| 
								 | 
							
								
  | 
							
								
  | 
						
								
  | 
						
| 
			
			
			
			 It'll be legen-waitforit 
			
			
		
			
				
			
			
			Join Date: Jan 2002 
				Location: Calgary, Canada 
				
				
					Posts: 7,006
				 
                
				
				
				
				 | 
	
	
	
		
		
		
		
		
		 
			SO what was the outcome? Did you have a backup of the configuration, and a copy of the changes you made last? 
		
	
		
	
			
				A couple things in your statement confuse me; you said refusing LAN connections then you said you SSH'd into the Public IP? Can you ssh to the private IP from the LAN? As well why would you only use a password on the public interface? (I know this doesn't help but I had to ask). If you had HTTPs enabled on the inside interface can you get to it that way? As well, as stated, did you try the default username pass? What was the aaa method set to in the past? Good luck, let us know <-- CCSP working on CCIE now 
				__________________ 
		
		
		
		
		
	
	Bob James 06 Cayman S - Money Penny 18 Macan GTS Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo  | 
||
| 		
			
			 | 
	
	
  | 
| 
			
			
			
			 Registered 
			
			
		
			
			
			Join Date: Jul 2003 
				Location: Glorious Pac NW 
				
				
					Posts: 4,184
				 
                
				
				
				
				 | 
	
	
	
		
		
		
		
		
		 Quote: 
	
 Just need a pin insert/extraction tool (although you can get by without one if you don't mess up assembling it)... 
				__________________ 
		
		
		
		
		
	
	'77 S with '78 930 power and a few other things.  | 
||
| 		
			
			 | 
	
	
  | 
| 
			
			
			
			 Registered 
			
			
		
			
				
			
			
								
		
	 | 
	
	
	
		
		
		
		
		
		 Quote: 
	
 This would not affect any outbound traffic like web browsing and so forth as that comes from the inside interface to the outside. The inside interface has a higher security level than the outside so traffic (unless otherwise denied by an inbound ACL) is by default permitted in that direction. SSH access to the outside - ideally - should not be allowed from the public internet (also I believe that the old 6.x code may not support more than SSHv1 which is not bad but not great. In less than ideal circumstances SSH access from the outside should be protected by more than just the enable password. At the very least a local user should be configured. Better would be a tacacs server but we're talking less than ideal situations here. I'm not criticizing so please don't take it that way, I know that ultimately it comes down to money. I have worked for companies that you would not believe were unwilling to spend a dime on the network yet had expectations that were sky high. Unreal - seriously. If management won't spend the money then you end up with less than ideal circumstances and it is so easy to get there. Feel free to pick my brain on the PIX configuration or routing or switching or wireless for that matter. A few years back I tried to get the CCSP, I passed all the tests except the IDS test. This was when the 4 code was still in use and being tested on (if memory serves). After 3 attempts (at the time something like $125 a pop) at that one test I gave up. I will never take another CCxP level exam again. I will only take CCIE level exams which keep my current certs online and hopefully advance my career potential. I'm hoping to take the R&S lab around april when I will be going to one of those 5 day boot camps (for free). 
				__________________ 
		
		
		
		
		
		
			-The Mikester I heart Boobies Last edited by mikester; 01-21-2009 at 09:11 PM..  | 
||
| 		
			
			 | 
	
	
  | 
| 
			
			
			
			 Registered 
			
			
		
			
				
			
			
								
		
	 | 
	
	
	
		
		
		
		
		
		 
			no update?
		 
		
	
		
	
			
			
				
					
				__________________ 
		
		
		
		
		
	
	-The Mikester I heart Boobies  | 
||
| 		
			
			 | 
	
	
  |