<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH connections through asa hanging in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390964#M306449</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;waqas gondal wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ASA allows the connection through but after a random amount of time the connection hangs.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's reason why I suggest you turn on ssh keep-alive and see if the issue goes away.&amp;nbsp; If the issue goes away, then you know it is a firewall issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 04 Jan 2014 18:05:23 GMT</pubDate>
    <dc:creator>cciesec2011</dc:creator>
    <dc:date>2014-01-04T18:05:23Z</dc:date>
    <item>
      <title>SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390944#M306365</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been troubleshooting this intermittent issue with Cisco TAC for about 3 weeks now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is that when users connect to external servers via ssh whether it is over a VPN or not, the connections hang. The timing is random and is not dependant on anything. After a user connects, the connection will hang and the show local host indicates that the connection is idle.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using an ASA 5505 with version 8.4(5) and a 5510 with 8.4(6) at another location with a site-to-site VPN in between them. The users who initiate the ssh connection are behind the 5505 and sometimes connect to servers behind the 5510, those connections also hang randomly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When we create ssh traffic through the VPN to servers behind the 5510:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The packet captures don't show a reason for the connection to hang, they just show that packets have stopped going through.&lt;/P&gt;&lt;P&gt;Syslog messages show nothing on the 5505 when the connection hangs, syslogs on the 5510 sometimes show the "deny tcp (no connection)" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas as to what might cause this issue?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 03:24:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390944#M306365</guid>
      <dc:creator>waqas gondal</dc:creator>
      <dc:date>2019-03-12T03:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390945#M306371</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is it possible this could have something to do with your ISP or other providers?&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 18:08:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390945#M306371</guid>
      <dc:creator>Jon Are Endrerud</dc:creator>
      <dc:date>2014-01-03T18:08:42Z</dc:date>
    </item>
    <item>
      <title>SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390946#M306374</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is possible but I have not checked with them yet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 19:46:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390946#M306374</guid>
      <dc:creator>waqas gondal</dc:creator>
      <dc:date>2014-01-03T19:46:21Z</dc:date>
    </item>
    <item>
      <title>Re: SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390947#M306376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So basically a SSH session that already was closed is still present on the local-host table of the ASA and the connection table??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you check the Timeout configuration on your firewall and also the MPF setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's the Idle time you have configured for a TCP session?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking for some Networking Assistance?&amp;nbsp; &lt;BR /&gt;&lt;SPAN&gt;Contact me directly at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;I will fix your problem ASAP. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 19:47:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390947#M306376</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2014-01-03T19:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390948#M306387</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The timeout on both ASAs is 1 hour. However if an ssh connection is established from behind the 5505 to a destination behind the 5510 the hanging connection is not present in the table of the 5510, and idle on the 5505.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem isn't getting the connection out of the connection table. The problem is trying to figure out why the connections are hanging intermittently.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There is no MPF setup&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 21:10:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390948#M306387</guid>
      <dc:creator>waqas gondal</dc:creator>
      <dc:date>2014-01-03T21:10:12Z</dc:date>
    </item>
    <item>
      <title>SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390949#M306396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you say the hanging connection what do you mean?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you mean the connection is closed but still present on one of the FWs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That let us know we can focus on the ASA 5505&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you share the configuration used there&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking for some Networking Assistance?&amp;nbsp; &lt;BR /&gt;&lt;SPAN&gt;Contact me directly at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;I will fix your problem ASAP. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 21:14:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390949#M306396</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2014-01-03T21:14:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390950#M306403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By hanging connections I mean there is no packet in any of the wireshark captures that indicates the connection has closed. A connection remains on the 5505 but the amount of bytes passed through do not increase. The ssh connection window to the device behind the 5510 is still open but inactive with no messages indicating close.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortuantly I cannot share configuration for policy reasons. Here I just wanted some ideas for things to look for when troubleshooting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your time.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 21:33:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390950#M306403</guid>
