<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to SSH  to server from ASA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205380#M351159</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So with&amp;nbsp; other&amp;nbsp; subnet it works fine IP of that subnet is 170.31.24.106.&lt;/P&gt;&lt;P&gt;So one thing to confirm with you i read that whenever you get Rest TCP O it means that lower security has terminated &lt;/P&gt;&lt;P&gt;the connection and Y has lower security then X.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So this is always the rule that Rest O comes from the lower security device and culprit is not the firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will check if i can run packet capture tomorrow?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jouni when i click on X interface ASDM&amp;nbsp; it shows IP as 170.16.0.0/12 do you why is this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Apr 2013 00:47:12 GMT</pubDate>
    <dc:creator>mahesh18</dc:creator>
    <dc:date>2013-04-24T00:47:12Z</dc:date>
    <item>
      <title>Unable to SSH  server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205372#M351151</link>
      <description>&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Hi everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA&amp;nbsp; has 2 interfaces say x and y.&lt;/P&gt;&lt;P&gt;From interface x when on subnet say 171.31.0.0 mask /24 i am able to ssh server.&lt;/P&gt;&lt;P&gt;ASA&amp;nbsp; shows hit counts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When on subnet 171.23 ssh does not work.logs shows tcp reset 0&amp;nbsp; thats from interface y.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;both subnets have connection from interface x to server which is on ASA interface y.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I check IP on interface x it shows 171.15.0.0/12.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:33:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205372#M351151</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2019-03-12T01:33:49Z</dc:date>
    </item>
    <item>
      <title>Unable to SSH  to server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205373#M351152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mahesh,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you perhaps share some ASA configurations and/or the logs messages you are seeing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you saying that from the first subnet you get hitcounts in the ACL and the SSH connection through the ASA works? Are you seeing hitcounts on the ACL when connecting from the other subnet behind x?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you talk about a TCP Reset 0 from the direction of y, it would seem to me that the actual server is not allowing this connection and ASA might not have anything to do with blocking the connection or the connection failing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps the actual server has restrictions on where it can be connected from? Like some local software firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Apr 2013 22:10:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205373#M351152</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-23T22:10:26Z</dc:date>
    </item>
    <item>
      <title>Unable to SSH  to server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205374#M351153</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA has 2 interfaces and when i try from&amp;nbsp; my subnet it works fine.&lt;/P&gt;&lt;P&gt;I can see the hit counts on interface X&amp;nbsp; of ASA.&lt;/P&gt;&lt;P&gt;Connection to server goes out via interface Y of ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When user try from his subnet connection goes via interface X&amp;nbsp; and goes to Server via interface Y of ASA.&lt;/P&gt;&lt;P&gt;I can see in logs TCP connection build up and after a sec i see TCP connection teardown in logs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It also show TCP Rest O that points to interface Y&amp;nbsp; of ASA&amp;nbsp; where server is connected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to confirm with you if server is not allowing the connection to user subnet or it is ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;X interface of ASA when i click on ASDM shows subnet 171.16.10.0/15 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to know if user IP is included in this subnet?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thnaks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Apr 2013 22:45:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205374#M351153</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-04-23T22:45:37Z</dc:date>
    </item>
    <item>
      <title>Unable to SSH  to server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205375#M351154</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are giving totally different subnets on both of your posts. It would be easier to see the actual configurations and the logs messages you are seeing. Otherwise we will probably just spend time guessing what is actually happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Network 171.16.0.0/15 would mean addresses between 171.16.0.0 - 171.17.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Network 171.15.0.0/12 would mean addresses between 171.0.0.0 - 171.15.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Apr 2013 22:58:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205375#M351154</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-23T22:58:03Z</dc:date>
    </item>
    <item>
      <title>Unable to SSH  to server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205376#M351155</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am currently away&amp;nbsp; i will show you log in an hour if you are still awake?&lt;/P&gt;&lt;P&gt;Also will confirm actual subnets.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Apr 2013 23:01:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205376#M351155</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-04-23T23:01:38Z</dc:date>
    </item>
    <item>
      <title>Unable to SSH  to server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205377#M351156</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let us know when you get the information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Apr 2013 23:06:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205377#M351156</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-23T23:06:23Z</dc:date>
    </item>
    <item>
