<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSH issues after upgrading to ASYNC 8.0 M670 in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/ssh-issues-after-upgrading-to-async-8-0-m670/m-p/2228530#M3399</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly open a TAC case to get futher assistance. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Puja&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 08 Jun 2013 17:56:20 GMT</pubDate>
    <dc:creator>Puja Mahapatra</dc:creator>
    <dc:date>2013-06-08T17:56:20Z</dc:date>
    <item>
      <title>SSH issues after upgrading to ASYNC 8.0 M670</title>
      <link>https://community.cisco.com/t5/web-security/ssh-issues-after-upgrading-to-async-8-0-m670/m-p/2228529#M3398</link>
      <description>&lt;P&gt;I can no longer connect to 2 WSA from the M670 appliance after upgrading to 8.0.&amp;nbsp; I get prompted for credentials then it just hangs when I input my credentials.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Before running this latest AsyncOS update release, I checked the configuration of the log subscription files to verify the SSH1 setting and it was not configured.&amp;nbsp; Apparently, there were other configurations that use SSH1 that I was not aware of so it was not checked and changed.&amp;nbsp; Just on a side note, I tried to run the command 'logconfig &amp;gt; hostkeyconfig' (via Putty) on the M670 appliance but the command would run and it would immediately exit out of Putty so I was not able to view or change the SSH settings.&lt;/P&gt;</description>
      <pubDate>Fri, 07 Jun 2013 00:27:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/ssh-issues-after-upgrading-to-async-8-0-m670/m-p/2228529#M3398</guid>
      <dc:creator>HT Managed_Services</dc:creator>
      <dc:date>2013-06-07T00:27:54Z</dc:date>
    </item>
    <item>
      <title>SSH issues after upgrading to ASYNC 8.0 M670</title>
      <link>https://community.cisco.com/t5/web-security/ssh-issues-after-upgrading-to-async-8-0-m670/m-p/2228530#M3399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly open a TAC case to get futher assistance. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Puja&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 08 Jun 2013 17:56:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/ssh-issues-after-upgrading-to-async-8-0-m670/m-p/2228530#M3399</guid>
      <dc:creator>Puja Mahapatra</dc:creator>
      <dc:date>2013-06-08T17:56:20Z</dc:date>
    </item>
    <item>
      <title>SSH issues after upgrading to ASYNC 8.0 M670</title>
      <link>https://community.cisco.com/t5/web-security/ssh-issues-after-upgrading-to-async-8-0-m670/m-p/2228531#M3400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello &lt;/P&gt;&lt;P&gt; We have recently found a defect tjay lead to this behavior.&amp;nbsp; Degeft ID &lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCuh38818" target="_blank"&gt;CSCuh38818&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem only happens if the SMA appliance has a SSHv1 key in its configuration before upgrading to the AsyncOS 8.0 for management.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Workaround:&lt;/P&gt;&lt;P&gt;On the Cisco Security Management Appliance (SMA) running 8.0 version:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Save the configuration file under GUI &amp;gt; System Administration &amp;gt; Configure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Ensure that the passwords are un-masked so that we can re-upload the configuration file&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) Open the configuration file in a text editor, search for "hostkey" and delete the host key/s which look like below&lt;/P&gt;&lt;P&gt;&lt;HOSTKEY&gt;&lt;IP_ADDRESS&gt; 2048 xx .....&lt;/IP_ADDRESS&gt;&lt;/HOSTKEY&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) Upload the new configuration on SMA and commit changes&lt;/P&gt;&lt;P&gt;5) Once done, the WSA appliance should be able to authenticate&amp;nbsp; any WSA and ESA appliance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Alvaro&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 10 Jun 2013 15:28:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/ssh-issues-after-upgrading-to-async-8-0-m670/m-p/2228531#M3400</guid>
      <dc:creator>Alvaro J Gordon-Escobar</dc:creator>
      <dc:date>2013-06-10T15:28:55Z</dc:date>
    </item>
    <item>
      <title>SSH issues after upgrading to ASYNC 8.0 M670</title>
      <link>https://community.cisco.com/t5/web-security/ssh-issues-after-upgrading-to-async-8-0-m670/m-p/2228532#M3401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Alvaro,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your response, your recommendation worked like a charm.&amp;nbsp; Following the upload of the configuration without the "&lt;HOSTKEY&gt;&lt;IP_ADDRESS&gt; 2048 xx ....." entries and a reboot, connectivity was restored. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/IP_ADDRESS&gt;&lt;/HOSTKEY&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Jun 2013 23:43:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/ssh-issues-after-upgrading-to-async-8-0-m670/m-p/2228532#M3401</guid>
      <dc:creator>HT Managed_Services</dc:creator>
      <dc:date>2013-06-13T23:43:28Z</dc:date>
    </item>
  </channel>
</rss>

