
9-22
Cisco PIX Firewall and VPN Configuration Guide
78-15033-01
Chapter 9 Accessing and Monitoring PIX Firewall
Using SSH for Remote System Management
Overview
SSH is an application running on top of a reliable transport layer, such as TCP/IP that provides strong
authentication and encryption capabilities. The PIX
Firewall supports the SSH remote shell functionality
provided in SSH Version 1. SSH Version 1 also works with Cisco IOS software devices. Up to five SSH
clients are allowed simultaneous access to the PIX
Firewall console.
Note Before trying to use SSH, generate an RSA key-pair for the PIX Firewall. To use SSH, your PIX Firewall
requires a DES or 3DES activation key.
Another method of remotely configuring a PIX Firewall involves using a Telnet connection to the
firewall to start a shell session and then entering configuration mode. This connection method can only
provide as much security as Telnet provides, which is only provided as lower-layer encryption (for
example, IPSec) and application security (username/password authentication at the remote host).
Note The PIX Firewall SSH implementation provides a secure remote shell session without IPSec, and only
functions as a server, which means that the PIX Firewall cannot initiate SSH connections.
Obtaining an SSH Client
Note SSH v1.x and v2 are entirely different protocols and are not compatible. Make sure that you download
a client that supports SSH v1.x.
You can download an SSH v1.x client from a number of different websites, including the following:
• Windows 3.1, Windows CE, Windows 95, and Windows NT 4.0—download the free Tera Term Pro
SSH v1.x client from the following website:
http://hp.vector.co.jp/authors/VA002416/teraterm.html
The TTSSH security enhancement for Tera Term Pro is available at the following website:
http://www.zip.com.au/~roca/ttssh.html
Note To use Tera Term Pro with SSH, download TTSSH. TTSSH provides a Zip file that you copy
to your system. Extract the zipped files into the same folder that you installed Tera Term Pro.
• Linux, Solaris, OpenBSD, AIX, IRIX, HP/UX, FreeBSD, and NetBSD—download the SSH v1.x
client from the following website:
http://www.openssh.com
• Macintosh—(except for Macintosh OSX, which includes an SSH client) download the Nifty
Telnet
1.1 SSH client at the following website:
http://www.lysator.liu.se/~jonasw/freeware/niftyssh/
Commentaires sur ces manuels