<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>安全讨论区中的主题 Re: FPR2140   ASA  SSH failonfiged</title>
    <link>https://community.cisco.com/t5/%E5%AE%89%E5%85%A8%E8%AE%A8%E8%AE%BA%E5%8C%BA/fpr2140-asa-ssh-failonfiged/m-p/5041566#M9062</link>
    <description>&lt;LI-CODE lang="markup"&gt;i try write erase and reload the ASA. and try go re-configure using Console again&lt;/LI-CODE&gt;
&lt;P&gt;This is not the best practice to configure SSH to erase all the config.&lt;/P&gt;
&lt;P&gt;can we have running configuration (removing sensitive information to have look)&lt;/P&gt;
&lt;P&gt;follow below guide - for SSH access :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa917/configuration/general/asa-917-general-config/admin-management.html#ID-2111-0000013a" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa917/configuration/general/asa-917-general-config/admin-management.html#ID-2111-0000013a&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 17 Mar 2024 07:54:13 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2024-03-17T07:54:13Z</dc:date>
    <item>
      <title>FPR2140   ASA  SSH failonfiged</title>
      <link>https://community.cisco.com/t5/%E5%AE%89%E5%85%A8%E8%AE%A8%E8%AE%BA%E5%8C%BA/fpr2140-asa-ssh-failonfiged/m-p/5041420#M9057</link>
      <description>&lt;P&gt;in ASA，i have enter SSH command ：&lt;/P&gt;&lt;P&gt;crypto key generate rsa modulus 1024&lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;&lt;P&gt;ssh 172.32.254.0 255.255.255.0 management&lt;/P&gt;&lt;P&gt;ssh version 2&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;/P&gt;&lt;P&gt;Yesterday when i configed，i can logined from SSH。and write，power down。and today，when i power up the ASA, I can not login SSH。i have re-config the command and reload ASA. but fail again.The fault information as follows:&lt;/P&gt;&lt;P&gt;key exchange faild&lt;/P&gt;&lt;P&gt;No compatible key-exchange method . The server supports these methods : diffie-hellman&lt;/P&gt;&lt;P&gt;The diffie hellman key exchange method is off by default to address the logjam vulnerability . It can be turned on in the sessions options dialog in the&amp;nbsp; Connection / SSH2 category in order to connect to servers that only supportle -diffie-hellman&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2024 16:35:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/%E5%AE%89%E5%85%A8%E8%AE%A8%E8%AE%BA%E5%8C%BA/fpr2140-asa-ssh-failonfiged/m-p/5041420#M9057</guid>
      <dc:creator>renma19th</dc:creator>
      <dc:date>2024-03-16T16:35:54Z</dc:date>
    </item>
    <item>
      <title>回复： FPR2140   ASA  SSH failonfiged</title>
      <link>https://community.cisco.com/t5/%E5%AE%89%E5%85%A8%E8%AE%A8%E8%AE%BA%E5%8C%BA/fpr2140-asa-ssh-failonfiged/m-p/5041423#M9058</link>
      <description>&lt;P&gt;I use CRT v9.1 and Xshell 7,and other PC use CRT ,but problem is still.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2024 16:48:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/%E5%AE%89%E5%85%A8%E8%AE%A8%E8%AE%BA%E5%8C%BA/fpr2140-asa-ssh-failonfiged/m-p/5041423#M9058</guid>
      <dc:creator>renma19th</dc:creator>
      <dc:date>2024-03-16T16:48:59Z</dc:date>
    </item>
    <item>
      <title>Re: FPR2140   ASA  SSH failonfiged</title>
      <link>https://community.cisco.com/t5/%E5%AE%89%E5%85%A8%E8%AE%A8%E8%AE%BA%E5%8C%BA/fpr2140-asa-ssh-failonfiged/m-p/5041428#M9059</link>
      <description>&lt;P&gt;Try to understand the issue you have configured SSH config using Console and you tested and working.&lt;/P&gt;
&lt;P&gt;After Off and n - the configuration not working was SSH&lt;/P&gt;
&lt;P&gt;i need to ask here, you try go configure here using Console again ? did you see the configuration or the configuration lost ?&lt;/P&gt;
&lt;P&gt;or the configuration remain save and you not able to login to ASA ?.&lt;/P&gt;
&lt;P&gt;what ASA&amp;nbsp; version code ?&lt;/P&gt;
