<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic It seems it's not liking the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asdm-connection-problems/m-p/3075136#M136236</link>
    <description>&lt;P&gt;It seems it's not liking the ASA self-signed certificate. While I usually generate a permanent vs. temporary one, the latter should work as well.&lt;/P&gt;
&lt;P&gt;Depending on your PC settings, you may need to trust the ASA "site" in Java security.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also notice you have some next generation encryption settings in your SSL. Can you confirm if you created an RSA key to be used for your self-signed certificate? If you don't have that and instead are using an ecdsa key that may be causing the error.&lt;/P&gt;</description>
    <pubDate>Wed, 26 Apr 2017 13:55:56 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2017-04-26T13:55:56Z</dc:date>
    <item>
      <title>asdm connection problems</title>
      <link>https://community.cisco.com/t5/network-security/asdm-connection-problems/m-p/3075133#M136231</link>
      <description>&lt;P&gt;Hi there,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am struggling to browse to ASDM which just hangs. See below my current setup though i have tried with other version of ASA and ASDM&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ciscoasa(config)# show asdm image&lt;BR /&gt;Device Manager image file, disk0:/asdm-771-150.bin&lt;BR /&gt;ciscoasa(config)# &lt;BR /&gt;ciscoasa(config)# sh ver&lt;/P&gt;
&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.4(1) &lt;BR /&gt;Device Manager Version 7.7(1)150&lt;/P&gt;
&lt;P&gt;Compiled on Sat 21-Mar-15 11:43 PDT by builders&lt;BR /&gt;System image file is "boot:/asa941-smp-k8.bin"&lt;BR /&gt;Config file at boot was "startup-config"&lt;/P&gt;
&lt;P&gt;ciscoasa up 14 hours 9 mins&lt;/P&gt;
&lt;P&gt;Hardware: ASAv, 2048 MB RAM, CPU Pentium II 3591 MHz,&lt;BR /&gt;Internal ATA Compact Flash, 8192MB&lt;BR /&gt;Slot 1: ATA Compact Flash, 8192MB&lt;BR /&gt;BIOS Flash Firmware Hub @ 0x0, 0KB&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt; 0: Ext: Management0/0 : address is 00a2.56fd.0800, irq 11&lt;BR /&gt; 1: Ext: GigabitEthernet0/0 : address is 00a2.56fd.0801, irq 11&lt;BR /&gt; 2: Ext: GigabitEthernet0/1 : address is 00a2.56fd.0802, irq 10&lt;BR /&gt; 3: Ext: GigabitEthernet0/2 : address is 00a2.56fd.0803, irq 10&lt;BR /&gt; 4: Ext: GigabitEthernet0/3 : address is 00a2.56fd.0804, irq 11&lt;BR /&gt; 5: Ext: GigabitEthernet0/4 : address is 00a2.56fd.0805, irq 11&lt;BR /&gt; 6: Ext: GigabitEthernet0/5 : address is 00a2.56fd.0806, irq 10&lt;BR /&gt; 7: Ext: GigabitEthernet0/6 : address is 00a2.56fd.0807, irq 10&lt;BR /&gt; &lt;BR /&gt;License mode: Smart Licensing&lt;BR /&gt;ASAv Platform License State: Unlicensed&lt;BR /&gt;No active entitlement: no feature tier and no throughput level configured&lt;/P&gt;
&lt;P&gt;Licensed features for this platform:&lt;BR /&gt;Maximum Physical Interfaces : 10 perpetual&lt;BR /&gt;Maximum VLANs : 50 perpetual&lt;BR /&gt;Inside Hosts : Unlimited perpetual&lt;BR /&gt;Failover : Active/Standby perpetual&lt;BR /&gt;Encryption-DES : Enabled perpetual&lt;BR /&gt;Encryption-3DES-AES : Enabled perpetual&lt;BR /&gt;Security Contexts : 0 perpetual&lt;BR /&gt;GTP/GPRS : Disabled perpetual&lt;BR /&gt;AnyConnect Premium Peers : 2 perpetual&lt;BR /&gt;AnyConnect Essentials : Disabled perpetual&lt;BR /&gt;Other VPN Peers : 250 perpetual&lt;BR /&gt;Total VPN Peers : 250 perpetual&lt;BR /&gt;Shared License : Disabled perpetual&lt;BR /&gt;AnyConnect for Mobile : Disabled perpetual&lt;BR /&gt;AnyConnect for Cisco VPN Phone : Disabled perpetual&lt;BR /&gt;Advanced Endpoint Assessment : Disabled perpetual&lt;BR /&gt;Total UC Proxy Sessions : 2 perpetual&lt;BR /&gt;Botnet Traffic Filter : Enabled perpetual&lt;BR /&gt;Cluster : Disabled perpetual&lt;/P&gt;
&lt;P&gt;Licensing mode is Smart Licensing&lt;/P&gt;
&lt;P&gt;Serial Number: 9AAF5L9CT3R&lt;/P&gt;
&lt;P&gt;Image type : Release&lt;BR /&gt;Key version : A&lt;/P&gt;
