<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSH and ASDM not accessible in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssh-and-asdm-not-accessible/m-p/2979892#M149822</link>
    <description>&lt;P&gt;hello&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I hope you can help, we have an ASA 5550 model, and SSH &amp;amp; ASDM have been working fine for years now. But all of a sudden they have stop responding.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The firewall itself is working and still routing traffic to the internet. No ACL were changed on it either.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you please advise what troubleshooting i can potentially do from the console cable on the firewall to restart these services again.&lt;/P&gt;
&lt;P&gt;many thanks&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 08:17:50 GMT</pubDate>
    <dc:creator>upen desai</dc:creator>
    <dc:date>2019-03-12T08:17:50Z</dc:date>
    <item>
      <title>SSH and ASDM not accessible</title>
      <link>https://community.cisco.com/t5/network-security/ssh-and-asdm-not-accessible/m-p/2979892#M149822</link>
      <description>&lt;P&gt;hello&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I hope you can help, we have an ASA 5550 model, and SSH &amp;amp; ASDM have been working fine for years now. But all of a sudden they have stop responding.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The firewall itself is working and still routing traffic to the internet. No ACL were changed on it either.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you please advise what troubleshooting i can potentially do from the console cable on the firewall to restart these services again.&lt;/P&gt;
&lt;P&gt;many thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 08:17:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-and-asdm-not-accessible/m-p/2979892#M149822</guid>
      <dc:creator>upen desai</dc:creator>
      <dc:date>2019-03-12T08:17:50Z</dc:date>
    </item>
    <item>
      <title>Hello Mr. Desai,</title>
      <link>https://community.cisco.com/t5/network-security/ssh-and-asdm-not-accessible/m-p/2979893#M149823</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Hello Mr. Desai,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Can you post the output of &lt;STRONG&gt;show asp table socket&lt;/STRONG&gt; command ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;This command will return what connection the firewall is listening.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Best Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Alex Gutierrez.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 14:11:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-and-asdm-not-accessible/m-p/2979893#M149823</guid>
      <dc:creator>Alex D. Silva Gutierrez</dc:creator>
      <dc:date>2016-09-20T14:11:24Z</dc:date>
    </item>
    <item>
      <title>hello Alex</title>
      <link>https://community.cisco.com/t5/network-security/ssh-and-asdm-not-accessible/m-p/2979894#M149824</link>
      <description>&lt;P&gt;hello Alex&lt;/P&gt;
&lt;P&gt;thank you for coming back to me. I do have access to the console cable to the firewall and did a debug on the SSH service and got the following error.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Lut-ASAFirewall#&lt;BR /&gt;Device ssh opened successfully.&lt;BR /&gt;SSH1: SSH client: IP = '10.251.251.107' interface # = 2&lt;BR /&gt;SSH: host key initialised&lt;BR /&gt;SSH1: starting SSH control process&lt;BR /&gt;SSH1: Exchanging versions - SSH-1.99-Cisco-1.25&lt;/P&gt;
&lt;P&gt;SSH1: send SSH message: outdata is NULL&lt;BR /&gt;SSH1: Session disconnected by SSH server - error 0x3c "Time-out activated"&lt;BR /&gt;SSH1: send unsuccessful - status 0x3c&lt;/P&gt;
&lt;P&gt;Lut-ASAFirewall# sh asp drop&lt;/P&gt;
