Re: Fail to SSH Cisco PIX 6.3 device - secondary standby unit

From: Ryan West <rwest_at_zyedge.com>
Date: Sun, 11 Apr 2010 12:07:59 +0000

Ca generate rsa gen mod 1024
Ca save all

Perform those commands on the secondary unit.

The PIX OS does not sync RSA keys, that wasn't implemented until 7.x
and above

Sent from handheld.

On Apr 11, 2010, at 7:31 AM, "C Chan" <cch.ccie_at_gmail.com> wrote:

> Hi Expert,
>
> Have you encountered the following strange situation? PIX-1 and
> PIX-2 are
> running in failover mode while PIX-1 is primary-active while PIX-2 is
> secondary standby. I am able to SSH (ver 1) PIX-1 remotely from
> management
> station while I cannot access PIX-2 via *SSH*.
> However, when I perform console access. Both devices are working
> fine. And,
> ping traffic is ok towards two firewalls from management station.
>
> I remembered that there is some trick to manage (or regenerate) the
> SSH key
> of secondary-standby PIX 6.x if you perform reboot or do something
> in that
> firewall pairs. However, I cannot recall the exact way to mitigate
> that. Is
> there any suggestion?
>
> cch
>
>
> Blogs and organic groups at http://www.ccie.net
>
> _______________________________________________________________________
 

> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html

Blogs and organic groups at http://www.ccie.net
Received on Sun Apr 11 2010 - 12:07:59 ART

This archive was generated by hypermail 2.2.0 : Sat May 01 2010 - 09:49:57 ART