<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firepower 2130 OOB ASDM and SSH management. in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-2130-oob-asdm-and-ssh-management/m-p/4177931#M1075416</link>
    <description>&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;Good Morning,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been working with testing a remote connection for a network expansion we have coming up, and have been unsuccessful in figuring out how to access the new Firepower 2130 via ASDM through an outside network connection in order to maintain and manage the device remotely across our campus LAN transport.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tested all the older model ASA configurations to allow access to ASDM and SSH via the outside port, but have had no luck with the new Firepower 2130 at this time. So far I am only able to access management on the device from a directly connected switch, or desktop configuration. At this point I am thinking I may have a technician configure their end of the connection with a VM internal system that I can connect to, and then connect into the FP ASDM management that way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am open to any suggestions anyone may have however, so that I may keep this managed from outside the internal connection that the Firepower provides security for as I feel going around behind it would just create a security issue that I do not want to have on our network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you all in advance for any advice and assistance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Respectfully,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ron Leet&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
    <pubDate>Tue, 03 Nov 2020 11:53:35 GMT</pubDate>
    <dc:creator>RonLeet504990</dc:creator>
    <dc:date>2020-11-03T11:53:35Z</dc:date>
    <item>
      <title>Firepower 2130 OOB ASDM and SSH management.</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2130-oob-asdm-and-ssh-management/m-p/4177931#M1075416</link>
      <description>&lt;DIV class="lia-message-body lia-component-message-view-widget-body lia-component-body-signature-highlight-escalation lia-component-message-view-widget-body-signature-highlight-escalation"&gt;&lt;DIV class="lia-message-body-content"&gt;&lt;P&gt;Good Morning,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have been working with testing a remote connection for a network expansion we have coming up, and have been unsuccessful in figuring out how to access the new Firepower 2130 via ASDM through an outside network connection in order to maintain and manage the device remotely across our campus LAN transport.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tested all the older model ASA configurations to allow access to ASDM and SSH via the outside port, but have had no luck with the new Firepower 2130 at this time. So far I am only able to access management on the device from a directly connected switch, or desktop configuration. At this point I am thinking I may have a technician configure their end of the connection with a VM internal system that I can connect to, and then connect into the FP ASDM management that way.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am open to any suggestions anyone may have however, so that I may keep this managed from outside the internal connection that the Firepower provides security for as I feel going around behind it would just create a security issue that I do not want to have on our network.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you all in advance for any advice and assistance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Respectfully,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ron Leet&lt;/P&gt;&lt;/DIV&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 03 Nov 2020 11:53:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2130-oob-asdm-and-ssh-management/m-p/4177931#M1075416</guid>
      <dc:creator>RonLeet504990</dc:creator>
      <dc:date>2020-11-03T11:53:35Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2130 OOB ASDM and SSH management.</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2130-oob-asdm-and-ssh-management/m-p/4177958#M1075419</link>
      <description>&lt;P&gt;Just for clarity, you have ASA software installed on the FTD2130?&lt;/P&gt;
&lt;P&gt;Could you post the configuration you are trying to implement &lt;FONT color="#FF0000"&gt;(remember to remove any public IPs, usernames, and passwords)&lt;/FONT&gt;?&lt;/P&gt;
&lt;P&gt;Are you trying to connect directly to the outside/internet facing interface or over å RA-VPN?&lt;/P&gt;
&lt;P&gt;Usually to get this working directly to the outside interface you would need to do the following.&lt;/P&gt;