      <dc:creator>waqas gondal</dc:creator>
      <dc:date>2014-01-03T21:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390951#M306409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would create a capture on both of the interfaces (as you said you did).&lt;/P&gt;&lt;P&gt;I would check the MPF configuration for any specific set connection timeout&lt;/P&gt;&lt;P&gt;I would also check the Global timeout connection.&lt;/P&gt;&lt;P&gt;And of course enable logging on the FW to capture as much information as possible (between this sessions)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this the only traffic affected?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking for some Networking Assistance?&amp;nbsp; &lt;BR /&gt;&lt;SPAN&gt;Contact me directly at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;I will fix your problem ASAP. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 21:57:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390951#M306409</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2014-01-03T21:57:03Z</dc:date>
    </item>
    <item>
      <title>Re: SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390952#M306412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SSH is the only affected connection type.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And I have tried all of the things which you have mentioned. It is difficult to look through the firewall logs because they are extensive and don't show what caused the connection to hang.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Waqas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 23:53:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390952#M306412</guid>
      <dc:creator>waqas gondal</dc:creator>
      <dc:date>2014-01-03T23:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390953#M306416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am basically troubleshooting on blind mode so we cannot move forward bud.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking for some Networking Assistance?&amp;nbsp; &lt;BR /&gt;&lt;SPAN&gt;Contact me directly at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;I will fix your problem ASAP. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Jan 2014 23:57:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390953#M306416</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2014-01-03T23:57:05Z</dc:date>
    </item>
    <item>
      <title>Re: SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390954#M306420</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your input though, I really appreciate it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Jan 2014 00:24:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390954#M306420</guid>
      <dc:creator>waqas gondal</dc:creator>
      <dc:date>2014-01-04T00:24:58Z</dc:date>
    </item>
    <item>
      <title>Re: SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390955#M306428</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sure,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are willing to work providing updates and config related to the problem let us know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking for some Networking Assistance?&amp;nbsp; &lt;BR /&gt;&lt;SPAN&gt;Contact me directly at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;I will fix your problem ASAP. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Jan 2014 01:01:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390955#M306428</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2014-01-04T01:01:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390956#M306429</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem can be resolved very easily without touching the Cisco device.&amp;nbsp; By enabling ssh keep-alive on either the ssh client or the ssh server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;CODE&gt;&lt;/CODE&gt;&lt;CODE&gt;/etc/ssh/sshd_config&lt;/CODE&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Look for &lt;EM&gt;TCPKeepAlive&lt;/EM&gt; and make sure it is set to &lt;EM&gt;yes&lt;/EM&gt; and add the following lines after it:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;DIV id="highlighter_213297"&gt;&lt;TABLE border="0" cellpadding="0" cellspacing="0"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;&lt;/TD&gt;&lt;TD&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ClientAliveInterval 30&lt;/P&gt;&lt;P&gt;ClientAliveCountMax 10000&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service sshd restart&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will help the ssh connection from disconnecting.&amp;nbsp; If you still experience it, it is the cisco ASA &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Jan 2014 01:50:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390956#M306429</guid>
      <dc:creator>cciesec2011</dc:creator>
      <dc:date>2014-01-04T01:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390957#M306432</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I seriously do not think your configuration on the client/server side will make any difference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have already found where the problem is (ASA 5505) as the connection is hanging there while not traffic is being seeing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the other ASA (5510) the connection is succesfully removed from all of the respective tables.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So your work-around will not make any difference here as for the client/server the connection has been already closed (this after the customer description of the problem)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking for some Networking Assistance?&amp;nbsp; &lt;BR /&gt;&lt;SPAN&gt;Contact me directly at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;I will fix your problem ASAP. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Jan 2014 02:25:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390957#M306432</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2014-01-04T02:25:56Z</dc:date>
