<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ASAv - HTTPS/ASDM not working -SSL lib error in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asav-https-asdm-not-working-ssl-lib-error/m-p/3214947#M1023442</link>
    <description>&lt;P&gt;It does indeed work (with limited throughput but full functionality).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What Java version are you running on the workstation? I have not been able to get ASDM (on any ASA) to work with the latest "Java 9" (1.9) update and have had to revert to 1.8.&lt;/P&gt;</description>
    <pubDate>Sat, 11 Nov 2017 13:09:35 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-11-11T13:09:35Z</dc:date>
    <item>
      <title>Cisco ASAv - HTTPS/ASDM not working -SSL lib error</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asav-https-asdm-not-working-ssl-lib-error/m-p/3212139#M1023440</link>
      <description>&lt;P&gt;I've downloaded the latest version of Cisco ASAv to carry out some evaluation in our VMware ESXi lab. I've installed the appliance and configured the management interface via CLI, but I can't seem to get it to accept a HTTPS/ASDM connection. It's failing on SSL handshake despite the having matching ciphers on both the client and ASAv. I'm getting the error:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SSL lib error. Function: ssl3_get_client_hello Reason: no shared cipher&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;However, if you look at the logs, there are indeed matching ciphers. Am I wrong in assuming that you can use the ASAv in a lab environment, with limited functionality, for evaluation purposes, without a licence? Surely ASDM should work?&lt;BR /&gt;Below is the Show Version followed by the logs which show that ciphers match, but I still get the SSL lib error.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;ciscoasa# sh ver&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Cisco Adaptive Security Appliance Software Version 9.8(2) &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Firepower Extensible Operating System Version 2.2(2.52)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Device Manager Version 7.8(2)&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Compiled on Sun 27-Aug-17 13:09 PDT by builders&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;System image file is "boot:/asa982-smp-k8.bin"&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Config file at boot was "startup-config"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;ciscoasa up 5 days 19 hours&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Hardware: ASAv, 1024 MB RAM, CPU Pentium II 2933 MHz,&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Model Id: ASAv5&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Internal ATA Compact Flash, 1024MB&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Slot 1: ATA Compact Flash, 8192MB&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;BIOS Flash Firmware Hub @ 0x0, 0KB&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;EM&gt; 0: Ext: Management0/0 : address is 0050.5680.0693, irq 10&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; 1: Ext: GigabitEthernet0/0 : address is 0050.5680.a342, irq 5&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; 2: Ext: GigabitEthernet0/1 : address is 0050.5680.2086, irq 9&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; 3: Ext: GigabitEthernet0/2 : address is 0050.5680.0c51, irq 11&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; 4: Ext: GigabitEthernet0/3 : address is 0050.5680.7b8e, irq 10&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; 5: Ext: GigabitEthernet0/4 : address is 0050.5680.66e1, irq 5&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; 6: Ext: GigabitEthernet0/5 : address is 0050.5680.58d5, irq 9&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; 7: Ext: GigabitEthernet0/6 : address is 0050.5680.e822, irq 11&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; 8: Ext: GigabitEthernet0/7 : address is 0050.5680.3e0c, irq 10&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt; 9: Ext: GigabitEthernet0/8 : address is 0050.5680.0882, irq 5&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;License mode: Smart Licensing&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ASAv Platform License State: Unlicensed&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;No active entitlement: no feature tier and no throughput level configured&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;*Memory resource allocation is more than the permitted limit.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Licensed features for this platform:&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Maximum VLANs : 25 &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Inside Hosts : Unlimited &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Failover : Active/Standby &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Encryption-DES : Enabled &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Encryption-3DES-AES : Enabled &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Security Contexts : 0 &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Carrier : Disabled &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;AnyConnect Premium Peers : 2 &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;AnyConnect Essentials : Disabled &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Other VPN Peers : 50 &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Total VPN Peers : 50 &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;AnyConnect for Mobile : Disabled &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;AnyConnect for Cisco VPN Phone : Disabled &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Advanced Endpoint Assessment : Disabled &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Shared License : Disabled &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Total TLS Proxy Sessions : 2 &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Botnet Traffic Filter : Enabled &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Cluster : Disabled&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Serial Number: 9AT64WC9QLR&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Image type : Release&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Key version : A&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;Configuration last modified by enable_15 at 16:26:25.788 UTC Thu Nov 2 2017&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ciscoasa#&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;%ASA-6-302013: Built inbound TCP connection 305 for Management:10.222.5.8/29031 (10.222.5.8/29031) to identity:10.73.40.22/443 (10.73.40.22/443)&lt;BR /&gt;%ASA-6-725001: Starting SSL handshake with client Management:10.222.5.8/29031 to 10.73.40.22/443 for TLS session&lt;BR /&gt;%ASA-7-725010: Device supports the following 21 cipher(s)&lt;BR /&gt;%ASA-7-725011: Cipher[1] : ECDHE-ECDSA-AES256-GCM-SHA384&lt;BR /&gt;%ASA-7-725011: Cipher[2] : ECDHE-RSA-AES256-GCM-SHA384&lt;BR /&gt;%ASA-7-725011: Cipher[3] : DHE-RSA-AES256-GCM-SHA384&lt;BR /&gt;%ASA-7-725011: Cipher[4] : AES256-GCM-SHA384&lt;BR /&gt;%ASA-7-725011: Cipher[5] : ECDHE-ECDSA-AES256-SHA384&lt;BR /&gt;%ASA-7-725011: Cipher[6] : ECDHE-RSA-AES256-SHA384&lt;BR /&gt;%ASA-7-725011: Cipher[7] : DHE-RSA-AES256-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[8] : AES256-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[9] : ECDHE-ECDSA-AES128-GCM-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[10] : ECDHE-RSA-AES128-GCM-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[11] : DHE-RSA-AES128-GCM-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[12] : AES128-GCM-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[13] : ECDHE-ECDSA-AES128-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[14] : ECDHE-RSA-AES128-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[15] : DHE-RSA-AES128-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[16] : AES128-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[17] : DHE-RSA-AES256-SHA&lt;BR /&gt;%ASA-7-725011: Cipher[18] : AES256-SHA&lt;BR /&gt;%ASA-7-725011: Cipher[19] : DHE-RSA-AES128-SHA&lt;BR /&gt;%ASA-7-725011: Cipher[20] : AES128-SHA&lt;BR /&gt;%ASA-7-725011: Cipher[21] : DES-CBC3-SHA&lt;BR /&gt;%ASA-7-725008: SSL client Management:10.222.5.8/29031 to 10.73.40.22/443 proposes the following 20 cipher(s)&lt;BR /&gt;%ASA-7-725011: Cipher[1] : ECDHE-ECDSA-AES128-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[2] : ECDHE-RSA-AES128-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[3] : AES128-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[4] : DHE-RSA-AES128-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[5] : DHE-DSS-AES128-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[6] : ECDHE-ECDSA-AES128-SHA&lt;BR /&gt;%ASA-7-725011: Cipher[7] : ECDHE-RSA-AES128-SHA&lt;BR /&gt;%ASA-7-725011: Cipher[8] : AES128-SHA&lt;BR /&gt;%ASA-7-725011: Cipher[9] : DHE-RSA-AES128-SHA&lt;BR /&gt;%ASA-7-725011: Cipher[10] : DHE-DSS-AES128-SHA&lt;BR /&gt;%ASA-7-725011: Cipher[11] : ECDHE-ECDSA-AES128-GCM-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[12] : ECDHE-RSA-AES128-GCM-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[13] : AES128-GCM-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[14] : DHE-RSA-AES128-GCM-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[15] : DHE-DSS-AES128-GCM-SHA256&lt;BR /&gt;%ASA-7-725011: Cipher[16] : ECDHE-ECDSA-DES-CBC3-SHA&lt;BR /&gt;%ASA-7-725011: Cipher[17] : ECDHE-RSA-DES-CBC3-SHA&lt;BR /&gt;%ASA-7-725011: Cipher[18] : DES-CBC3-SHA&lt;BR /&gt;%ASA-7-725011: Cipher[19] : EDH-RSA-DES-CBC3-SHA&lt;BR /&gt;%ASA-7-725011: Cipher[20] : EDH-DSS-DES-CBC3-SHA&lt;BR /&gt;%ASA-7-725014: SSL lib error. Function: ssl3_get_client_hello Reason: no shared cipher&lt;BR /&gt;%ASA-6-302014: Teardown TCP connection 305 for Management:10.222.5.8/29031 to identity:10.73.40.22/443 duration 0:00:00 bytes 7 TCP FINs&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Network routing is correct and a correct RSA SSL certificate has been generated.&lt;/P&gt;
&lt;P&gt;Any help appreciated. Thanks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:39:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asav-https-asdm-not-working-ssl-lib-error/m-p/3212139#M1023440</guid>
      <dc:creator>Domwilko</dc:creator>
      <dc:date>2020-02-21T14:39:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASAv - HTTPS/ASDM not working -SSL lib error</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asav-https-asdm-not-working-ssl-lib-error/m-p/3214746#M1023441</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-device-manager/110282-asdm-tshoot.html#prblm4" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-device-manager/110282-asdm-tshoot.html#prblm4&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2017 19:25:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asav-https-asdm-not-working-ssl-lib-error/m-p/3214746#M1023441</guid>
