<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5506 - no SSH possible in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4299861#M1078925</link>
    <description>&lt;P&gt;After resetting did you configure below :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="pre codeblock"&gt;&lt;CODE&gt;aaa authentication ssh console LOCAL&lt;/CODE&gt;&lt;BR /&gt;username XXXX passowrd&lt;/PRE&gt;
&lt;P&gt;please post the complete config again, show run, also what client you using.&lt;/P&gt;
&lt;P&gt;are you able to ping 192.168.1.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Quick question is this your intention of BVI with inside_1 to 7&amp;nbsp; (since we see this is a bug) - it automatically creates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;read this post :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.petenetlive.com/KB/Article/0001422" target="_blank"&gt;https://www.petenetlive.com/KB/Article/0001422&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in that case, still, you need to use the inside interface here. Try below :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;no ssh 192.168.1.0 255.255.255.0 inside_7&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ssh 192.168.1.0 255.255.255.0 inside&lt;/STRONG&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Mar 2021 09:58:52 GMT</pubDate>
    <dc:creator>balaji.bandi</dc:creator>
    <dc:date>2021-03-02T09:58:52Z</dc:date>
    <item>
      <title>ASA 5506 - no SSH possible</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4298955#M1078853</link>
      <description>&lt;P&gt;Hello Together&lt;BR /&gt;Please i will open for LAN "Inside" the SSH Port. try with this commands but no postive result appair "Connection redused"&lt;/P&gt;&lt;P&gt;i know iam on the right way, please and thanks for any Update:&lt;BR /&gt;&lt;BR /&gt;asa(config)# crypto key generate rsa general-keys modulus 2048&lt;BR /&gt;Keypair generation process begin. Please wait...&lt;BR /&gt;asa(config)# username SSH password *********&lt;BR /&gt;asa(config)# aaa authentication ssh console LOCAL&lt;BR /&gt;asa(config)# ssh version 2&lt;BR /&gt;asa(config)# wr&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Mauri&lt;/P&gt;</description>
      <pubDate>Sun, 28 Feb 2021 10:02:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4298955#M1078853</guid>
      <dc:creator>Maurizio Caloro</dc:creator>
      <dc:date>2021-02-28T10:02:40Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 - no SSH possible</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4298957#M1078854</link>
      <description>&lt;P&gt;Try below and test it&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG class="cBold"&gt;ssh 10.10.10.0 255.255.255.0&amp;nbsp; inside&lt;/STRONG&gt;&lt;/SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ( replace the network 10.10.10.0/24 with your network)&lt;/P&gt;</description>
      <pubDate>Sun, 28 Feb 2021 10:09:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4298957#M1078854</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-02-28T10:09:13Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 - no SSH possible</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4298958#M1078855</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You will need to define the whitelist for incoming SSH connection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;ssh [security-zone] [whitelisted-prefix/ip] [mask]
ssh inside 192.168.1.100 255.255.255.255&lt;/PRE&gt;&lt;P&gt;Also, you need to ssh from the same security zone that with the ASA interface. For example, outisde interface (100.64.0.1/30) &amp;amp; inside interface (192.168.1.1/24). You could ssh to ASA's 192.168.1.1 from 192.168.1.100, but you cannot ssh to ASA's 100.64.0.1 from 192.168.1.100.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 28 Feb 2021 10:11:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4298958#M1078855</guid>
      <dc:creator>ngkin2010</dc:creator>
      <dc:date>2021-02-28T10:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 - no SSH possible</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4298970#M1078858</link>
      <description>&lt;P&gt;In addition to what the other have mentioned, please also ensure that you have the 3DES-AES license enabled on your ASA.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Feb 2021 11:08:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4298970#M1078858</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-02-28T11:08:42Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 - no SSH possible</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4298972#M1078859</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as Marvin mentioned you need to make sure you have the 3DES-AES licence. to check if you have 3DES and 3DES-AES enable. issue a command "show version" &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Encryption-DES : Enabled perpetual&lt;BR /&gt;Encryption-3DES-AES : Enabled perpetual&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;also you can issue a command "show ssh ciphers" to check what encrytion is available and what encrytion is configured. or&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;show run all ssh cipher&lt;BR /&gt;ssh cipher encryption medium&lt;BR /&gt;ssh cipher integrity high&lt;/P&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;show run all ssh&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;your command/configuration is right. however, just to mention you need to define the privi level too.&lt;/P&gt;
