<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi Jouni,The sh run ssh only in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-ssh-in-to-asa-with-new-created-user/m-p/2511564#M234713</link>
    <description>&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;The sh run ssh only shows me the subnets that are allowed to SSH in. No users in this list.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Sep 2014 13:22:54 GMT</pubDate>
    <dc:creator>Charger1129</dc:creator>
    <dc:date>2014-09-19T13:22:54Z</dc:date>
    <item>
      <title>Unable to SSH in to ASA with new created user</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-in-to-asa-with-new-created-user/m-p/2511561#M234706</link>
      <description>&lt;P&gt;Hello. I have an ASA 5510 firewall running an older verison of code. I"m trying to create a new user account to log in but I can't seem to SSH with this account. ASDM works fine but SSH fails. I thought the command would have been:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;username newuser password usertest123&amp;nbsp;privilege 15&lt;/P&gt;&lt;P&gt;But I can't SSH with this. What am I missing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco Adaptive Security Appliance Software Version 7.2(4)&lt;BR /&gt;Device Manager Version 5.2(4)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:47:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-in-to-asa-with-new-created-user/m-p/2511561#M234706</guid>
      <dc:creator>Charger1129</dc:creator>
      <dc:date>2019-03-12T04:47:03Z</dc:date>
    </item>
    <item>
      <title>Does ssh work OK with other</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-in-to-asa-with-new-created-user/m-p/2511562#M234708</link>
      <description>&lt;P&gt;Does ssh work OK&amp;nbsp;with other local users?&lt;/P&gt;&lt;P&gt;If not, you may be missing:&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;aaa authentication ssh console LOCAL&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 13:02:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-in-to-asa-with-new-created-user/m-p/2511562#M234708</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-09-19T13:02:51Z</dc:date>
    </item>
    <item>
      <title>Hi, In addition to what</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-in-to-asa-with-new-created-user/m-p/2511563#M234711</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In addition to what Marvin suggested I would suggest simply checking the ASDM logs while the users tries to log in with SSH.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also if there is others using SSH connections to the ASA I would confirm if the new users is in a different subnet and perhaps even behind another interface on the ASA and you perhaps have not allowed SSH connection from that subnet?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Check the output of the command&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show run ssh&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To check which users can connect with SSH to the ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 13:07:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-in-to-asa-with-new-created-user/m-p/2511563#M234711</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2014-09-19T13:07:06Z</dc:date>
    </item>
    <item>
      <title>Hi Jouni,The sh run ssh only</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-in-to-asa-with-new-created-user/m-p/2511564#M234713</link>
      <description>&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;The sh run ssh only shows me the subnets that are allowed to SSH in. No users in this list.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 13:22:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-in-to-asa-with-new-created-user/m-p/2511564#M234713</guid>
      <dc:creator>Charger1129</dc:creator>
      <dc:date>2014-09-19T13:22:54Z</dc:date>
    </item>
    <item>
      <title>I think this may be what's</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-in-to-asa-with-new-created-user/m-p/2511565#M234714</link>
      <description>&lt;P&gt;I think this may be what's missing. Here's the error I received though when trying to add this to the configuration. I'm assuming I need to create this group?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;FIrewall-ASA(config)# aaa authentication ssh console local&lt;BR /&gt;ERROR: aaa-server group local does not exist&lt;BR /&gt;Usage: [no] aaa mac-exempt match &amp;lt;mac-list-id&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; [no] aaa authentication secure-http-client&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; [no] aaa authentication listener http|https &amp;lt;if_name&amp;gt; [port &amp;lt;port&amp;gt;] [redirect]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; [no] aaa authentication|authorization|accounting include|exclude &amp;lt;svc&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;if_name&amp;gt; &amp;lt;l_ip&amp;gt; &amp;lt;l_mask&amp;gt; [&amp;lt;f_ip&amp;gt; &amp;lt;f_mask&amp;gt;] &amp;lt;server_tag&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; [no] aaa authentication serial|telnet|ssh|http|enable console&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;server_tag&amp;gt; [LOCAL]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; [no] aaa accounting telnet|ssh|serial|enable console &amp;lt;server_tag&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; [no] aaa authentication|authorization|accounting match&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;lt;access_list_name&amp;gt; &amp;lt;if_name&amp;gt; &amp;lt;server_tag&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; [no] aaa authorization command {LOCAL | &amp;lt;tacacs_server_tag&amp;gt; [LOCAL]}&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; [no] aaa accounting command {privilege &amp;lt;level&amp;gt;} &amp;lt;tacacs_server_tag&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; [no] aaa proxy-limit &amp;lt;proxy limit&amp;gt; | disable&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; [no] aaa local authentication attempts max-fail &amp;lt;fail-attempts&amp;gt;&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; clear configure aaa&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; clear aaa local user {fail-attempts|lockout} {all | username &amp;lt;uname&amp;gt;}}&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; show running-config [all] aaa [authentication|authorization|accounting&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |max-exempt|proxy-limit]&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; show aaa local user [lockout]&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 13:26:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-in-to-asa-with-new-created-user/m-p/2511565#M234714</guid>
      <dc:creator>Charger1129</dc:creator>
      <dc:date>2014-09-19T13:26:20Z</dc:date>
    </item>
    <item>
      <title>I believe it's case-sensitive</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-in-to-asa-with-new-created-user/m-p/2511566#M234715</link>
      <description>&lt;P&gt;I believe it's case-sensitive.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14px; background-color: rgb(249, 249, 249);"&gt;&amp;nbsp;aaa authentication ssh console LOCAL&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 14:37:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-in-to-asa-with-new-created-user/m-p/2511566#M234715</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-09-19T14:37:59Z</dc:date>
    </item>
    <item>
      <title>Looks like you were right!</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-in-to-asa-with-new-created-user/m-p/2511567#M234716</link>
      <description>&lt;P&gt;Looks like you were right! Definitely case sensitive.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Another question on the topic. The enable password regardless of user is the same for all users correct?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 15:26:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-in-to-asa-with-new-created-user/m-p/2511567#M234716</guid>
      <dc:creator>Charger1129</dc:creator>
      <dc:date>2014-09-19T15:26:21Z</dc:date>
    </item>
    <item>
      <title>For LOCAL users, yes - the</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-in-to-asa-with-new-created-user/m-p/2511568#M234717</link>
      <description>&lt;P&gt;For LOCAL users, yes - the enable password is common between users.&lt;/P&gt;&lt;P&gt;If you use external authentication (and the user is authorized for enable), then they re-use their login password for enable access.&lt;/P&gt;&lt;P&gt;As of ASA 9.2 you can also allow direct login to enable level&amp;nbsp;("aaa authorization exec") as described &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa92/release/notes/asarn92.html"&gt;in the Release Notes&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Sep 2014 18:28:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-in-to-asa-with-new-created-user/m-p/2511568#M234717</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-09-19T18:28:02Z</dc:date>
    </item>
  </channel>
</rss>

