<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic intermittent loss of ssh access, asa does not listen on 22 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/intermittent-loss-of-ssh-access-asa-does-not-listen-on-22/m-p/5254813#M1119235</link>
    <description>&lt;P&gt;I just got kind of similar issue to&amp;nbsp;&lt;SPAN&gt;CSCwb94312&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/network-security/asa-unable-to-configure-service-on-port-22/td-p/1742513" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/network-security/asa-unable-to-configure-service-on-port-22/td-p/1742513&lt;/A&gt;&lt;BR /&gt;or&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/cisco-software-discussions/lost-ssh-access-to-asa-after-upgrading-from-9-15-1-1-to-9-20-2-2/td-p/4992216" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/cisco-software-discussions/lost-ssh-access-to-asa-after-upgrading-from-9-15-1-1-to-9-20-2-2/td-p/4992216&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;but not exactly:&lt;BR /&gt;out of the blue and with no change made (no upgrade so not the case from the second link)&lt;BR /&gt;- I cannot ssh (telnet, ASDM work)&lt;BR /&gt;I did not reboot but I deleted and re-added ssh and it works again... for some time (up to few hours)&lt;BR /&gt;Hence ssh configuration is still possible unlike in the bug&amp;nbsp;&lt;SPAN&gt;CSCwb94312&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;weird thing:&amp;nbsp;seems like ASA does not listen on port 22&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kewwa_0-1738246896134.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238796i050273C3960584A6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kewwa_0-1738246896134.png" alt="kewwa_0-1738246896134.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;However the command above was run from a very ssh session so for sure the session was established.&lt;BR /&gt;Also I played adding and deleting telnet and it "updates" - I can see ASA listening and not listening to 23 accordingly.&lt;BR /&gt;However configuring and deleting ssh does not change anything&lt;/P&gt;
&lt;P&gt;at the same time I have ssh in PAT table&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kewwa_1-1738246945288.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238797i2758CFB32D5D408C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kewwa_1-1738246945288.png" alt="kewwa_1-1738246945288.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;To give the full picture: when ssh does not work:&lt;BR /&gt;-the authentication works fine (I do not have log but basically the admin is correctly authenticated by a remote server&lt;BR /&gt;- and the syn arrives at ASA (pcap from ASA) but never gets a reply&lt;/P&gt;
&lt;P&gt;Version is 9.20(3)7&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jan 2025 14:50:31 GMT</pubDate>
    <dc:creator>kewwa</dc:creator>
    <dc:date>2025-01-30T14:50:31Z</dc:date>
    <item>
      <title>intermittent loss of ssh access, asa does not listen on 22</title>
      <link>https://community.cisco.com/t5/network-security/intermittent-loss-of-ssh-access-asa-does-not-listen-on-22/m-p/5254813#M1119235</link>
      <description>&lt;P&gt;I just got kind of similar issue to&amp;nbsp;&lt;SPAN&gt;CSCwb94312&lt;/SPAN&gt;&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/network-security/asa-unable-to-configure-service-on-port-22/td-p/1742513" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/network-security/asa-unable-to-configure-service-on-port-22/td-p/1742513&lt;/A&gt;&lt;BR /&gt;or&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/cisco-software-discussions/lost-ssh-access-to-asa-after-upgrading-from-9-15-1-1-to-9-20-2-2/td-p/4992216" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/cisco-software-discussions/lost-ssh-access-to-asa-after-upgrading-from-9-15-1-1-to-9-20-2-2/td-p/4992216&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;but not exactly:&lt;BR /&gt;out of the blue and with no change made (no upgrade so not the case from the second link)&lt;BR /&gt;- I cannot ssh (telnet, ASDM work)&lt;BR /&gt;I did not reboot but I deleted and re-added ssh and it works again... for some time (up to few hours)&lt;BR /&gt;Hence ssh configuration is still possible unlike in the bug&amp;nbsp;&lt;SPAN&gt;CSCwb94312&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;weird thing:&amp;nbsp;seems like ASA does not listen on port 22&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kewwa_0-1738246896134.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238796i050273C3960584A6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kewwa_0-1738246896134.png" alt="kewwa_0-1738246896134.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;However the command above was run from a very ssh session so for sure the session was established.&lt;BR /&gt;Also I played adding and deleting telnet and it "updates" - I can see ASA listening and not listening to 23 accordingly.&lt;BR /&gt;However configuring and deleting ssh does not change anything&lt;/P&gt;
&lt;P&gt;at the same time I have ssh in PAT table&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kewwa_1-1738246945288.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/238797i2758CFB32D5D408C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kewwa_1-1738246945288.png" alt="kewwa_1-1738246945288.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;To give the full picture: when ssh does not work:&lt;BR /&gt;-the authentication works fine (I do not have log but basically the admin is correctly authenticated by a remote server&lt;BR /&gt;- and the syn arrives at ASA (pcap from ASA) but never gets a reply&lt;/P&gt;
&lt;P&gt;Version is 9.20(3)7&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 14:50:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intermittent-loss-of-ssh-access-asa-does-not-listen-on-22/m-p/5254813#M1119235</guid>
      <dc:creator>kewwa</dc:creator>
      <dc:date>2025-01-30T14:50:31Z</dc:date>
    </item>
    <item>
      <title>Re: intermittent loss of ssh access, asa does not listen on 22</title>
      <link>https://community.cisco.com/t5/network-security/intermittent-loss-of-ssh-access-asa-does-not-listen-on-22/m-p/5254831#M1119236</link>
      <description>&lt;P&gt;Can I see&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Show run nat&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 15:02:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/intermittent-loss-of-ssh-access-asa-does-not-listen-on-22/m-p/5254831#M1119236</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-30T15:02:00Z</dc:date>
    </item>
  </channel>
</rss>