&lt;P&gt;"username SSH password xxxxx privilege 15"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as ngkin2010 mentioned you need to specified which interface you landing/coming from (source ip). rest your configuration is solid.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Feb 2021 11:26:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4298972#M1078859</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2021-02-28T11:26:25Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 - no SSH possible</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4298999#M1078863</link>
      <description>&lt;P&gt;thanks for so meny answer, did anything but no result.... the ssh port for LAN usage still closed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;asa(config)# ssh 192.168.1.1 255.255.255.0 inside&lt;BR /&gt;ERROR: % Ambiguous command: "ssh 192.168.1.0 255.255.255.0 inside"&lt;/P&gt;&lt;P&gt;Encryption-DES : Enabled perpetual&lt;BR /&gt;Encryption-3DES-AES : Enabled perpetual&lt;/P&gt;&lt;P&gt;asa(config)# show run all ssh&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;ssh version 2&lt;BR /&gt;ssh cipher encryption medium&lt;BR /&gt;ssh cipher integrity high&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;ssh 192.168.1.0 255.255.255.0 inside_7&lt;BR /&gt;ssh 192.168.1.1 255.255.255.255 inside_7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Inside_7 = are connectec to my PC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;yes, wr also are done.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Feb 2021 13:49:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4298999#M1078863</guid>
      <dc:creator>Maurizio Caloro</dc:creator>
      <dc:date>2021-02-28T13:49:01Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 - no SSH possible</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4299006#M1078865</link>
      <description>&lt;P&gt;ssh 192.168.1.0 255.255.255.0 inside_7&amp;nbsp;&amp;nbsp; (inside most people uses , if this is your only insde interface that should work)&lt;BR /&gt;no ssh 192.168.1.1 255.255.255.255 inside_7&amp;nbsp; - you do not need this one since above subnet cover all.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To assists better post-complete configuration. ( show run post output.)&lt;/P&gt;
&lt;P&gt;what is the IP address you trying to SSH to ASA ?&lt;/P&gt;</description>
      <pubDate>Sun, 28 Feb 2021 14:29:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4299006#M1078865</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-02-28T14:29:04Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 - no SSH possible</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4299009#M1078866</link>
      <description>&lt;P&gt;Please share the output of:&lt;/P&gt;
&lt;PRE&gt;show asp table socket | i 22&lt;/PRE&gt;</description>
      <pubDate>Sun, 28 Feb 2021 14:31:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4299009#M1078866</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-02-28T14:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 - no SSH possible</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4299016#M1078869</link>
      <description>&lt;P&gt;I think the problem is you give the ip address and than you mentioned the subnet.&lt;/P&gt;
&lt;P&gt;asa(config)# ssh 192.168.1.1 255.255.255.0 inside&lt;BR /&gt;ERROR: % Ambiguous command: "ssh 192.168.1.0 255.255.255.0 inside"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;where as it has to be like thiks &lt;STRONG&gt;"ssh 192.168.1.0 255.255.255.0 inside_7" &lt;/STRONG&gt;not ssh 192.168.1.1 255.255.255.0 inside&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;now if you want only 192.168.1.1 to access the firewall on ssh than it has to be in this way 192.168.1.1 255.255.255.255 inside.&lt;/P&gt;</description>
      <pubDate>Sun, 28 Feb 2021 14:49:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4299016#M1078869</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2021-02-28T14:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 - no SSH possible</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4299183#M1078888</link>
      <description>&lt;P&gt;thanks for answer, try to reach with the application Putty the ASA&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;asa(config)# show asp table socket | i 22&lt;BR /&gt;TCP 040fb558 LISTEN 192.168.1.1:22 0.0.0.0:*&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;asa(config)# sh run ssh&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;ssh version 2&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;ssh 192.168.1.0 255.255.255.0 inside_7&lt;BR /&gt;ssh 192.168.1.1 255.255.255.255 inside_7&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/287680"&gt;@Sheraz.Salim&lt;/a&gt;&lt;/P&gt;&lt;P&gt;Sorry this was my error, hear reply:&lt;/P&gt;&lt;P&gt;asa(config)# ssh 192.168.1.1 255.255.255.0 inside&lt;BR /&gt;ERROR: % Ambiguous command: "ssh 192.168.1.1 255.255.255.0 inside"&lt;/P&gt;&lt;P&gt;this FW are new... but have also other strange problem..... SSH are not reachable (Network Connection refused)&lt;BR /&gt;Clients that are connected to ASA like ESXI, Printers, DNS Server are not pingable at all times !