<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH &amp;amp; HTTPS issue on Firepower 4100 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssh-amp-https-issue-on-firepower-4100/m-p/4456395#M1083201</link>
    <description>&lt;P&gt;I've had issues with 4100 and 9300 series not liking the strong password I used ( I did NOT select enforce strong password during bootstrap) and thus blocking logon via ssh or FCM subsequent to bootstrapping via console.&lt;/P&gt;
&lt;P&gt;My work around was to go back in and do the console-based password recovery procedure choosing a not quite so strong password. Then, once I was able to login via ssh, I was able to go back to the original strong password.&lt;/P&gt;</description>
    <pubDate>Sun, 29 Aug 2021 03:43:34 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2021-08-29T03:43:34Z</dc:date>
    <item>
      <title>SSH &amp; HTTPS issue on Firepower 4100</title>
      <link>https://community.cisco.com/t5/network-security/ssh-amp-https-issue-on-firepower-4100/m-p/4455841#M1083180</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;&lt;SPAN&gt;I am facing an issue with SSH/HTTPS management access on a Firepower 4100.&amp;nbsp; After un-boxing the device, I consoled in and ran through the initial setup.&amp;nbsp; I assigned the IP, subnet, hostname, default gateway, and IP blocks on the interface.&amp;nbsp; I am able to ping the chassis mgmt interface from a laptop on the same subnet.&amp;nbsp; From my laptop, I use putty to SSH in, I get a response, but using the same credentials that work for console access, it says access denied.&amp;nbsp; I can confirm that my IP is in the IP block list on the private subnet of: 10.200.1.x/24&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cisco1.png" style="width: 490px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/128957i25F94602C24284A3/image-size/large?v=v2&amp;amp;px=999" role="button" title="cisco1.png" alt="cisco1.png" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cisco2.png" style="width: 383px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/128958i50B046E22A46B106/image-size/large?v=v2&amp;amp;px=999" role="button" title="cisco2.png" alt="cisco2.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When I attempt to access the 4100 via https, I get the login page, but my credentials that work for console access, do not work for web access:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="cisco3.png" style="width: 414px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/128959i256A41AA42A1A64D/image-size/large?v=v2&amp;amp;px=999" role="button" title="cisco3.png" alt="cisco3.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The only network connectivity that I have to the appliance is to the chassis mgmt port.&amp;nbsp; I simply want SSH and/or HTTPS access.&amp;nbsp; I tried creating a 2nd admin user.&amp;nbsp; I have the same issue with that account.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Is there something simple that I am missing to SSH/HTTPS into the chassis management port?&amp;nbsp; I'm on version 2.4(1.101).&amp;nbsp; I have followed the&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/fp4100/firepower-4100-gsg/chassis_setup.html#id_69569" target="_self"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/quick_start/fp4100/firepower-4100-gsg/chassis_setup&lt;/A&gt;/&lt;A href="https://promokodik.net/" target="_self"&gt;promokodik.net&amp;nbsp;&lt;/A&gt; &amp;nbsp;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;According to the doc, after the initial configuration, one should be able to SSH in to the appliance.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 10:25:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-amp-https-issue-on-firepower-4100/m-p/4455841#M1083180</guid>
      <dc:creator>Jenny11</dc:creator>
      <dc:date>2021-08-27T10:25:07Z</dc:date>
    </item>
    <item>
      <title>Re: SSH &amp; HTTPS issue on Firepower 4100</title>
      <link>https://community.cisco.com/t5/network-security/ssh-amp-https-issue-on-firepower-4100/m-p/4455904#M1083185</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1233928"&gt;@Jenny11&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;This is a standard procedure, so everything you did looks fine to me. Yes, you should be able to authenticate with same account to SSH/Web/Console.&lt;/P&gt;&lt;P&gt;Try checking your users from console access with:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;scope security&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;show local-user&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;show local-user &lt;EM&gt;user&lt;/EM&gt; detail&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Also, please check your authentication configuration:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;scope security&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;show authentication&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Third option could be to try and reduce your password complexity, and try with something simple (perhaps some special character is not parsing properly, or causing troubles).&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;scope security&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;set enforce-strong-password no&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;commit&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;set password&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Finally, you are running really old FXOS version, so you should upgrade to more recent one (you might be hitting some bug from older releases).&lt;/P&gt;&lt;P&gt;BR,&lt;/P&gt;&lt;P&gt;Milos&lt;/P&gt;</description>
      <pubDate>Fri, 27 Aug 2021 12:44:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-amp-https-issue-on-firepower-4100/m-p/4455904#M1083185</guid>
      <dc:creator>Milos_Jovanovic</dc:creator>
      <dc:date>2021-08-27T12:44:22Z</dc:date>
    </item>
    <item>
      <title>Re: SSH &amp; HTTPS issue on Firepower 4100</title>
      <link>https://community.cisco.com/t5/network-security/ssh-amp-https-issue-on-firepower-4100/m-p/4456395#M1083201</link>
      <description>&lt;P&gt;I've had issues with 4100 and 9300 series not liking the strong password I used ( I did NOT select enforce strong password during bootstrap) and thus blocking logon via ssh or FCM subsequent to bootstrapping via console.&lt;/P&gt;
&lt;P&gt;My work around was to go back in and do the console-based password recovery procedure choosing a not quite so strong password. Then, once I was able to login via ssh, I was able to go back to the original strong password.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Aug 2021 03:43:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-amp-https-issue-on-firepower-4100/m-p/4456395#M1083201</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-08-29T03:43:34Z</dc:date>
    </item>
  </channel>
</rss>