      <title>Unable to SSH  to server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205378#M351157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are logs of user&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MDT&amp;nbsp;&amp;nbsp;&amp;nbsp; 170.31.100.11&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; %ASA-6-302014: Teardown TCP connection 27307345 for Y:170.24.156.5/22 to X:170.30.252.62/51017 duration 0:00:00 bytes 0 TCP Reset-O&lt;/P&gt;&lt;P&gt;5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 170.31.100.11&amp;nbsp;&amp;nbsp;&amp;nbsp; %ASA-6-302013: Built outbound TCP connection 27307345 for Y:170.24.156.5/22 (170.24.156.5/22) to X:170.30.252.62/51017 (170.30.252.62/51017)&lt;/P&gt;&lt;P&gt;4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 170.31.100.11&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; %ASA-6-302014: Teardown TCP connection 27307276 for Y:170.24.156.5/22 to X:170.30.252.62/51017 duration 0:00:00 bytes 0 TCP Reset-O&lt;/P&gt;&lt;P&gt;3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 170.31.100.11&amp;nbsp;&amp;nbsp;&amp;nbsp; : %ASA-6-302013: Built outbound TCP connection 27307276 for Y:170.24.156.5/22 (170.24.156.5/22) to X:170.30.252.62/51017 (170.30.252.62/51017)&lt;/P&gt;&lt;P&gt;2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 170.31.100.11&amp;nbsp;&amp;nbsp;&amp;nbsp; %ASA-6-302014: Teardown TCP connection 27307257 for Y:170.24.156.5/22 to X:170.30.252.62/51017 duration 0:00:00 bytes 0 TCP Reset-O&lt;/P&gt;&lt;P&gt;1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 170.31.100.11&amp;nbsp;&amp;nbsp;&amp;nbsp; : %ASA-6-302013: Built outbound TCP connection 27307257 for Y:170.24.156.5/22 (170.24.156.5/22) to X:170.30.252.62/51017 (170.30.252.62/51017)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where 170.30.252.62&amp;nbsp; is user PC&lt;/P&gt;&lt;P&gt;170.24.156.5 is server IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When i click on ASDM interface of FW&amp;nbsp; it shows 170.16.0.0/12.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 00:11:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205378#M351157</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-04-24T00:11:51Z</dc:date>
    </item>
    <item>
      <title>Unable to SSH  to server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205379#M351158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems to me that the Server to which you are trying to connect with SSH might be terminating the TCP connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I would check if the server settings first to see if its blocking the connection according to some settings or perhaps because of some software firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to get more information about this connection you could do a capture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list SSH-CAPTURE permit ip host 170.30.252.62 host 170.24.156.5&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;access-list SSH-CAPTURE permit ip host 170.24.156.5 host 170.30.252.62&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;capture SSH-CAPTURE type raw-data access-list SSH-CAPTURE interface X buffer 1000000 circular-buffer&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then check the capture contents after test with&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show capture SSH-CAPTURE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And possinly load the capture to a TFTP server with command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN&gt;copy /pcap capture:SSH-CAPTURE t&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="ftp://x.x.x.x/SSH-CAPTURE.pcap"&gt;ftp://x.x.x.x/SSH-CAPTURE.pcap&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And you could then attach it to this discussion if needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 00:23:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205379#M351158</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-24T00:23:33Z</dc:date>
    </item>
    <item>
      <title>Unable to SSH  to server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205380#M351159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So with&amp;nbsp; other&amp;nbsp; subnet it works fine IP of that subnet is 170.31.24.106.&lt;/P&gt;&lt;P&gt;So one thing to confirm with you i read that whenever you get Rest TCP O it means that lower security has terminated &lt;/P&gt;&lt;P&gt;the connection and Y has lower security then X.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So this is always the rule that Rest O comes from the lower security device and culprit is not the firewall?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will check if i can run packet capture tomorrow?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jouni when i click on X interface ASDM&amp;nbsp; it shows IP as 170.16.0.0/12 do you why is this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 00:47:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205380#M351159</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-04-24T00:47:12Z</dc:date>
    </item>
    <item>
      <title>Unable to SSH  to server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205381#M351160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, TCP Reset-O should mean that the TCP Reset came from the host on the interface with the lower "security-level"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TCP Reset-I would mean that the TCP Reset came from the host on the interface with the higher "security-level"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would imagine that the server might block connection based its own configurations and reset the whole SSH connection attempt. As you can see there is no data transmitted between the hosts as the counter says "0" and also the duration is "0" which means that the connection was resetted pretty much right away when the server received it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure what you mean with the ASDM interface thing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you perhaps share some screenshot of what you are seeing? I dont use ASDM that much so cant give you an answer wihtout seeing the actual situation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My own ASA firewalls ASDM "Home" view lists the ASA interfaces and their IP addresses and network masks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 01:06:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205381#M351160</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-24T01:06:44Z</dc:date>
    </item>
    <item>
      <title>Unable to SSH  to server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205382#M351161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When you say Counter says zero does it mean bytes 0?&lt;/P&gt;&lt;P&gt;Also when we have ssh connection established via ASA&amp;nbsp; when all is good then we should see some number in bytes&lt;/P&gt;&lt;P&gt;when connection is established?