<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: can't connect to ASA5520 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160005#M368823</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes we are making progress.  You are right, there was a route missing through the inside interface, I can now ping the firewall from the work station (after I've added the route), but I am still unable to ssh to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would any debug show me what's happeing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 Jan 2009 20:31:04 GMT</pubDate>
    <dc:creator>ronshuster</dc:creator>
    <dc:date>2009-01-12T20:31:04Z</dc:date>
    <item>
      <title>can't connect to ASA5520</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1159999#M368817</link>
      <description>&lt;P&gt;This is an easy one, but if you're stuck you're stuck!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am unable to connect to my ASA5520, I get the following message:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[SSH] FAIL: No connection could be made because the target machine actively refused it.   &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a backdoor to access it and not sure how to clear whatever is there that is not allowing me in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have ssh &amp;lt;network&amp;gt; &amp;lt;segment&amp;gt; interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:16:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1159999#M368817</guid>
      <dc:creator>ronshuster</dc:creator>
      <dc:date>2019-03-10T23:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: can't connect to ASA5520</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160000#M368818</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Roni&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My first question would whether you have configured the RSA keys that are required for SSH to work?&lt;/P&gt;&lt;P&gt;My second question would be whether you have properly configured SSH access? Can you post the output from the ASA of show run | incude ssh&lt;/P&gt;&lt;P&gt;My third question would be whether you can look on the logs of the ASA and find any messages about the attempt to connect. These might help in identifying the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Jan 2009 17:41:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160000#M368818</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2009-01-08T17:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: can't connect to ASA5520</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160001#M368819</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto key generate rsa modulus 1024&lt;/P&gt;&lt;P&gt;ssh a.b.c.d 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The routes to the firewall is also ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But for some reason the firewall will not accept SSH &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2009 18:48:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160001#M368819</guid>
      <dc:creator>ronshuster</dc:creator>
      <dc:date>2009-01-12T18:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: can't connect to ASA5520</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160002#M368820</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Roni&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like you have answered my first question and that RSA keys have been generated. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have answered only part of my second question. You have shown the ssh a.b.c.d which enable SSH for that address but have not indicated on which interface you have enabled it. And you have not told us to which interface you are attempting to SSH.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And you have not answered my third question, which is perhaps most likely to show us the problem. Can you attempt SSH and then quickly look in the logs of the ASA and see what it has to say about the attempt to SSH?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2009 19:01:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160002#M368820</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2009-01-12T19:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: can't connect to ASA5520</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160003#M368821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry...&lt;/P&gt;&lt;P&gt;I just opened up ssh completely:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 Inside&lt;/P&gt;&lt;P&gt;I am attempting to ssh to the INSIDE interface and I am coming from the INSIDE interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I opened everything for all incoming traffic to the INSIDE interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list inside_access_in extended permit ip any any&lt;/P&gt;&lt;P&gt;access-group inside_access_in in interface Inside &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logs: in fact I did see something on the log, here it is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jan 12 2009 12:43:08: %ASA-1-106021: Deny TCP reverse path check from 10.0.107.8&lt;/P&gt;&lt;P&gt; to 192.168.230.2 on interface Inside  &lt;/P&gt;&lt;P&gt;(107.8 is my address)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just removed ip verify reverse-path interface Inside and I am still unable to access it with SSH but this time it is not timing out right away.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2009 20:09:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160003#M368821</guid>
      <dc:creator>ronshuster</dc:creator>
      <dc:date>2009-01-12T20:09:41Z</dc:date>
    </item>
    <item>
      <title>Re: can't connect to ASA5520</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160004#M368822</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Roni&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is making progress &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Obviously your PC has a valid routed path to the ASA. Does the ASA have a valid routed path back to your PC? (the reverse path check issue suggests that the ASA does not have a route to your address through the inside interface).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2009 20:20:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160004#M368822</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2009-01-12T20:20:37Z</dc:date>
    </item>
    <item>
      <title>Re: can't connect to ASA5520</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160005#M368823</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes we are making progress.  You are right, there was a route missing through the inside interface, I can now ping the firewall from the work station (after I've added the route), but I am still unable to ssh to it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would any debug show me what's happeing?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2009 20:31:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160005#M368823</guid>
      <dc:creator>ronshuster</dc:creator>
      <dc:date>2009-01-12T20:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: can't connect to ASA5520</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160006#M368824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here's a capture:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.0.107.8 is my workstation&lt;/P&gt;&lt;P&gt;192.168.230.2 is the INSIDE of the fw&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6 packets captured&lt;/P&gt;&lt;P&gt;   1: 13:18:06.783559 10.0.107.8.3107 &amp;gt; 192.168.230.2.22: S 3573581954:3573581954(0) win 64512 &lt;MSS 1460=""&gt;&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;   2: 13:18:06.783605 192.168.230.2.22 &amp;gt; 10.0.107.8.3107: S 4117345141:4117345141(0) ack 3573581955 win 8192 &lt;MSS 1380=""&gt;&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;   3: 13:18:09.763113 10.0.107.8.3107 &amp;gt; 192.168.230.2.22: S 3573581954:3573581954(0) win 64512 &lt;MSS 1460=""&gt;&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;   4: 13:18:09.763159 192.168.230.2.22 &amp;gt; 10.0.107.8.3107: S 4117345141:4117345141(0) ack 3573581955 win 8192 &lt;MSS 1380=""&gt;&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;   5: 13:18:15.698404 10.0.107.8.3107 &amp;gt; 192.168.230.2.22: S 3573581954:3573581954(0) win 64512 &lt;MSS 1460=""&gt;&lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;   6: 13:18:15.698450 192.168.230.2.22 &amp;gt; 10.0.107.8.3107: S 4133945093:4133945093(0) ack 3573581955 win 8192 &lt;MSS 1380=""&gt;       &lt;/MSS&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what debug do you recommend to run?  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2009 20:43:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160006#M368824</guid>
      <dc:creator>ronshuster</dc:creator>
      <dc:date>2009-01-12T20:43:00Z</dc:date>
    </item>
    <item>
      <title>Re: can't connect to ASA5520</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160007#M368825</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Roni&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would start with debug ssh and see what it tells you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2009 20:54:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160007#M368825</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2009-01-12T20:54:00Z</dc:date>
    </item>
    <item>
      <title>Re: can't connect to ASA5520</title>
      <link>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160008#M368826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Roni&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another thought occurs to me about possible issues with SSH access. Have you configured authentication for SSH? Authentication could be done using an external authentication server or could be done with local authentication (which also requires configuration of a local user ID and password). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rick&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Jan 2009 21:44:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-t-connect-to-asa5520/m-p/1160008#M368826</guid>
      <dc:creator>Richard Burts</dc:creator>
      <dc:date>2009-01-12T21:44:32Z</dc:date>
    </item>
  </channel>
</rss>