&lt;P&gt;For ASDM:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;http server enable 4433 &lt;FONT color="#FF0000"&gt;!(or any other port you want to connect to.&amp;nbsp; leave blank to use port 443)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;http 1.1.1.1 255.255.255.255 outside&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;asdm image &amp;lt;image_name&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For SSH:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;make sure SSH is enabled ( it should be enabled by default) show ssh&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;crypto key generate rsa modulus 2048 &lt;FONT color="#FF0000"&gt;!(optional if SSH is already enabled)&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ssh 1.1.1.1 255.255.255.255 outside&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 12:20:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2130-oob-asdm-and-ssh-management/m-p/4177958#M1075419</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-11-03T12:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2130 OOB ASDM and SSH management.</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2130-oob-asdm-and-ssh-management/m-p/4184367#M1075822</link>
      <description>&lt;P&gt;Good Morning Marius,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I apologize for the delayed response, this account is tagged to my work email, and I was unable to make it into the office for the past ten days. I do want to per-emptively thank you for any assistance you are able to offer and thank you for what you have currently offered already.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For clarification purposes:&lt;/P&gt;&lt;P&gt;Yes we have ASA software and ASDM installed on our FP2130s.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As for configurations, these are currently in a testing lab based environment, and are air-gapped systems, I will have to manually transcribe them to the open internet in order to share, but I will work on that for better insight and assistance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In response to your current suggestions, I have actually performed both of these configurations in different fashions here and there through multiple tests, and have not been able to get ASDM to open at all from the outside switch/laptop setup. As for SSH, I was able to get this to actually function ONCE at some point in testing and have not been able to get SSH to work ever since, this is because we currently do not have our 3DES license configured on our systems, as they are currently listed as smart license products, and we need on-prem ones, Cisco is currently working with me to get that resolved, other than that I cannot get any SSH instances to work, but can get Telnet (all from the inside port btw).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A quick glimpse as to how my ports are configured on the ASA FP2130, and C9300 however, they are like this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ASA:&lt;/P&gt;&lt;P&gt;interface Ethernet1/1&lt;/P&gt;&lt;P&gt;nameif outside&lt;/P&gt;&lt;P&gt;security-level 0&lt;/P&gt;&lt;P&gt;ip address x.x.x.195 255.255.255.192&lt;/P&gt;&lt;P&gt;interface Ethernet1/2.10&lt;/P&gt;&lt;P&gt;vlan10&lt;/P&gt;&lt;P&gt;nameif inside&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address x.x.x.1 255.255.255.128&lt;/P&gt;&lt;P&gt;interface Management1/1.32&lt;/P&gt;&lt;P&gt;management-only&lt;/P&gt;&lt;P&gt;vlan 32&lt;/P&gt;&lt;P&gt;nameif management&lt;/P&gt;&lt;P&gt;security-level 100&lt;/P&gt;&lt;P&gt;ip address x.x.x.129 255.255.255.224&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(inside 9300 configuration setup for trunk ports to management and inside interfaces to test inside settings, which now I can't even get ASDM to open I was able to before I was stuck at home for the past ten days.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Outside C9300&lt;/P&gt;&lt;P&gt;interface Vlan530&lt;/P&gt;&lt;P&gt;ip address x.x.x.194 255.255.255.192&lt;/P&gt;&lt;P&gt;vlan 530&lt;/P&gt;&lt;P&gt;name Ext-Site&lt;/P&gt;&lt;P&gt;interface GigabitEthernet1/0/47&lt;/P&gt;&lt;P&gt;description External-FP2130&lt;/P&gt;&lt;P&gt;switchport access vlan 530&lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2020 14:35:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2130-oob-asdm-and-ssh-management/m-p/4184367#M1075822</guid>
      <dc:creator>RonLeet504990</dc:creator>
      <dc:date>2020-11-16T14:35:39Z</dc:date>
    </item>
    <item>
      <title>Re: Firepower 2130 OOB ASDM and SSH management.</title>
      <link>https://community.cisco.com/t5/network-security/firepower-2130-oob-asdm-and-ssh-management/m-p/4184375#M1075824</link>
      <description>&lt;P&gt;Could you post the output of &lt;STRONG&gt;show run ssh, show run http, show run asdm, dir,&lt;/STRONG&gt; and &lt;STRONG&gt;show ssh&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;as well as the configuration of the switch port that connects to the management interface.&amp;nbsp; Are you sure that this isn't a routing issue?&amp;nbsp; When you are testing are you on the same subnet as the ASA interface you are connecting to?&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2020 15:07:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-2130-oob-asdm-and-ssh-management/m-p/4184375#M1075824</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-11-16T15:07:27Z</dc:date>
    </item>
  </channel>
</rss>

