<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE 2.3 Patch 4 SFTP Repository SSH issue. in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3802892#M485446</link>
    <description>&lt;P&gt;Known limitation --&amp;nbsp;CSCum13116&lt;/P&gt;</description>
    <pubDate>Fri, 15 Feb 2019 17:14:24 GMT</pubDate>
    <dc:creator>hslai</dc:creator>
    <dc:date>2019-02-15T17:14:24Z</dc:date>
    <item>
      <title>ISE 2.3 Patch 4 SFTP Repository SSH issue.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3796319#M485434</link>
      <description>&lt;P&gt;I have created a new SFTP repository on a ISE 2.3 Patch 4 primary admin node both in the CLI and GUI and run the&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Crypto host-key add host URL_of_SFTP server&lt;/P&gt;
&lt;P&gt;And I get the error below when I try to validate the repository.&amp;nbsp; What did I miss for the config?&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Repository validation failed due to error - SSH connect error. Verify configuration&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 21:17:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3796319#M485434</guid>
      <dc:creator>vseward</dc:creator>
      <dc:date>2019-02-06T21:17:02Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 Patch 4 SFTP Repository SSH issue.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3796371#M485435</link>
      <description>&lt;P&gt;Have you configured the SFTP server to accept request from the ISE node? Also, check the ADE log (show logging system ade/ADE.log) for more information on why it failed.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 22:39:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3796371#M485435</guid>
      <dc:creator>howon</dc:creator>
      <dc:date>2019-02-06T22:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 Patch 4 SFTP Repository SSH issue.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3796691#M485437</link>
      <description>&lt;P&gt;Are you using the Microsoft version of OpenSSH SFTP server by any chance?&amp;nbsp; It's an option in Windows10 and I suppose in some of the Server variants too, since Microsoft historically didn't support SFTP in its IIS server.&amp;nbsp; In that case you need to fiddle around with the allowed cipher suites.&amp;nbsp; ISE is a bit limited&amp;nbsp;and it does not support CTC ciphers support - and you may have to tell your SFTP server to support some legacy ciphers like aes256-cbc,aes128-cbc etc.&lt;/P&gt;
&lt;P&gt;The SFTP&amp;nbsp;Server logs will probably reveal your problem.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 11:03:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3796691#M485437</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2019-02-07T11:03:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 Patch 4 SFTP Repository SSH issue.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3801392#M485438</link>
      <description>&lt;P&gt;The SFTP server is&amp;nbsp;&lt;SPAN&gt;Redhat 7.5 and the error in its log is.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Unable to negotiate with X.X.X.X port 48745: no matching cipher found. Their offer: aes256-cbc,aes128-cbc&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 00:26:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3801392#M485438</guid>
      <dc:creator>vseward</dc:creator>
      <dc:date>2019-02-14T00:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 Patch 4 SFTP Repository SSH issue.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3801441#M485442</link>
      <description>&lt;P&gt;What do you see if you take capture on ISE for SFTP server? Is three way handshake getting completed?&lt;/P&gt;</description>
      <pubDate>Thu, 14 Feb 2019 03:24:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3801441#M485442</guid>
      <dc:creator>pan</dc:creator>
      <dc:date>2019-02-14T03:24:36Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 Patch 4 SFTP Repository SSH issue.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3801455#M485443</link>
      <description>That's ISE saying it will only use aes256-cbc or aes128-cbc.  I don't know of any way to adjust the ISE chiper set, but this is certainly supported and modifiable in your Redhat Linux.  My Linux skills are rusty, but I think I would start in /etc/ssh/sshd_config. &lt;BR /&gt;&lt;BR /&gt;There should be a ciphers line that you can modify to include the two being suggested by ISE.  It would appear that your new version of RHEL changed the default from the sshd man page or someone modified the default.  If aes256-cbc and aes128-cbc are still in there then you might have something else handling this connection.  &lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;From the sshd man page:&lt;BR /&gt;&lt;BR /&gt;Ciphers&lt;BR /&gt;Specifies the ciphers allowed for protocol version 2. Multiple ciphers must be comma-separated. The supported ciphers are ''3des-cbc'', ''aes128-cbc'', ''aes192-cbc'', ''aes256-cbc'', ''aes128-ctr'', ''aes192-ctr'', ''aes256-ctr'', ''arcfour128'', ''arcfour256'', ''arcfour'', ''blowfish-cbc'', and ''cast128-cbc''. The default is:&lt;BR /&gt;&lt;BR /&gt;aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,&lt;BR /&gt;aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,aes192-cbc,&lt;BR /&gt;aes256-cbc,arcfour</description>
      <pubDate>Thu, 14 Feb 2019 03:48:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3801455#M485443</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-02-14T03:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 Patch 4 SFTP Repository SSH issue.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3802892#M485446</link>
      <description>&lt;P&gt;Known limitation --&amp;nbsp;CSCum13116&lt;/P&gt;</description>
      <pubDate>Fri, 15 Feb 2019 17:14:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3802892#M485446</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-02-15T17:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 Patch 4 SFTP Repository SSH issue.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3802968#M485448</link>
      <description>&lt;P&gt;So I posted this in another post relating to scp ISE issues.&amp;nbsp; See below, this may help you out:&lt;/P&gt;&lt;P&gt;Use this link to setup remote sftp linux repo:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.howtoforge.com/tutorial/how-to-setup-an-sftp-server-on-centos/" target="_blank" rel="nofollow noopener noreferrer"&gt;https://www.howtoforge.com/tutorial/how-to-setup-an-sftp-server-on-centos/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Don't forget to add the key to ISE:&lt;/P&gt;&lt;P&gt;ise/admin# configure terminal&lt;BR /&gt;ise/admin(config)# repository myrepository&lt;BR /&gt;ise/admin(config-Repository)# url sftp://ise&lt;BR /&gt;ise/admin(config-Repository)# host-key host ise&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On your server you may see the following errors:&lt;/P&gt;&lt;P&gt;sshd[18546]: fatal: bad ownership or modes for chroot directory "/data/ise" [postauth]&lt;/P&gt;&lt;P&gt;sshd[18351]: fatal: no matching cipher found: client aes256-cbc,aes128-cbc,aes128-gcm@openssh.com,aes256-gcm@openssh.com server aes128-ctr,aes192-ctr,aes256-ctr [preauth]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Double check ownership on your directories you are writing to or pulling from. Also, if you need to tweak ciphers modify your sshd_config.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Or if you want to use ftp you can do so this way (process should be similar even if attempting to use SCP):&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;make sure you create local repo&lt;BR /&gt;#conf t&lt;BR /&gt;#repository&amp;nbsp;REPO&lt;BR /&gt;##url disk:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;copy ftp://XXXXX/FILENAME disk:/&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;delete FILE disk:/&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;HTH!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Feb 2019 19:26:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3802968#M485448</guid>
      <dc:creator>Mike.Cifelli</dc:creator>
      <dc:date>2019-02-15T19:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: ISE 2.3 Patch 4 SFTP Repository SSH issue.</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3803034#M485449</link>
      <description>Thanks for sharing that.  Good to know it's tracked, hopefully it makes it in to a future release.</description>
      <pubDate>Fri, 15 Feb 2019 21:18:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-2-3-patch-4-sftp-repository-ssh-issue/m-p/3803034#M485449</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-02-15T21:18:57Z</dc:date>
    </item>
  </channel>
</rss>

