<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FWSM issue , cant run any command in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-issue-cant-run-any-command/m-p/4184637#M1075883</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had issue that the primary device was dead as the module died. hardware was replaced everything is fine, i manged to configure it. It replicated well. Primary device is active, secondary device is active as it should be.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;but now cant login to active context with IP, as crypto key is required to be ran on all the contexts in FWMS, because they have been just&amp;nbsp; replicated from the standby device.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;but how I do it ? i cant login to them before adding the crypto key, and from doing "session slot # p 1"&lt;BR /&gt;&lt;BR /&gt;it gives me error "Command authorization failed"&amp;nbsp;&lt;BR /&gt;cant ran any command and have to kill the session to exit.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;how can I fix this please?&lt;BR /&gt;version is bit lower&amp;nbsp;&amp;nbsp;FWSM Firewall Version 4.1(6) &amp;lt;system&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Please assist.&amp;nbsp;&lt;BR /&gt;Regards&lt;BR /&gt;shinda&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 17 Nov 2020 10:44:44 GMT</pubDate>
    <dc:creator>shinda_77</dc:creator>
    <dc:date>2020-11-17T10:44:44Z</dc:date>
    <item>
      <title>FWSM issue , cant run any command</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-issue-cant-run-any-command/m-p/4184637#M1075883</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had issue that the primary device was dead as the module died. hardware was replaced everything is fine, i manged to configure it. It replicated well. Primary device is active, secondary device is active as it should be.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;but now cant login to active context with IP, as crypto key is required to be ran on all the contexts in FWMS, because they have been just&amp;nbsp; replicated from the standby device.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;but how I do it ? i cant login to them before adding the crypto key, and from doing "session slot # p 1"&lt;BR /&gt;&lt;BR /&gt;it gives me error "Command authorization failed"&amp;nbsp;&lt;BR /&gt;cant ran any command and have to kill the session to exit.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;how can I fix this please?&lt;BR /&gt;version is bit lower&amp;nbsp;&amp;nbsp;FWSM Firewall Version 4.1(6) &amp;lt;system&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Please assist.&amp;nbsp;&lt;BR /&gt;Regards&lt;BR /&gt;shinda&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 10:44:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-issue-cant-run-any-command/m-p/4184637#M1075883</guid>
      <dc:creator>shinda_77</dc:creator>
      <dc:date>2020-11-17T10:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM issue , cant run any command</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-issue-cant-run-any-command/m-p/4184644#M1075885</link>
      <description>&lt;P&gt;Are you able to login to other FWSM Module from console ? or do you have both FWSM Module issue ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;best suggestion is just eject the Module and reseat and test it. - make sure you login and check the one you have access - check the HA availability.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HA requirement, make sure you need to have both same version before join in HA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 11:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-issue-cant-run-any-command/m-p/4184644#M1075885</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-11-17T11:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM issue , cant run any command</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-issue-cant-run-any-command/m-p/4185023#M1075904</link>
      <description>&lt;P&gt;Thanks BB:&lt;BR /&gt;&lt;BR /&gt;I can login to 6500 by console or however ..all possible&lt;BR /&gt;from 6500&lt;/P&gt;&lt;P&gt;i can login to the active module&lt;BR /&gt;6500# sess slot 6 p 1&lt;BR /&gt;enter credentials and I am in ..&lt;BR /&gt;FWMS/act#&amp;nbsp;&lt;BR /&gt;on system context i can do anything&amp;nbsp; ..&lt;BR /&gt;but when i change to any other contexts i can change&lt;BR /&gt;FWMS/Admin/act# sh run&lt;BR /&gt;it brings error..&lt;BR /&gt;&lt;SPAN&gt;Command authorization failed&lt;/SPAN&gt;&lt;BR /&gt;that means I need to run crypto key,, but how can I do it ?&lt;BR /&gt;I cant ssh to any context directly neither can perform any change when logged in vai module ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;however I can ssh to standby but making changes on standby will not replicate..&lt;BR /&gt;&lt;BR /&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 03:01:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-issue-cant-run-any-command/m-p/4185023#M1075904</guid>
      <dc:creator>shinda_77</dc:creator>
      <dc:date>2020-11-18T03:01:38Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM issue , cant run any command</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-issue-cant-run-any-command/m-p/4185532#M1075944</link>
      <description>&lt;P&gt;i suggest to pull the new install module and try.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 20:59:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-issue-cant-run-any-command/m-p/4185532#M1075944</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2020-11-18T20:59:11Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM issue , cant run any command</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-issue-cant-run-any-command/m-p/4185542#M1075946</link>
      <description>&lt;P&gt;You could try logging into the secondary FWSM and send commands to the primary from there (for example remove command authorization configuration) using:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;failover exec active show run aaa&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;find the aaa authorization command, and if it is present, remove it.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;failover exec active no aaa authorizaiton command &amp;lt;tacacs+ server&amp;gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;You should now be able to run commands there.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Another thing you can and should check before doing this is the AAA server you are running command authorization towards.&amp;nbsp; Your user might have "accidentally" had a change of privileges.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Nov 2020 21:12:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-issue-cant-run-any-command/m-p/4185542#M1075946</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2020-11-18T21:12:32Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM issue , cant run any command</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-issue-cant-run-any-command/m-p/4185605#M1075955</link>
      <description>&lt;P&gt;Hi Marius,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks a lot for your response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;sorry i could not run those commands on standby, neither on system or admin context&lt;/P&gt;&lt;P&gt;&lt;FONT face="comic sans ms,sans-serif"&gt;#admin/stby# sh failover ?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="comic sans ms,sans-serif"&gt;| Output modifiers&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="comic sans ms,sans-serif"&gt;&amp;lt;cr&amp;gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT face="comic sans ms,sans-serif"&gt;#/stby# failover ?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="comic sans ms,sans-serif"&gt;active Make this system to be the active unit of the failover pair&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="comic sans ms,sans-serif"&gt;reload-standby Force standby unit to reboot&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT face="comic sans ms,sans-serif"&gt;reset Force an unit or failover group to an unfailed state&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Please note that issue is with contexts and not on 'system'&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2020 00:36:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-issue-cant-run-any-command/m-p/4185605#M1075955</guid>
      <dc:creator>shinda_77</dc:creator>
      <dc:date>2020-11-19T00:36:02Z</dc:date>
    </item>
  </channel>
</rss>

