<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SSH to Failover Interface  of Active/Standby ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssh-to-failover-interface-of-active-standby-asa/m-p/2498414#M238017</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have config ASA as Active/Standby for home lab for learning purposes.&lt;/P&gt;&lt;P&gt;I was trying to ssh to failover interface IP of active device but it did not work from my PC&lt;/P&gt;&lt;P&gt;May 30 2014 22:50:40: %ASA-6-110002: Failed to locate egress interface for TCP from inside:10.0.0.21/54702 to 10.30.30.1/22&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pri/act/ASA1#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sh failover inte$&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; interface fo Vlan30&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; System IP Address: 10.30.30.1 255.255.255.252&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; My IP Address&amp;nbsp;&amp;nbsp;&amp;nbsp; : 10.30.30.1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Other IP Address : 10.30.30.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PC is behind ASA inside interface.&lt;/P&gt;&lt;P&gt;Need to know by design is ssh possible to failover interface IP address or not?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 04:16:06 GMT</pubDate>
    <dc:creator>mahesh18</dc:creator>
    <dc:date>2019-03-12T04:16:06Z</dc:date>
    <item>
      <title>SSH to Failover Interface  of Active/Standby ASA</title>
      <link>https://community.cisco.com/t5/network-security/ssh-to-failover-interface-of-active-standby-asa/m-p/2498414#M238017</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have config ASA as Active/Standby for home lab for learning purposes.&lt;/P&gt;&lt;P&gt;I was trying to ssh to failover interface IP of active device but it did not work from my PC&lt;/P&gt;&lt;P&gt;May 30 2014 22:50:40: %ASA-6-110002: Failed to locate egress interface for TCP from inside:10.0.0.21/54702 to 10.30.30.1/22&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;pri/act/ASA1#&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sh failover inte$&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; interface fo Vlan30&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; System IP Address: 10.30.30.1 255.255.255.252&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; My IP Address&amp;nbsp;&amp;nbsp;&amp;nbsp; : 10.30.30.1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Other IP Address : 10.30.30.2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PC is behind ASA inside interface.&lt;/P&gt;&lt;P&gt;Need to know by design is ssh possible to failover interface IP address or not?&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 04:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-to-failover-interface-of-active-standby-asa/m-p/2498414#M238017</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T04:16:06Z</dc:date>
    </item>
    <item>
      <title>That is possible. You should</title>
      <link>https://community.cisco.com/t5/network-security/ssh-to-failover-interface-of-active-standby-asa/m-p/2498415#M238020</link>
      <description>&lt;P&gt;That is possible. You should be able to SSH if your active/standby firewall is in normal state. Try to generate the crypto keys again while on active/standby mode then save. If you can ping both active and standby IPs then there's very much little to troubleshoot. If you can SSH the active IP then much better. You'll figure it out. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 31 May 2014 12:12:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-to-failover-interface-of-active-standby-asa/m-p/2498415#M238020</guid>
      <dc:creator>jpl861</dc:creator>
      <dc:date>2014-05-31T12:12:36Z</dc:date>
    </item>
    <item>
      <title>Mahesh,Please refer to the</title>
      <link>https://community.cisco.com/t5/network-security/ssh-to-failover-interface-of-active-standby-asa/m-p/2498416#M238022</link>
      <description>&lt;P&gt;Mahesh,&lt;/P&gt;&lt;P&gt;Please refer to the &lt;A href="http://www.cisco.com/c/en/us/td/docs/security/asa/asa92/configuration/general/asa-general-cli/ha-failover.html#pgfId-1077563"&gt;configuration guide&lt;/A&gt; which states :&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; font-size: 12px; line-height: normal;"&gt;"The failover link interface is not configured as a normal networking interface; it exists for failover communication only. This interface can only be used for the failover link (and optionally also for the state link)."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;So the answer is "no".&lt;/P&gt;</description>
      <pubDate>Sat, 31 May 2014 15:12:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-to-failover-interface-of-active-standby-asa/m-p/2498416#M238022</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2014-05-31T15:12:18Z</dc:date>
    </item>
    <item>
      <title> Thanks for Answering the</title>
      <link>https://community.cisco.com/t5/network-security/ssh-to-failover-interface-of-active-standby-asa/m-p/2498417#M238026</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for Answering the question.&lt;/P&gt;&lt;P&gt;Best Regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;</description>
      <pubDate>Sat, 31 May 2014 18:26:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-to-failover-interface-of-active-standby-asa/m-p/2498417#M238026</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2014-05-31T18:26:51Z</dc:date>
    </item>
  </channel>
</rss>