&lt;P&gt;what client you using to connect ? (if putty , get latest version of putty and test it ?)&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2024 17:01:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/%E5%AE%89%E5%85%A8%E8%AE%A8%E8%AE%BA%E5%8C%BA/fpr2140-asa-ssh-failonfiged/m-p/5041428#M9059</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-03-16T17:01:34Z</dc:date>
    </item>
    <item>
      <title>Re: FPR2140   ASA  SSH failonfiged</title>
      <link>https://community.cisco.com/t5/%E5%AE%89%E5%85%A8%E8%AE%A8%E8%AE%BA%E5%8C%BA/fpr2140-asa-ssh-failonfiged/m-p/5041479#M9060</link>
      <description>&lt;P&gt;yes, when i can not SSH to ASA, i try write erase and reload the ASA. and try go re-configure using Console again. but&amp;nbsp;the problem still persists .&amp;nbsp;I compared the old-config and new-config,no difference found.&lt;/P&gt;&lt;P&gt;ASA&amp;nbsp;Version 9.8(4)20&lt;/P&gt;&lt;P&gt;MY client is CRT Version9.1&amp;nbsp; and&amp;nbsp;&lt;SPAN&gt;Xshell 7。I request my colleagues try SSH use her PC, she also&amp;nbsp;unable to login use SSH. But we can SSH to fxos and use "connect asa" command to ASA&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2024 20:29:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/%E5%AE%89%E5%85%A8%E8%AE%A8%E8%AE%BA%E5%8C%BA/fpr2140-asa-ssh-failonfiged/m-p/5041479#M9060</guid>
      <dc:creator>renma19th</dc:creator>
      <dc:date>2024-03-16T20:29:29Z</dc:date>
    </item>
    <item>
      <title>Re: FPR2140   ASA  SSH failonfiged</title>
      <link>https://community.cisco.com/t5/%E5%AE%89%E5%85%A8%E8%AE%A8%E8%AE%BA%E5%8C%BA/fpr2140-asa-ssh-failonfiged/m-p/5041481#M9061</link>
      <description>&lt;PRE id="wp8411317820__codeblock_vkh_hd1_jzb" class="pre codeblock"&gt;&lt;CODE&gt;&lt;KBD class="userinput"&gt;&lt;STRONG class="ph userinput"&gt;ssh stack ciscossh&lt;/STRONG&gt;&lt;/KBD&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;Try add this command and check&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sat, 16 Mar 2024 20:34:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/%E5%AE%89%E5%85%A8%E8%AE%A8%E8%AE%BA%E5%8C%BA/fpr2140-asa-ssh-failonfiged/m-p/5041481#M9061</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2024-03-16T20:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: FPR2140   ASA  SSH failonfiged</title>
      <link>https://community.cisco.com/t5/%E5%AE%89%E5%85%A8%E8%AE%A8%E8%AE%BA%E5%8C%BA/fpr2140-asa-ssh-failonfiged/m-p/5041566#M9062</link>
      <description>&lt;LI-CODE lang="markup"&gt;i try write erase and reload the ASA. and try go re-configure using Console again&lt;/LI-CODE&gt;
&lt;P&gt;This is not the best practice to configure SSH to erase all the config.&lt;/P&gt;
&lt;P&gt;can we have running configuration (removing sensitive information to have look)&lt;/P&gt;
&lt;P&gt;follow below guide - for SSH access :&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/asa/asa917/configuration/general/asa-917-general-config/admin-management.html#ID-2111-0000013a" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/asa/asa917/configuration/general/asa-917-general-config/admin-management.html#ID-2111-0000013a&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 17 Mar 2024 07:54:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/%E5%AE%89%E5%85%A8%E8%AE%A8%E8%AE%BA%E5%8C%BA/fpr2140-asa-ssh-failonfiged/m-p/5041566#M9062</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2024-03-17T07:54:13Z</dc:date>
    </item>
    <item>
      <title>回复： FPR2140   ASA  SSH failonfiged</title>
      <link>https://community.cisco.com/t5/%E5%AE%89%E5%85%A8%E8%AE%A8%E8%AE%BA%E5%8C%BA/fpr2140-asa-ssh-failonfiged/m-p/5044694#M9063</link>
      <description>&lt;P&gt;well, i change another ASA device.&amp;nbsp; the issus is&amp;nbsp;has disappeared&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 01:19:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/%E5%AE%89%E5%85%A8%E8%AE%A8%E8%AE%BA%E5%8C%BA/fpr2140-asa-ssh-failonfiged/m-p/5044694#M9063</guid>
      <dc:creator>renma19th</dc:creator>
      <dc:date>2024-03-20T01:19:30Z</dc:date>
    </item>
  </channel>
</rss>