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 01:17:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205382#M351161</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-04-24T01:17:05Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to SSH  to server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205383#M351162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, the data counter in the Teardown message says that 0 bytes were transmitted on the connection in question before it was teardown from the ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the duration counter says that the connection was teardown in under a second since it says 0:00:00&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take for example one connection Teardown message from my own ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Apr 24 2013 04:21:20 ASA : %ASA-6-302014: Teardown TCP connection 1979132 for WAN:x.x.x.x/443 to LAN:10.0.0.100/61529 duration 0:00:50 bytes 6517 TCP FINs&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The duration says that the connection was up for 50 seconds. The other counter also says that 6517 Bytes were transmitted on the TCP connection in question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to see how much data has been transfered on a connection that is STILL ACTIVE on the ASA then you could use this command. Again using my own ASA as an example&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;ASA(config)# sh conn long | inc 10.0.0.100&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TCP WAN:x.x.x.x/443 (x.x.x.x/443) LAN:10.0.0.100/61472 (y.y.y.y/61472), flags UIO, idle 41s, uptime 13m21s, timeout 1h0m, bytes 64378&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;10.0.0.100 is my computer&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above for example says that&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;There is an HTTPS connection from my LAN to the WAN (Internet)&lt;/LI&gt;&lt;LI&gt;The TCP connection is fully formed because there is TCP flag U&lt;/LI&gt;&lt;LI&gt;The TCP connection has seen data in both directions. TCP flag I for input and TCP flag O for output&lt;/LI&gt;&lt;LI&gt;The TCP connection has been up for 13 minutes and 21 seconds&lt;/LI&gt;&lt;LI&gt;The TCP connection will timeout in 1 hour if there is no traffic&lt;/LI&gt;&lt;LI&gt;So far 64378 bytes have been transmitted on this TCP connection&lt;/LI&gt;&lt;LI&gt;The TCP connection has been idle for 41 seconds before this output was taken&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also use these commands (using my computer IP as example)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show conn long address 10.0.0.100&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;show local-host 10.0.0.100 detail&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 01:27:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205383#M351162</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-24T01:27:55Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to SSH  to server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205384#M351163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the ASDM &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;where you see outside - incoming rules&amp;nbsp; you see PC icon just before the IP 192.168.0.0.&lt;/P&gt;&lt;P&gt;When i click on&amp;nbsp; PC icon i see there 170.16.0.0/12 on X&amp;nbsp; interface of ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 01:40:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205384#M351163</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-04-24T01:40:02Z</dc:date>
    </item>
    <item>
      <title>Unable to SSH  to server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205385#M351164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I dont really know what is showing such an output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cant also see 192.168.0.0 anywhere in the picture.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 01:48:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205385#M351164</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-24T01:48:58Z</dc:date>
    </item>
    <item>
      <title>Unable to SSH  server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205386#M351166</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That Pic is from my ASA i gave you as an example&amp;nbsp; on other&amp;nbsp; ASA&amp;nbsp; when i click on screen i see 170.x.x.x/12 subnet.&lt;/P&gt;&lt;P&gt;this is mean to say.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mahesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 02:08:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205386#M351166</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-04-24T02:08:14Z</dc:date>
    </item>
    <item>
      <title>Unable to SSH  server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205387#M351168</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would imagine that you have some "object-group network" or "object network" or some such object used in the ACL and when you keep your mouse over the object it shows the IP address/network configured under it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't really say for sure as I dont use ASDM in general.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 02:14:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205387#M351168</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-24T02:14:38Z</dc:date>
    </item>
    <item>
      <title>Unable to SSH  server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205388#M351171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems there was another firewall inbetween the server that did not have ACL to allow the user subnet.&lt;/P&gt;&lt;P&gt;So it was blocking the connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for all the answers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 17:44:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205388#M351171</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-04-24T17:44:39Z</dc:date>
    </item>
    <item>
      <title>Unable to SSH  server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205389#M351174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Ok,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Glad its working now. &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It seems that the firewall that is between is either an ASA that is configured differently from the default operation OR its a firewall from different manufacturer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA firewalls by default dont send TCP Reset to connections that they block (BUT they can be configured to do this). By default the connection will simply timeout and your ASA would have then seen a Teardown message with SYN Timeout (Instead of TCP Reset-O). Seems that this firewall in between just immediately Resets the TCP connection if its not allowed according to the firewalls rules.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 17:49:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205389#M351174</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2013-04-24T17:49:52Z</dc:date>
    </item>
    <item>
      <title>Unable to SSH  server from ASA</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205390#M351177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jouni,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you got it its configured differently in non routed mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAhesh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Apr 2013 17:54:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-server-from-asa/m-p/2205390#M351177</guid>
      <dc:creator>mahesh18</dc:creator>
      <dc:date>2013-04-24T17:54:22Z</dc:date>
    </item>
  </channel>
</rss>

