<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FPR1010 running asa software. ASDM not authenticating from outside in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5264406#M1119757</link>
    <description>&lt;P&gt;Sorry everyone for not replying sooner. Got a bit ill and taken out of service. So it would seem that after updating the firmware on an ASA5506X to the latest version also has created this same problem. Can authenticate from inside and from VPN, but can not authenticate from outside. The outside is permitted and was working before the update. It does connect but just gets a username/password error. I will be doing some debug captures later this week and can post them. But it would seem that password authentication broke with the latest version of the firmware/ASDM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 24 Feb 2025 20:09:11 GMT</pubDate>
    <dc:creator>troyb</dc:creator>
    <dc:date>2025-02-24T20:09:11Z</dc:date>
    <item>
      <title>FPR1010 running asa software. ASDM not authenticating from outside.</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5254427#M1119197</link>
      <description>&lt;P&gt;Has anyone ran into the issue whereby you can use the ASDM on an FPR1010 running asa software from the inside LAN and it works fine, but from outside, it connects but you get a password error? I see this on two different FPR units.&lt;/P&gt;&lt;P&gt;I could understand if it was just not connecting as this&amp;nbsp; would be an issue with the device not setup for remote management. But it is setup and it does connect and it comes back with login failed. Enter username and password.&lt;/P&gt;&lt;P&gt;Units are current on their firmware.&lt;/P&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Troyb&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 19:34:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5254427#M1119197</guid>
      <dc:creator>troyb</dc:creator>
      <dc:date>2025-01-29T19:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: FPR1010 running asa software. ASDM not authenticating from outside</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5254429#M1119198</link>
      <description>&lt;P&gt;Can I see aaa config in your ASA&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 19:41:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5254429#M1119198</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-29T19:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: FPR1010 running asa software. ASDM not authenticating from outside</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5254455#M1119199</link>
      <description>&lt;P&gt;aaa authentication http console LOCAL&lt;BR /&gt;aaa authentication ssh console LOCAL&lt;BR /&gt;aaa authentication login-history&lt;/P&gt;&lt;P&gt;There are aaa servers configured but are only used for VPN, Cisco duo and LDAP.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jan 2025 20:38:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5254455#M1119199</guid>
      <dc:creator>troyb</dc:creator>
      <dc:date>2025-01-29T20:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: FPR1010 running asa software. ASDM not authenticating from outside</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5254502#M1119207</link>
      <description>&lt;P&gt;hey can you double check if you have enable the http access and also enable at outside interface.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;http server enable
http &amp;lt;outside-interface-IP&amp;gt; &amp;lt;subnet-mask&amp;gt; &amp;lt;outside-interface&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;also I beleive you the problem you're describing, where ASDM works fine from the inside LAN but fails with a password error from the outside, is likely related to the management-access configuration so try this command&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;management-access inside
http server enable
http 0.0.0.0 0.0.0.0 outside
http 0.0.0.0 0.0.0.0 inside&lt;/LI-CODE&gt;&lt;P&gt;if you still having issues in that case best is to collect the logs via debugs.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;debug aaa authentication
debug webvpn 255
!