&lt;P&gt;Frame drop:&lt;BR /&gt; Bad IPSEC NATT packet (bad-ipsec-natt) 2&lt;BR /&gt; IPSEC tunnel is down (ipsec-tun-down) 4&lt;BR /&gt; Invalid encapsulation (invalid-encap) 19084&lt;BR /&gt; Invalid IP header (invalid-ip-header) 16&lt;BR /&gt; Invalid TCP Length (invalid-tcp-hdr-length) 38&lt;BR /&gt; Invalid UDP Length (invalid-udp-length) 67&lt;BR /&gt; No valid adjacency (no-adjacency) 452&lt;BR /&gt; No route to host (no-route) 4294&lt;BR /&gt; Flow is denied by configured rule (acl-drop) 513815804&lt;BR /&gt; Invalid SPI (np-sp-invalid-spi) 15604&lt;BR /&gt; First TCP packet not SYN (tcp-not-syn) 4373384&lt;BR /&gt; Bad TCP checksum (bad-tcp-cksum) 1&lt;BR /&gt; Bad TCP flags (bad-tcp-flags) 621&lt;BR /&gt; TCP Dual open denied (tcp-dual-open) 300&lt;BR /&gt; TCP data send after FIN (tcp-data-past-fin) 334&lt;BR /&gt; TCP failed 3 way handshake (tcp-3whs-failed) 487894&lt;BR /&gt; TCP RST/FIN out of order (tcp-rstfin-ooo) 2743470&lt;BR /&gt; TCP SEQ in SYN/SYNACK invalid (tcp-seq-syn-diff) 75477&lt;BR /&gt; TCP SYNACK on established conn (tcp-synack-ooo) 1105&lt;BR /&gt; TCP packet SEQ past window (tcp-seq-past-win) 1456851&lt;BR /&gt; TCP invalid ACK (tcp-invalid-ack) 1760&lt;BR /&gt; TCP ACK in 3 way handshake invalid (tcp-discarded-ooo) 6&lt;BR /&gt; TCP Out-of-Order packet buffer timeout (tcp-buffer-timeout) 1&lt;BR /&gt; TCP RST/SYN in window (tcp-rst-syn-in-win) 3281&lt;BR /&gt; TCP dup of packet in Out-of-Order queue (tcp-dup-in-queue) 74&lt;BR /&gt; TCP packet failed PAWS test (tcp-paws-fail) 71221&lt;BR /&gt; CTM returned error (ctm-error) 121&lt;BR /&gt; Slowpath security checks failed (sp-security-failed) 612638&lt;BR /&gt; ICMP Inspect seq num not matched (inspect-icmp-seq-num-not-matched) 9834&lt;BR /&gt; ICMP Error Inspect no existing conn (inspect-icmp-error-no-existing-conn) 52&lt;BR /&gt; DNS Inspect invalid packet (inspect-dns-invalid-pak) 7&lt;BR /&gt; DNS Inspect invalid domain label (inspect-dns-invalid-domain-label) 304&lt;BR /&gt; DNS Inspect packet too long (inspect-dns-pak-too-long) 103668&lt;BR /&gt; DNS Inspect id not matched (inspect-dns-id-not-matched) 27824&lt;BR /&gt; FP L2 rule drop (l2_acl) 33707&lt;BR /&gt; Interface is down (interface-down) 58&lt;BR /&gt; Dropped pending packets in a closed socket (np-socket-closed) 1270193&lt;/P&gt;
&lt;P&gt;Last clearing: Never&lt;/P&gt;
&lt;P&gt;Flow drop:&lt;BR /&gt; Need to start IKE negotiation (need-ike) 950&lt;BR /&gt; NAT failed (nat-failed) 328720&lt;BR /&gt; NAT reverse path failed (nat-rpf-failed) 4&lt;BR /&gt; Inspection failure (inspect-fail) 7968106&lt;BR /&gt; SSL bad record detected (ssl-bad-record-detect) 2857&lt;BR /&gt; SSL handshake failed (ssl-handshake-failed) 6404&lt;BR /&gt; SSL malloc error (ssl-malloc-error) 125&lt;BR /&gt; SSL received close alert (ssl-received-close-alert) 136&lt;/P&gt;
&lt;P&gt;Last clearing: Never&lt;BR /&gt;Lut-ASAFirewall#&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Lut-ASAFirewall# sh asp table socket&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Protocol Socket Local Address Foreign Address State&lt;BR /&gt;SSL 0000133f 192.168.1.1:443 0.0.0.0:* LISTEN&lt;BR /&gt;SSL 000020af 192.168.252.17:443 0.0.0.0:* LISTEN&lt;BR /&gt;TCP 0000459f 192.168.252.17:22 0.0.0.0:* LISTEN&lt;BR /&gt;SSL 062a1e5f 192.168.252.17:443 10.2.20.245:55177 ESTAB&lt;BR /&gt;SSL 062e1c5f 192.168.252.17:443 10.3.1.114:10016 ESTAB&lt;BR /&gt;SSL 062e25cf 192.168.252.17:443 10.3.1.114:10056 ESTAB&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;please let me know if you need any more information.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;many thanks&lt;/P&gt;
&lt;P&gt;Upen Desai&lt;/P&gt;</description>
      <pubDate>Tue, 20 Sep 2016 15:11:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-and-asdm-not-accessible/m-p/2979894#M149824</guid>
      <dc:creator>upen desai</dc:creator>
      <dc:date>2016-09-20T15:11:30Z</dc:date>
    </item>
    <item>
      <title>Hi Upen,</title>
      <link>https://community.cisco.com/t5/network-security/ssh-and-asdm-not-accessible/m-p/2979895#M149825</link>
      <description>&lt;P&gt;Hi &lt;G class="gr_ gr_5 gr-alert gr_spell gr_run_anim ContextualSpelling ins-del multiReplace" id="5" data-gr-id="5"&gt;Upen,&lt;/G&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Could you share the show memory and show blocks output from the ASA ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Aditya&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Please rate helpful posts and mark correct answers.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Sep 2016 06:02:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-and-asdm-not-accessible/m-p/2979895#M149825</guid>
      <dc:creator>Aditya Ganjoo</dc:creator>
      <dc:date>2016-09-21T06:02:52Z</dc:date>
    </item>
  </channel>
</rss>