      <dc:creator>jumora1</dc:creator>
      <dc:date>2017-11-10T19:25:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASAv - HTTPS/ASDM not working -SSL lib error</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asav-https-asdm-not-working-ssl-lib-error/m-p/3214947#M1023442</link>
      <description>&lt;P&gt;It does indeed work (with limited throughput but full functionality).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What Java version are you running on the workstation? I have not been able to get ASDM (on any ASA) to work with the latest "Java 9" (1.9) update and have had to revert to 1.8.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Nov 2017 13:09:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asav-https-asdm-not-working-ssl-lib-error/m-p/3214947#M1023442</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-11-11T13:09:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASAv - HTTPS/ASDM not working -SSL lib error</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asav-https-asdm-not-working-ssl-lib-error/m-p/3215488#M1023444</link>
      <description>&lt;P&gt;Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've been using Java 1.8.0_151 and I also tried Java 1.8.0_73, but it won't work with either. I've also tried it on several freshly built PCs, both Windows 7 and Windows 10, but it just won't work. From the firewall logs I can see the ASDM client connecting and I can see the SSL lib error, even though there are matching ciphers.&lt;/P&gt;
&lt;P&gt;So you can definitely confirm that you can download the Cisco ASAv from CCO, build the appliance in VMware ESXI and run it without the application of any licence and it should work, albeit with limited throughput (which is all I need)?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dom.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 09:29:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asav-https-asdm-not-working-ssl-lib-error/m-p/3215488#M1023444</guid>
      <dc:creator>Domwilko</dc:creator>
      <dc:date>2017-11-13T09:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASAv - HTTPS/ASDM not working -SSL lib error</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asav-https-asdm-not-working-ssl-lib-error/m-p/3215497#M1023447</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've already run through all of the proposed solutions on that link and none of them work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I always get the SSL Lib error, despite there being matching ciphers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dom.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 09:41:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asav-https-asdm-not-working-ssl-lib-error/m-p/3215497#M1023447</guid>
      <dc:creator>Domwilko</dc:creator>
      <dc:date>2017-11-13T09:41:31Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASAv - HTTPS/ASDM not working -SSL lib error</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asav-https-asdm-not-working-ssl-lib-error/m-p/3215569#M1023452</link>
      <description>&lt;P&gt;Yes, I confirm it works with the combination you asked.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is a screenshot of my unlicensed ASAv running on my ESXi 6.0 Update 3 host being managed by ASDM on Windows 10:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ASDM on ASAv.PNG" style="width: 876px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/3251i008EA2F5FEB4F11F/image-size/large?v=v2&amp;amp;px=999" role="button" title="ASDM on ASAv.PNG" alt="ASDM on ASAv.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;asav# show ver&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT face="courier new,courier"&gt;Cisco Adaptive Security Appliance Software Version 9.8(1)7 &lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Firepower Extensible Operating System Version 2.2(1.51)&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="courier new,courier"&gt;Device Manager Version 7.8(2)151&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 12:18:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asav-https-asdm-not-working-ssl-lib-error/m-p/3215569#M1023452</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-11-13T12:18:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ASAv - HTTPS/ASDM not working -SSL lib error</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asav-https-asdm-not-working-ssl-lib-error/m-p/3215584#M1023465</link>
      <description>&lt;P&gt;Thanks Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How very odd. The only difference I can see is that you are running 9.8.1(7), whereas i'm running 9.8(2).&lt;/P&gt;
&lt;P&gt;I'll try dropping back to the release you are using and see if that works.&lt;/P&gt;
&lt;P&gt;Thanks for taking your time to respond. At least I know that it's definitely not a licencing issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As an aside, I seem to be able to configure the firewall fine from CLI, it's just the ASDM that doesn't want to play.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Dom&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2017 12:38:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asav-https-asdm-not-working-ssl-lib-error/m-p/3215584#M1023465</guid>
      <dc:creator>Domwilko</dc:creator>
      <dc:date>2017-11-13T12:38:17Z</dc:date>
    </item>
  </channel>
</rss>

