Page 1 of 1

SSH to Cisco FTD

Posted: Mon May 01, 2023 12:06 pm
by Soter
Hi, I have tried the Live desk, where the support was not sufficient.

So here goes. My set up is based on newest EVE-NG pro 5.17.8. installed on en Esxi 7 server

I use securecrt for ssh into the lab, on a bridged network. works with routers, sw, and ASA's, but not FTD's I have imported the cisco KVM image according to Cookbook, used both FTD v.7.0.5, and 7.2.1-40. FTD Management interface is configured on same network as the bridged one. FTD are added to an FMC outside eve, so the bridged network works. Also other SSH over the bridged network works to SV, routers, and ASA's

But the FTD refuces the connection. by default the FTD has enabled SSH on the management interface.

VNC, works, but when config the FTD node to use "telnet" in eve, there is no connection. Telent uses securecrt and also works on other nodes in eve.

Any ideas?

Re: SSH to Cisco FTD

Posted: Mon May 01, 2023 6:33 pm
by Soter
So to answer my own question, there are a key-exchange bug in these FTD's

I had to use FTD 7.3.1-19 for it to work, and change keys in securecrt... but it only is displayed if you use quick-connection as showed. After this, you can changes key-exchange for the session, in session option
Untitled picture.png

Re: SSH to Cisco FTD

Posted: Fri May 05, 2023 8:20 pm
by Uldis (UD)
Did you check your Secure CRT session to enable necessary algorithms ?!?!

Re: SSH to Cisco FTD

Posted: Sun May 07, 2023 5:25 pm
by Soter
Uldis (UD) wrote:
Fri May 05, 2023 8:20 pm
Did you check your Secure CRT session to enable necessary algorithms ?!?!
well I looked into it, and enabled all available keys in securecrt, but it still wouldn't connect. Besidens other FTD's at this version7.0.5, never had any problems, but they were not virtuel. I had to use the newest FTD virtuel image, ver. 7.3.1-19 before I was able to ssh to it.

Re: SSH to Cisco FTD

Posted: Mon May 08, 2023 7:28 am
by Uldis (UD)
Virtual FTD 7.3.X SSH works, I tested myself
7.0.5 NO

Re: SSH to Cisco FTD

Posted: Mon May 08, 2023 8:59 am
by Soter
Uldis (UD) wrote:
Mon May 08, 2023 7:28 am
Virtual FTD 7.3.X SSH works, I tested myself
7.0.5 NO
you mean works? and yes, this is excatly what I'm telling in my post ;-)

Re: SSH to Cisco FTD

Posted: Fri May 19, 2023 12:10 pm
by alonkaka
Experience the latest FTD virtual image, version 7.3.1-19, and gain seamless SSH access.