<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: No access to asdm !?! in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/no-access-to-asdm/m-p/3865637#M27196</link>
    <description>&lt;P&gt;Thank you Balaji , i will try the fix and&amp;nbsp; give you feedback.&amp;nbsp; but am I able to renew the certificate without access to asdm ?!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't&amp;nbsp; have an access to&amp;nbsp; ASDM at all.&lt;/P&gt;</description>
    <pubDate>Fri, 31 May 2019 09:25:12 GMT</pubDate>
    <dc:creator>mstoitso</dc:creator>
    <dc:date>2019-05-31T09:25:12Z</dc:date>
    <item>
      <title>No access to asdm !?!</title>
      <link>https://community.cisco.com/t5/network-security/no-access-to-asdm/m-p/3865582#M27186</link>
      <description>&lt;P&gt;On Monday I &amp;nbsp;was able to&amp;nbsp; run&amp;nbsp; ASDM on my PC but last days it crashed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I’m using Java 7 update 79. I added the ip address of the asa to the exception list and imported the ASA certificate into&amp;nbsp; Java as well in trusted root authorities store&amp;nbsp; in windows &amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is the current configuration.&lt;/P&gt;
&lt;P&gt;aaa authentication enable console LOCAL&lt;/P&gt;
&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;
&lt;P&gt;aaa authentication http console LOCAL&lt;/P&gt;
&lt;P&gt;ciscoasa# sh run ssl&lt;/P&gt;
&lt;P&gt;ssl encryption 3des-sha1 aes128-sha1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And the error message is&amp;nbsp; ERR_CERT_AUTHORITY_INVALID&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.1(5)16&lt;/P&gt;
&lt;P&gt;Each device can ping each other. Firewall switched off&lt;/P&gt;
&lt;P&gt;ASDM version 7122.bin&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could please advise how to solve the issue please.&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 06:41:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-access-to-asdm/m-p/3865582#M27186</guid>
      <dc:creator>mstoitso</dc:creator>
      <dc:date>2019-05-31T06:41:28Z</dc:date>
    </item>
    <item>
      <title>Re: No access to asdm !?!</title>
      <link>https://community.cisco.com/t5/network-security/no-access-to-asdm/m-p/3865613#M27192</link>
      <description>&lt;P&gt;&lt;STRONG&gt;And the error message is&amp;nbsp; ERR_CERT_AUTHORITY_INVALID&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;here is the document to fix.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/107956-renew-ssl.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/107956-renew-ssl.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 07:34:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-access-to-asdm/m-p/3865613#M27192</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2019-05-31T07:34:41Z</dc:date>
    </item>
    <item>
      <title>Re: No access to asdm !?!</title>
      <link>https://community.cisco.com/t5/network-security/no-access-to-asdm/m-p/3865637#M27196</link>
      <description>&lt;P&gt;Thank you Balaji , i will try the fix and&amp;nbsp; give you feedback.&amp;nbsp; but am I able to renew the certificate without access to asdm ?!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I don't&amp;nbsp; have an access to&amp;nbsp; ASDM at all.&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 09:25:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-access-to-asdm/m-p/3865637#M27196</guid>
      <dc:creator>mstoitso</dc:creator>
      <dc:date>2019-05-31T09:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: No access to asdm !?!</title>
      <link>https://community.cisco.com/t5/network-security/no-access-to-asdm/m-p/3865951#M27199</link>
      <description>&lt;P&gt;I Tried with&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&lt;STRONG&gt;crypto ca trustpoint ASDM_TrustPoint0&lt;/STRONG&gt;
        keypair CertKey
        id-usage ssl-ipsec 
        fqdn 5540-uwe
        subject-name CN=ASA5540.company.com,OU=LAB,O=Cisco ystems,C=US,St=CA
        enrollment terminal
 &lt;STRONG&gt;crypto ca enroll ASDM_TrustPoint0&lt;BR /&gt;ssl trust poin certificate name &lt;BR /&gt;&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;but i got an error message&lt;/P&gt;