&lt;P&gt;Configuration last modified by enable_15 at 22:39:29.418 UTC Mon Apr 24 2017&lt;BR /&gt;ciscoasa(config)#&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ciscoasa(config)# show run all ssl &lt;BR /&gt;ssl server-version tlsv1.2&lt;BR /&gt;ssl client-version tlsv1.2&lt;BR /&gt;ssl cipher default custom "DES-CBC3-SHA:AES128-SHA:RC4-MD5:RC4-SHA"&lt;BR /&gt;ssl cipher tlsv1 custom "DES-CBC3-SHA:AES128-SHA:RC4-MD5:RC4-SHA"&lt;BR /&gt;ssl cipher tlsv1.1 all&lt;BR /&gt;ssl cipher tlsv1.2 custom "DES-CBC3-SHA:AES128-SHA:RC4-MD5:RC4-SHA"&lt;BR /&gt;ssl cipher dtlsv1 custom "DES-CBC3-SHA:AES128-SHA:RC4-MD5:RC4-SHA"&lt;BR /&gt;ssl dh-group group2&lt;BR /&gt;ssl ecdh-group group19&lt;BR /&gt;ssl certificate-authentication fca-timeout 2&lt;BR /&gt;ciscoasa(config)#&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;%ASA-6-725001: Starting SSL handshake with client outside:10.0.0.2/53428 to 10.0.0.252/443 for TLS session&lt;BR /&gt;%ASA-6-725003: SSL client outside:10.0.0.2/53428 to 10.0.0.252/443 request to resume previous session&lt;BR /&gt;%ASA-6-725002: Device completed SSL handshake with client outside:10.0.0.2/53428 to 10.0.0.252/443 for TLSv1.2 session&lt;BR /&gt;%ASA-6-302014: Teardown TCP connection 63 for outside:10.0.0.2/53425 to identity:10.0.0.252/443 duration 0:00:00 bytes 145 TCP Reset-I&lt;BR /&gt;%ASA-6-725007: SSL session with client outside:10.0.0.2/53426 to 10.0.0.252/443 terminated&lt;BR /&gt;%ASA-6-302014: Teardown TCP connection 64 for outside:10.0.0.2/53426 to identity:10.0.0.252/443 duration 0:00:00 bytes 384 TCP FINs&lt;BR /&gt;%ASA-6-725007: SSL session with client outside:10.0.0.2/53427 to 10.0.0.252/443 terminated&lt;BR /&gt;%ASA-6-302014: Teardown TCP connection 65 for outside:10.0.0.2/53427 to identity:10.0.0.252/443 duration 0:00:00 bytes 145 TCP Reset-I&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:15:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-connection-problems/m-p/3075133#M136231</guid>
      <dc:creator>christopher.martin.2</dc:creator>
      <dc:date>2019-03-12T09:15:44Z</dc:date>
    </item>
    <item>
      <title>What Java version is</title>
      <link>https://community.cisco.com/t5/network-security/asdm-connection-problems/m-p/3075134#M136232</link>
      <description>&lt;P&gt;What Java version is installed on your workstation?&lt;/P&gt;
&lt;P&gt;Please open the Java console when attempting to connect and share the outut you get from it.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2017 00:31:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-connection-problems/m-p/3075134#M136232</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-04-25T00:31:13Z</dc:date>
    </item>
    <item>
      <title>Hi marvin,</title>
      <link>https://community.cisco.com/t5/network-security/asdm-connection-problems/m-p/3075135#M136234</link>
      <description>&lt;P&gt;Hi marvin,&lt;/P&gt;
&lt;P&gt;Thankyou for offering to help!&lt;/P&gt;
&lt;P&gt;Im using 1.8.0_131-b11.&lt;/P&gt;
&lt;P&gt;I enable&amp;nbsp;the java console but it did not open when i initiated a connection to the ASA. On firefox i used the browser console and got below errors&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;10.0.0.252:443 uses an invalid security certificate.&lt;/P&gt;
&lt;P&gt;The certificate is not trusted because it is self-signed.&lt;BR /&gt;The certificate is only valid for ASA Temporary Self Signed Certificate&lt;/P&gt;
&lt;P&gt;Error code: &amp;lt;a id="errorCode" title="SEC_ERROR_UNKNOWN_ISSUER"&amp;gt;SEC_ERROR_UNKNOWN_ISSUER&amp;lt;/a&amp;gt;&lt;BR /&gt; &amp;lt;unknown&amp;gt;&lt;BR /&gt;TypeError: ownerDoc.location is null content.js:449:7&lt;BR /&gt;TypeError: docShell is null&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also, the browser console created jarfile logs with below:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;sendAsyncMessage("Browser:CertExceptionError", {
      location: ownerDoc.location.href,
      elementId: targetElement.getAttribute("id"),
      isTopFrame: (ownerDoc.defaultView.parent === ownerDoc.defaultView),
      securityInfoAsString: serializedSecurityInfo
    });
  },&lt;/PRE&gt;</description>
      <pubDate>Wed, 26 Apr 2017 12:49:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-connection-problems/m-p/3075135#M136234</guid>
      <dc:creator>christopher.martin.2</dc:creator>
      <dc:date>2017-04-26T12:49:29Z</dc:date>
    </item>
    <item>
      <title>It seems it's not liking the</title>
      <link>https://community.cisco.com/t5/network-security/asdm-connection-problems/m-p/3075136#M136236</link>
      <description>&lt;P&gt;It seems it's not liking the ASA self-signed certificate. While I usually generate a permanent vs. temporary one, the latter should work as well.&lt;/P&gt;
&lt;P&gt;Depending on your PC settings, you may need to trust the ASA "site" in Java security.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also notice you have some next generation encryption settings in your SSL. Can you confirm if you created an RSA key to be used for your self-signed certificate? If you don't have that and instead are using an ecdsa key that may be causing the error.&lt;/P&gt;</description>
      <pubDate>Wed, 26 Apr 2017 13:55:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-connection-problems/m-p/3075136#M136236</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-04-26T13:55:56Z</dc:date>
    </item>
  </channel>
</rss>

