs” section on
page 12-4
.
Step 2
To identify the IP addresses from which the FWSM accepts connections, enter the following command
for each address or subnet:
hostname(config)#
ssh
source_IP_address
mask
source_interface
The FWSM accepts SSH connections from all interfaces, including the one with the lowest security
level.
Step 3
(Optional) To set the duration for how long an SSH session can be idle before the FWSM disconnects
the session, enter the following command:
hostname(config)#
ssh timeout
minutes
Set the timeout from 1 to 60 minutes. The default is 5 minutes. The default duration is too short in most
cases and should be increased until all pre-production testing and troubleshooting has been completed.
Step 4
(Optional) To restrict the version of SSH accepted by the FWSM, enter the following command. By
default, the FWSM accepts both versions.
hostname(config)#
ssh version
{
1
|
2
)
For example, to generate RSA keys and let a host on the inside interface with an address of 192.168.1.2
access the FWSM, enter the following command:
hostname(config)#
crypto key generate rsa modulus
1024
hostname(config)#
write mem
hostname(config)#
ssh 192.168.1.2 255.255.255.255 inside
hostname(config)#
ssh 192.168.1.2 255.255.255.255 inside
hostname(config)#
ssh timeout 30
To allow all users on the 192.168.3.0 network to access the FWSM on the inside interface, the following
command:
hostname(config)#
ssh 192.168.3.0 255.255.255.0 inside
Using an SSH Client
To gain access to the FWSM console using SSH, at the SSH client enter the username
pix
and enter the
login password set by the
password
command (see the
“Changing the Login Password” section on
page 7-1
). By default, the password is “cisco.”
When starting an SSH session, a dot (.) displays on the FWSM console before the SSH user
authentication prompt appears, as follows:
hostname(config)# .
Summary of Contents for 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Page 35: ...P A R T 1 Getting Started and General Information ...
Page 36: ......
Page 297: ...P A R T 2 Configuring the Security Policy ...
Page 298: ......
Page 521: ...P A R T 3 System Administration ...
Page 522: ......
Page 613: ...P A R T 4 Reference ...
Page 614: ......