&lt;P&gt;ERROR: Trustpoint not enrolled.&amp;nbsp; Please enroll trustpoint and try again.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;then i tried with&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Equivalent CLI of the configuration.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;ASA5520A(config)#&lt;EM&gt;crypto key generate rsa usage-keys label Cert-key&amp;nbsp;modulus 2048 noconfirm&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;ASA5520A(config)#&lt;EM&gt;crypto ca trustpoint My_Certificate&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;ASA5520A(config-ca-trustpoint)#&lt;EM&gt;keypair Cert-Key&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;ASA5520A(config-ca-trustpoint)#&lt;EM&gt;&amp;nbsp;fqdn myvpn.cisco.com&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;ASA5520A(config-ca-trustpoint)#&lt;EM&gt;subject-name&amp;nbsp;CN=myvpn.cisco.com,OU=IT,O="Cisco Systems,&amp;nbsp;Inc",C=US,St=California,L=San Jose,EA=admin@cisco.com&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;ASA5520A(config-ca-trustpoint)#&lt;EM&gt;enrollment terminal&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;ASA5520A(config)#crypto ca enroll My_Certificate noconfirm&lt;/P&gt;
&lt;P&gt;ASA5520A(config)#crypto ca authenticate My_Certificate&lt;/P&gt;
&lt;P&gt;ASA5520A(config)#ssl trustpoint outside My_Certificate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;but got the same error message&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;this is the debug from the http 255&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;HTTP: admin session verified =&amp;nbsp; [0]&lt;/P&gt;
&lt;P&gt;HTTP: processing GET URL '/' from host 192.168.80.144&lt;/P&gt;
&lt;P&gt;HTTP: processing handoff to legacy admin server [/favicon.ico]&lt;/P&gt;
&lt;P&gt;HTTP: admin session verified =&amp;nbsp; [0]&lt;/P&gt;
&lt;P&gt;HTTP: processing GET URL '/favicon.ico' from host 192.168.80.144&lt;/P&gt;
&lt;P&gt;HTTP: Periodic admin session check&amp;nbsp; (idle-timeout = 1200, session-timeout = 0)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the issue is still outgoing.&lt;/P&gt;</description>
      <pubDate>Fri, 31 May 2019 20:40:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-access-to-asdm/m-p/3865951#M27199</guid>
      <dc:creator>mstoitso</dc:creator>
      <dc:date>2019-05-31T20:40:41Z</dc:date>
    </item>
    <item>
      <title>Re: No access to asdm !?!</title>
      <link>https://community.cisco.com/t5/network-security/no-access-to-asdm/m-p/3866111#M27211</link>
      <description>&lt;P&gt;I got&amp;nbsp; the asdm idm launcher&amp;nbsp; but i think that i have a compatibility issue.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just to be sure&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cisco Adaptive Security Appliance Software Version 9.1(5)16&lt;/P&gt;
&lt;P&gt;Device Manager Version 7.12(2)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So I can run any asdm &amp;nbsp;version 7.1(6)+ and above ?!&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jun 2019 07:25:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-access-to-asdm/m-p/3866111#M27211</guid>
      <dc:creator>mstoitso</dc:creator>
      <dc:date>2019-06-01T07:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: No access to asdm !?!</title>
      <link>https://community.cisco.com/t5/network-security/no-access-to-asdm/m-p/3866136#M27215</link>
      <description>&lt;P&gt;&amp;nbsp;I got an error massage unable to lauch device menager from ip&lt;/P&gt;
&lt;P&gt;I copied all the &lt;A href="https://www.oracle.com/technetwork/java/javase/downloads/jce8-download-2133166.html" target="_blank" rel="noopener"&gt;&lt;STRONG&gt;Java Cryptography Extension files to the java security folde but&amp;nbsp; it didi&amp;nbsp; hot help&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I tried with the lates version of java.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;java reported&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE class="lang-java prettyprint prettyprinted"&gt;&lt;CODE&gt;&lt;SPAN class="pln"&gt;javax&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;net&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;SPAN class="pln"&gt;ssl&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;.&lt;/SPAN&gt;&lt;SPAN class="typ"&gt;SSLException&lt;/SPAN&gt;&lt;SPAN class="pun"&gt;:failed&lt;/SPAN&gt;&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;the ASA self signed certificate is imported in javatrusted certificates &lt;/P&gt;</description>
      <pubDate>Sat, 01 Jun 2019 10:22:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/no-access-to-asdm/m-p/3866136#M27215</guid>
      <dc:creator>mstoitso</dc:creator>
      <dc:date>2019-06-01T10:22:52Z</dc:date>
    </item>
  </channel>
</rss>