show logging&lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 29 Jan 2025 22:50:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5254502#M1119207</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2025-01-29T22:50:29Z</dc:date>
    </item>
    <item>
      <title>Re: FPR1010 running asa software. ASDM not authenticating from outside</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5255024#M1119249</link>
      <description>&lt;P&gt;Share these&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Show run http&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Show asp table socket&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Debug http 10 &amp;lt;&amp;lt;- this optional&lt;/P&gt;
&lt;P&gt;Debug asdm history 10&lt;/P&gt;
&lt;P&gt;Capture asdm interface outside match tcp host &amp;lt;asa ip&amp;gt; eq 443 &amp;lt;host ip&amp;gt;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jan 2025 20:28:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5255024#M1119249</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-30T20:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: FPR1010 running asa software. ASDM not authenticating from outside</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5264406#M1119757</link>
      <description>&lt;P&gt;Sorry everyone for not replying sooner. Got a bit ill and taken out of service. So it would seem that after updating the firmware on an ASA5506X to the latest version also has created this same problem. Can authenticate from inside and from VPN, but can not authenticate from outside. The outside is permitted and was working before the update. It does connect but just gets a username/password error. I will be doing some debug captures later this week and can post them. But it would seem that password authentication broke with the latest version of the firmware/ASDM.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Feb 2025 20:09:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5264406#M1119757</guid>
      <dc:creator>troyb</dc:creator>
      <dc:date>2025-02-24T20:09:11Z</dc:date>
    </item>
    <item>
      <title>Re: FPR1010 running asa software. ASDM not authenticating from outside</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5264743#M1119771</link>
      <description>&lt;P&gt;Here is a datapoint. I was logged in via ASDM from an machine on the inside and watching the logs. Then while watching the logs, I attempted to connect to the same ASA from a machine on the outside that is in the ASDM allowed IP block with the same username and password that I am using with the one I am logged in with on the inside. It logged the reason as invalid password.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2025-02-25 at 9.05.38 AM.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/240546iF746889964418CA9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2025-02-25 at 9.05.38 AM.png" alt="Screenshot 2025-02-25 at 9.05.38 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 17:14:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5264743#M1119771</guid>
      <dc:creator>troyb</dc:creator>
      <dc:date>2025-02-25T17:14:20Z</dc:date>
    </item>
    <item>
      <title>Re: FPR1010 running asa software. ASDM not authenticating from outside</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5264815#M1119775</link>
      <description>&lt;P&gt;prior to the upgrade it was working since you done the upgrade its stop working. what were the software of ASA version prior to upgrade and whats the version post upgrade?&lt;/P&gt;&lt;P&gt;also could you confirm you running ASA-5506X or FPR101?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 20:07:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5264815#M1119775</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2025-02-25T20:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: FPR1010 running asa software. ASDM not authenticating from outside</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5264817#M1119777</link>
      <description>&lt;P&gt;what is the ASDM version you on and what is the software ASA code running? show your configuration "show run all http"&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 20:13:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5264817#M1119777</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2025-02-25T20:13:21Z</dc:date>
    </item>
    <item>
      <title>Re: FPR1010 running asa software. ASDM not authenticating from outside</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5264827#M1119779</link>
      <description>&lt;P&gt;On the only working FRP1010, we are running 9.14(2)15 with ASDM 7.14(1). On the FPR1010 units not working, they are running 9.18(4)40 or newer with ASDM 7.22(1). On the 5506x that stopped working after upgrade, it was running 9.8(4)25 and ASDM 7.10(1) and now it is running 9.16(4)76 and ASDM of 7.22(1).&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 20:36:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5264827#M1119779</guid>
      <dc:creator>troyb</dc:creator>
      <dc:date>2025-02-25T20:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: FPR1010 running asa software. ASDM not authenticating from outside</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5264828#M1119780</link>
      <description>&lt;P&gt;ASA5506 is EOL/EOS interesting I noted on-ward 9.14 ASDM outside is not working in your case. have you tested doing SSH from outside interface just tying to narrow down the problem.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 20:44:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5264828#M1119780</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2025-02-25T20:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: FPR1010 running asa software. ASDM not authenticating from outside</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5264830#M1119781</link>
