SSH Server behind PIX 515

SSH Server behind PIX 515

NewsGroups | Search | Tools
 comp.dcom.sys.cisco  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
SSH Server behind PIX 515 yanks2112 07-25-2008
Posted by Artie Lange on July 25, 2008, 12:49 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
yanks2112 wrote:
>> yanks2112 wrote:
>>> Hi Artie
>>> Thanks for the quick reply.
>>> Yes we can get to it from behind the firewall
>>> We dont have any inspection rules for ssh (this works for other ssh
>>> servers behind the firewall)
>>> The OS is Suse linux (not sure what version, I'll chekc that out) the
>> So you have other SSH servers that work behind the firewall? If so, I
>> would start by double checking to make sure that the NAT translation and
>> ACL's are constructed the same. If they are, I would suggest debugging
>> the errors from the SUSE box, tail -f /var/log/messages and you should
>> see some output of the error from there.
>
> Thanks. I checked the NAT and ACLs and they look ok. The ssh logs
> show:
>
> 11:39:24 10.10.10.10. sshd[6904]: Did not receive identification
> string from ::ffff:192.168.100.100
>
> Thanks again for your help

Well if you are getting that on the SUSE box, you are connecting fine.
From googling the error, that has something to do with authentication.

Are you using the same version of SSH across your network including your
clients?

Posted by yanks2112 on July 30, 2008, 10:32 am
If you were  Registered and logged in, you could reply and use other advanced thread options
> yanks2112 wrote:
> >> yanks2112 wrote:
> >>> Hi Artie
> >>> Thanks for the quick reply.
> >>> Yes we can get to it from behind the firewall
> >>> We dont have any inspection rules for ssh (this works for other ssh
> >>> servers behind the firewall)
> >>> The OS is Suse linux (not sure what version, I'll chekc that out) the
> >> So you have other SSH servers that work behind the firewall? If so, I
> >> would start by double checking to make sure that the NAT translation a=
nd
> >> ACL's are constructed the same. If they are, I would suggest debugging
> >> the errors from the SUSE box, tail -f /var/log/messages and you should
> >> see some output of the error from there.
>
> > Thanks. I checked the NAT and ACLs and they look ok. The ssh logs
> > show:
>
> > 11:39:24 10.10.10.10. sshd[6904]: Did not receive identification
> > string from ::ffff:192.168.100.100
>
> > Thanks again for your help
>
> Well if you are getting that on the SUSE box, you are connecting fine.
> =A0From googling the error, that has something to do with authentication.
>
> Are you using the same version of SSH across your network including your
> clients?- Hide quoted text -
>
> - Show quoted text -

Hi Artie

It turned out to be a Websense server that was in the middle. The
server was exluded from filtering, yet Websesne still blocked it.
Rebooting the websense server fixed it. Thanks a lot for your help

Similar ThreadsPosted
Importing a certiticate server on CSS 11503 with SSL module from RSA KEON server April 21, 2006, 12:54 pm
URGENT! PIX 501, Timeout between outside server and inside server October 12, 2005, 7:38 am
Cisco DHCP server and Microsoft DNS server September 11, 2007, 4:02 am
WWW server in DMZ, SQL Server Inside...newbie help needed January 17, 2008, 8:11 pm
server to server communications behind CSS 11501 January 6, 2006, 2:10 pm
ASA5510 dmz mail server forwarding to lan mail server April 25, 2007, 1:07 pm
Setting up a router with 29 Global IPs, BUT can't ping router internal interface from server or server interface from router December 11, 2005, 10:37 am
837. Unable to see internal web server from internal server. March 5, 2006, 8:52 am
SSH server on PIX. June 23, 2005, 2:10 pm
pix 501 as vpn server September 30, 2005, 11:23 am

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map