<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot access FXOS CLI via SSH anymore in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-access-fxos-cli-via-ssh-anymore/m-p/4562852#M1087886</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;Thank you for the suggestion. I tried to ssh from FTD expert mode to the chassis management address, but I'm still getting conenction refused. I will wait for console access.&lt;/P&gt;&lt;P&gt;Is the access list in fxos different from the one I see in Chassis manager web gui? The one I have there looks like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/145127i1B624F88A5E0F554/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 03 Mar 2022 09:49:46 GMT</pubDate>
    <dc:creator>Chess Norris</dc:creator>
    <dc:date>2022-03-03T09:49:46Z</dc:date>
    <item>
      <title>Cannot access FXOS CLI via SSH anymore</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-fxos-cli-via-ssh-anymore/m-p/4561920#M1087858</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;This morning I was trying to SSH into FXOS on two Firepower 4100 devices. I have been able to SSH into those devices before, but it was probably quite a while ago since i did it the last time.&lt;/P&gt;&lt;P&gt;I now get&amp;nbsp;a "The remote system refused the connection" message, when I am trying to use SSH. I still can access the web interface, and I've verified the SSH is enabled and that there are no access rules that would prevent SSH access.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any other way I can access the CLI? If I SSH directly to the FTD device, it takes me directly to the LINA CLI but I don't have the option to type "connect fxos".&lt;/P&gt;&lt;P&gt;A console connection might be my only option here, but the device is located in another country and it will probably take a while to get someone on site.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Chess&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 09:01:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-fxos-cli-via-ssh-anymore/m-p/4561920#M1087858</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2022-03-02T09:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access FXOS CLI via SSH anymore</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-fxos-cli-via-ssh-anymore/m-p/4562231#M1087867</link>
      <description>&lt;P&gt;I can only think that the ssh access list in fxos might have been enabled.&lt;/P&gt;
&lt;P&gt;Short of console access, can you try sshing to the chassis management address from an expert mode (Linux shell) session on the FTD instance?&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 16:20:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-fxos-cli-via-ssh-anymore/m-p/4562231#M1087867</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-03-02T16:20:36Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access FXOS CLI via SSH anymore</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-fxos-cli-via-ssh-anymore/m-p/4562852#M1087886</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;Thank you for the suggestion. I tried to ssh from FTD expert mode to the chassis management address, but I'm still getting conenction refused. I will wait for console access.&lt;/P&gt;&lt;P&gt;Is the access list in fxos different from the one I see in Chassis manager web gui? The one I have there looks like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/145127i1B624F88A5E0F554/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 09:49:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-fxos-cli-via-ssh-anymore/m-p/4562852#M1087886</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2022-03-03T09:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access FXOS CLI via SSH anymore</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-fxos-cli-via-ssh-anymore/m-p/4562853#M1087887</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/256705"&gt;@Chess Norris&lt;/a&gt; the settings you shared are the same as what one would configure from the cli. So that looks good.&lt;/P&gt;
&lt;P&gt;If your FTD management address is in the same subnet as the chassis management interface, then a middleware box would not be the problem.&lt;/P&gt;
&lt;P&gt;So it's a bit of a mystery still - please let us know what you find out.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Mar 2022 10:00:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-fxos-cli-via-ssh-anymore/m-p/4562853#M1087887</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2022-03-03T10:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot access FXOS CLI via SSH anymore</title>
      <link>https://community.cisco.com/t5/network-security/cannot-access-fxos-cli-via-ssh-anymore/m-p/4781652#M1098126</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/256705"&gt;@Chess Norris&lt;/a&gt;Does the error message include:&lt;BR /&gt;Unable to negotiate with &amp;lt;IP Address&amp;gt; port 22: no matching key exchange method found.&amp;nbsp; Their offer: &amp;lt;cipher&amp;gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;If so, you may need to explicitly include the "KexAlgorithms" stated in the &amp;lt;cipher&amp;gt;.&lt;BR /&gt;Example: ssh -oKexAlgorithms=+diffie-hellman-group14-sha1 &amp;lt;IP Address&amp;gt;&lt;/P&gt;&lt;P&gt;Then later update your ssh-server config via CLI and/or FCM to include additional algorithms.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Feb 2023 20:40:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-access-fxos-cli-via-ssh-anymore/m-p/4781652#M1098126</guid>
      <dc:creator>councilm</dc:creator>
      <dc:date>2023-02-23T20:40:35Z</dc:date>
    </item>
  </channel>
</rss>

