Networks Training

  • About
  • My Books
  • IP Tools
  • HOME
  • Cisco Networking
    • Cisco General
    • Cisco IOS
    • Cisco VPN
    • Cisco Wireless
  • Cisco ASA
    • Cisco ASA General
    • Cisco ASA Firewall Configuration
  • Certifications Training
    • CCNA Training
    • Cisco Certifications
    • I.T Training
  • General
    • Tech News
    • General Networking
    • IP Telephony
    • Network Security
    • Product Reviews
    • Software
  • Cisco Routers
  • Cisco Switches
You are here: Home / Cisco ASA Firewall Configuration / Connecting to the ASA Firewall with Telnet and SSH

Connecting to the ASA Firewall with Telnet and SSH

Edited By Harris Andrea

The Cisco ASA firewall appliance provides both graphical and command line methods for connecting to the device for management. With the graphical method, the administrator can use a web browser (https) for managing the firewall. This method necessitates that the ASDM software (Adaptive Security Device Manager) is installed on the flash memory of the firewall.

The command line methods use either Telnet or SSH to connect to the device. Since the Telnet protocol sends everything in clear text, it is recommended to use SSH where all communication with the firewall is encrypted.

So let’s take a look at the commands needed on the ASA to allow SSH connections:

1) Connect to the ASA via console and get in configuration mode.
2) You have to configure a hostname and domain name
firewall(config)# hostname ASA-FIREWALL
ASA-FIREWALL (config)# domain-name test.com

3) You will need to generate an RSA Key Pair since this is needed by the SSH protocol which uses SSL. This can be achieved with the following command:
ASA-FIREWALL(config)# crypto key generate rsa modulus 2048

MORE READING:  Configure Cisco ASA 5505 to allow Remote Desktop access from Internet

After issuing this command and hitting enter, you will see something like the following and you will need to wait:

For >= 2048, key generation could take up to several minutes. Please wait……….

4) Next, you will need to save your newly created Keys to flash by typing the following command:
ASA-FIREWALL # write mem

5) Now, we can tell the ASA exactly which hosts or networks can access the device via SSH. We also need to specify which interface we are allowing access to.

For example, if you have a management PC with internal IP address of 10.0.0.1 and just wanted to allow this PC to access the ASA on the inside interface, you would issue the following command:

ASA-FIREWALL(config) #ssh 10.0.0.1 255.255.255.255 inside

6) Enable authentication for the SSH. You can configure LOCAL authentication by configuring a local username/password on the device:
ASA-FIREWALL(config) # aaa authentication ssh console LOCAL
ASA-FIREWALL(config) # username admin password xxxxxxxx encrypted

MORE READING:  Cisco ASA Firewall Management Interface Configuration (with Example)

7) Download a free SSH client (e.g putty) for connecting to the device.

Spread the love

Related Posts

  • Prevent Spoofing Attacks on Cisco ASA using RPF
  • Configuring Connection Limits on Cisco ASA Firewalls – Protect from DoS
  • Configuring AAA Authentication-Authorization-Accounting on Cisco ASA Firewall (TACACS+, RADIUS)
  • Cisco ASA Firewall Management Interface Configuration (with Example)
  • How to Configure Access Control Lists on a Cisco ASA 5500/5500-X Firewall (with Examples)

Filed Under: Cisco ASA Firewall Configuration

Download Free Cisco Commands Cheat Sheets

Enter your Email below to Download our Free Cisco Commands Cheat Sheets for Routers, Switches and ASA Firewalls.

By subscribing to our email list you will be receiving technical tutorials and industry news from time-to-time. You can unsubscribe at any time.

About Harris Andrea

Harris Andrea is an Engineer with more than two decades of professional experience in the fields of TCP/IP Networks, Information Security and I.T. Over the years he has acquired several professional certifications such as CCNA, CCNP, CEH, ECSA etc.

He is a self-published author of two books ("Cisco ASA Firewall Fundamentals" and "Cisco VPN Configuration Guide") which are available at Amazon and on this website as well.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Search this site

About Networks Training

We Provide Technical Tutorials and Configuration Examples about TCP/IP Networks with focus on Cisco Products and Technologies. This blog entails my own thoughts and ideas, which may not represent the thoughts of Cisco Systems Inc. This blog is NOT affiliated or endorsed by Cisco Systems Inc. All product names, logos and artwork are copyrights/trademarks of their respective owners.

Amazon Disclosure

As an Amazon Associate I earn from qualifying purchases.
Amazon and the Amazon logo are trademarks of Amazon.com, Inc. or its affiliates.

Search

BLOGROLL

Tech21Century
Firewall.cx

Copyright © 2026 | Privacy Policy | Terms and Conditions | Contact | Amazon Disclaimer | Delivery Policy