      <description>Yes. SSH works fine from the outside. It is used by our config backup system. I am able to ssh using my same username and password that works inside via ssh and asdm on the outside with no issues. Just asdm that no longer authenticates.&lt;BR /&gt;</description>
      <pubDate>Tue, 25 Feb 2025 20:49:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5264830#M1119781</guid>
      <dc:creator>troyb</dc:creator>
      <dc:date>2025-02-25T20:49:08Z</dc:date>
    </item>
    <item>
      <title>Re: FPR1010 running asa software. ASDM not authenticating from outside</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5264833#M1119782</link>
      <description>&lt;P&gt;thats seem to be some bug behaviour. you can SSH same username and password but when using ASDM you have issue/s. Try using different ASDM version.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Feb 2025 20:55:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5264833#M1119782</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2025-02-25T20:55:05Z</dc:date>
    </item>
    <item>
      <title>Re: FPR1010 running asa software. ASDM not authenticating from outside</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5265787#M1119816</link>
      <description>&lt;P&gt;Okay, so here is what I was able to determine. The units (both FPR and 5506x) that are not working are resolved by turning off or removing from the config aaa authentication http console LOCAL resolves the issue. However the ones that were working and running earlier versions have those set and break ASDM if removed. This is the case for all FPR1010 and the 5506X except for one. We have one FPR1010 that is running version 9.16(3)23 and ASDM 7.19(1). This one if this setting is removed, can no longer connect at all via ASMD, not just get a password error.&lt;/P&gt;&lt;P&gt;So this looks like a bug where local authentication setting is reversed for ASDM authentication and is broken all together in the version of firmware or ASDM that is running on the one FPR1010 unit. I should note that SSH seems to work just fine with it enabled and breaks if you disable it, so no consistency in the code it would seem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/423511"&gt;@troyb&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Has anyone ran into the issue whereby you can use the ASDM on an FPR1010 running asa software from the inside LAN and it works fine, but from outside, it connects but you get a password error? I see this on two different FPR units.&lt;/P&gt;&lt;P&gt;I could understand if it was just not connecting as this&amp;nbsp; would be an issue with the device not setup for remote management. But it is setup and it does connect and it comes back with login failed. Enter username and password.&lt;/P&gt;&lt;P&gt;Units are current on their firmware.&lt;/P&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Troyb&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Thu, 27 Feb 2025 23:27:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5265787#M1119816</guid>
      <dc:creator>troyb</dc:creator>
      <dc:date>2025-02-27T23:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: FPR1010 running asa software. ASDM not authenticating from outside</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5265877#M1119820</link>
      <description>&lt;P&gt;If you have enabled SSL VPN on device, in that case, you cannot use ASDM to OUTSIDE interface as it uses same 443 port as VPN service.&lt;BR /&gt;to fix it, just issue the command -&amp;nbsp;&lt;SPAN&gt;http server enable 8443&lt;/SPAN&gt;&lt;BR /&gt;and in ASDM use vpn.company.com:8443&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 07:01:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5265877#M1119820</guid>
      <dc:creator>s_SiD_s</dc:creator>
      <dc:date>2025-02-28T07:01:40Z</dc:date>
    </item>
    <item>
      <title>Re: FPR1010 running asa software. ASDM not authenticating from outside</title>
      <link>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5266089#M1119825</link>
      <description>&lt;P&gt;Hello sSiDiUSs,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the Anyconnect secure client service and ASDM are not impacting each other. We have 40+ of the ASAs deployed and 10 FPR1010 units deployed. None have needed the ports changed to use ASDM and Anyconnect. This appears to be a bug in the firmware/ASDM image as inverting the setting for local authentication on the impacted units resolves the issue. The ASDM is using local authentication accounts and the Anyconnect is using radius/LDAP and Duo 2fa authentication. Having the Local authentication set on on these impacted units causes a password error (invalid password from local database) yet if you disable local authentication for the impacted units, Local authentication works for ASDM. Either setting does not impact the Anyconnect service.&lt;/P&gt;&lt;P&gt;However we do have one FPR1010 that is running a version that is between the older ones that work and the ones that have this bug that gets password errors from the local database when enabled and flat out will not connect at all if disabled (Gets connection timed out/No response). So will be upgrading this one unit to the current version which the others are running and verify. If all works with the inverted settings, then will open a bug case with TAC as I will have all the data needed to reproduce.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you for your response.&lt;/P&gt;&lt;P&gt;Best,&lt;/P&gt;&lt;P&gt;-Troy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 17:10:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fpr1010-running-asa-software-asdm-not-authenticating-from/m-p/5266089#M1119825</guid>
      <dc:creator>troyb</dc:creator>
      <dc:date>2025-02-28T17:10:54Z</dc:date>
    </item>
  </channel>
</rss>