&lt;/P&gt;&lt;P&gt;if unplug Printer,Esx to other switch, Printer are pingable, if plugin back to ASA, for first the Printer, Esxi and all other Clients are pingable, after a certain time, the printer, Esxi cannot be reached again.&lt;/P&gt;&lt;P&gt;G1/1 Outside - WAN&lt;BR /&gt;G1/2 INSIDE - Switch to other floor&lt;BR /&gt;G1/4 INSIDE - Printer&lt;BR /&gt;G1/5 INSIDE - ESXI&lt;BR /&gt;G1/6 INSIDE - DNS&lt;BR /&gt;G1/7 INSIDE - other Server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bevor i had Juniper and Forti, and newer, newer i had problem like this &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;also attached the ASA Config, thanks for possible answer&lt;BR /&gt;Mauri&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 07:24:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4299183#M1078888</guid>
      <dc:creator>Maurizio Caloro</dc:creator>
      <dc:date>2021-03-01T07:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 - no SSH possible</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4299204#M1078889</link>
      <description>&lt;P&gt;You asp table socket shows the ASA is only listening for incoming ssh from 192.168.1.1. Since that is the address of the BVI on the ASA, you need to remove that line in the config and makes sure the "ssh 192.168.1.0 255.255.255.0 inside" is the only ssh access restriction command in place.&lt;/P&gt;
&lt;P&gt;For your devices on the subnet not being reachable, please add "same-security-traffic permit intra-interface" to the configuration. This will allow the ASA to forward traffic back out the incoming interface for those hosts. They work for a while when moved from the other switch due to their being in the clients' arp caches and when that times out the ASA gets the requests for them and by default will not forward the traffic back ou the receiving interface.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Mar 2021 07:46:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4299204#M1078889</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-03-01T07:46:17Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 - no SSH possible</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4299374#M1078904</link>
      <description>&lt;P&gt;as suggested before :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;ssh 192.168.1.0 255.255.255.0 inside_7   (inside most people uses , if this is your only insde interface that should work)
no ssh 192.168.1.1 255.255.255.255 inside_7  - you do not need this one since above subnet cover all.&lt;/PRE&gt;</description>
      <pubDate>Mon, 01 Mar 2021 14:45:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4299374#M1078904</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-03-01T14:45:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 - no SSH possible</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4299739#M1078921</link>
      <description>&lt;P&gt;Hello Everyone&lt;/P&gt;&lt;P&gt;now reset the FW with "&lt;EM&gt;&lt;STRONG&gt;config factory-default&lt;/STRONG&gt;&lt;/EM&gt;" ok.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Encryption-DES : Enabled perpetual&lt;BR /&gt;Encryption-3DES-AES : Enabled perpetual&lt;/P&gt;&lt;P&gt;asa(config)# show run all ssh&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;ssh version 2&lt;BR /&gt;ssh cipher encryption medium&lt;BR /&gt;ssh cipher integrity high&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;BR /&gt;ssh 192.168.1.0 255.255.255.0 inside_7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but ssh stil are closed, connection refused.&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 06:46:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4299739#M1078921</guid>
      <dc:creator>Maurizio Caloro</dc:creator>
      <dc:date>2021-03-02T06:46:35Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5506 - no SSH possible</title>
      <link>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4299861#M1078925</link>
      <description>&lt;P&gt;After resetting did you configure below :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="pre codeblock"&gt;&lt;CODE&gt;aaa authentication ssh console LOCAL&lt;/CODE&gt;&lt;BR /&gt;username XXXX passowrd&lt;/PRE&gt;
&lt;P&gt;please post the complete config again, show run, also what client you using.&lt;/P&gt;
&lt;P&gt;are you able to ping 192.168.1.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Quick question is this your intention of BVI with inside_1 to 7&amp;nbsp; (since we see this is a bug) - it automatically creates.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;read this post :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.petenetlive.com/KB/Article/0001422" target="_blank"&gt;https://www.petenetlive.com/KB/Article/0001422&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;in that case, still, you need to use the inside interface here. Try below :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;no ssh 192.168.1.0 255.255.255.0 inside_7&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;ssh 192.168.1.0 255.255.255.0 inside&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Mar 2021 09:58:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5506-no-ssh-possible/m-p/4299861#M1078925</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-03-02T09:58:52Z</dc:date>
    </item>
  </channel>
</rss>