    </item>
    <item>
      <title>Re: SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390958#M306435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;jcarvaja wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I seriously do not think your configuration on the client/server side will make any difference.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have already found where the problem is (ASA 5505) as the connection is hanging there while not traffic is being seeing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the other ASA (5510) the connection is succesfully removed from all of the respective tables.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So your work-around will not make any difference here as for the client/server the connection has been already closed (this after the customer description of the problem)&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can not base that on what the user described.&amp;nbsp; In order to understand the issue, you need packet capture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I am suggesting is commonly used for connectivity traversing the firewall to prove whether the issue is on network or application itself.&amp;nbsp; By enabling keepalive on the application, you can see how it behaves.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Jan 2014 13:51:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390958#M306435</guid>
      <dc:creator>cciesec2011</dc:creator>
      <dc:date>2014-01-04T13:51:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390959#M306438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I had this kind of issue long time ago.&lt;BR /&gt;&lt;BR /&gt;I enabled an inside host to accept ssh connection and the ASA failed to enable it.&lt;BR /&gt;&lt;BR /&gt;I remember that one of the steps that I've done, was.. reconfigure (ssh) the ASA from scratch, and test it many times to make sure, it was working properly.&lt;BR /&gt;&lt;BR /&gt;Crypto, aaa, username, ip, inside/outside... All that.&lt;BR /&gt;&lt;BR /&gt;Then I went to create object, nat (inside, outside) host or subnet, acl then access-group.&lt;BR /&gt;&lt;BR /&gt;That way worked for me, but it tool me 3 days to figure that out.&lt;BR /&gt;&lt;BR /&gt;You could try that, hope it works.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;Oscar&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Jan 2014 15:08:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390959#M306438</guid>
      <dc:creator>Oscar Castillo</dc:creator>
      <dc:date>2014-01-04T15:08:17Z</dc:date>
    </item>
    <item>
      <title>Re: SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390960#M306441</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;STRONG&gt;You can not base that on what the user described.&amp;nbsp; In order to understand the issue, you need packet capture.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If customer does not provide us access to the box, inputs that we request we got to trust what he says. This is the case!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now, I do not think you understand what I am saying..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this were an app issue then the orphaned sessions would exist on both firewalls! Not just on one. As simple as that&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looking for some Networking Assistance?&amp;nbsp; &lt;BR /&gt;&lt;SPAN&gt;Contact me directly at &lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:jcarvaja@laguiadelnetworking.com"&gt;jcarvaja@laguiadelnetworking.com&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt; &lt;BR /&gt;I will fix your problem ASAP. &lt;BR /&gt; &lt;BR /&gt;Cheers, &lt;BR /&gt; &lt;BR /&gt;Julio Carvajal Segura &lt;BR /&gt;&lt;A class="jive-link-external-small" href="http://laguiadelnetworking.com"&gt;http://laguiadelnetworking.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Jan 2014 15:37:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390960#M306441</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2014-01-04T15:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390961#M306443</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is something I will check.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Jan 2014 17:24:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390961#M306443</guid>
      <dc:creator>waqas gondal</dc:creator>
      <dc:date>2014-01-04T17:24:47Z</dc:date>
    </item>
    <item>
      <title>Re: SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390962#M306445</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This issue is a little different I think.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ASA allows the connection through but after a random amount of time the connection hangs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I do understand your logic though, I have had issues where I simply erased the config, applied it again and everything was functonal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your input,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Waqas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Jan 2014 17:29:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390962#M306445</guid>
      <dc:creator>waqas gondal</dc:creator>
      <dc:date>2014-01-04T17:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: SSH connections through asa hanging</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390963#M306447</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;When does it hang? Is it possible to use it at all?&lt;BR /&gt;&lt;BR /&gt;Is it after big blocks of text passing through the terminal?&lt;BR /&gt;&lt;BR /&gt;What is the MTU between the ssh server and client?&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support iPhone App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 04 Jan 2014 17:48:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connections-through-asa-hanging/m-p/2390963#M306447</guid>
      <dc:creator>Jon Are Endrerud</dc:creator>
      <dc:date>2014-01-04T17:48:25Z</dc:date>
    </item>
  </channel>
</rss>

