<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA5520 - can't connect with putty in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183818#M358485</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;when I connect my laptop using the console cable, the screen is constantly scrolling with firewall traffic&lt;/PRE&gt;&lt;P&gt;That means that debugging/informational logging is enabled. You, after successful connection throug ssh, first disable the console logging using &lt;EM&gt;no logging console.&lt;/EM&gt; After that, disconnect from ssh, connect to console, enable &lt;/P&gt;&lt;P&gt;debug aaa authentication, connect again through ssh and see what's happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Are there any historical logs I can check when successfully conntect using ssh?&lt;/PRE&gt;&lt;P&gt;Yes, you can enable logging to buffer, i.e. &lt;EM&gt;logging buffer debugging. &lt;/EM&gt;The log will be saved to the buffer and you'll be able to see it later. Alternatively you can save logs to any syslog servers, but i don't think you need it here)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 15 Apr 2013 16:00:04 GMT</pubDate>
    <dc:creator>Andrew Phirsov</dc:creator>
    <dc:date>2013-04-15T16:00:04Z</dc:date>
    <item>
      <title>ASA5520 - can't connect with putty</title>
      <link>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183815#M358482</link>
      <description>&lt;P&gt;Hi folks,&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;A bit of a strange one I'm hoping some of you may have come across before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;When I try to SSH (putty) onto our Cisco ASA5520 (8.4.2), more often that not I get an 'Access denied' message when I enter the password which I'm 100% sure is correct.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;I enter the password three times until it disconnects me.&amp;nbsp; I then have to close the putty session (numerous times on occassions) and start again and then I can connect (if I'm lucky).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is from the Putty event log:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;2013-04-11 11:53:15 Sent password&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;2013-04-11 11:53:15 Access denied&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Are there logs I can check when successfully connected to the firewall?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 01:26:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183815#M358482</guid>
      <dc:creator>Alex Sykes</dc:creator>
      <dc:date>2019-03-12T01:26:43Z</dc:date>
    </item>
    <item>
      <title>ASA5520 - can't connect with putty</title>
      <link>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183816#M358483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;yes,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;are you using any external database for authentication.. if not just use&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug aaa authentication and try to login,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;post the results&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Apr 2013 17:38:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183816#M358483</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-11T17:38:38Z</dc:date>
    </item>
    <item>
      <title>ASA5520 - can't connect with putty</title>
      <link>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183817#M358484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have local authentication on our firewall, however, when I connect my laptop using the console cable, the screen is constantly scrolling with firewall traffic and I can't find a way to stop it and, therefore, I cannot enter the command you suggested.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This only happens via console - not remote ssh (when I eventually connect).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are there any historical logs I can check when successfully conntect using ssh?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have two 5520s in a HA pair and I can make the stand-by firewall the primary one, and the same problems occurs - cannot ssh using putty and when using colsole cable contstant scrolling of firewall traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is very odd behaviour.&amp;nbsp; Would something like a memory leak cause these issues?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Apr 2013 15:36:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183817#M358484</guid>
      <dc:creator>Alex Sykes</dc:creator>
      <dc:date>2013-04-15T15:36:45Z</dc:date>
    </item>
    <item>
      <title>ASA5520 - can't connect with putty</title>
      <link>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183818#M358485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;when I connect my laptop using the console cable, the screen is constantly scrolling with firewall traffic&lt;/PRE&gt;&lt;P&gt;That means that debugging/informational logging is enabled. You, after successful connection throug ssh, first disable the console logging using &lt;EM&gt;no logging console.&lt;/EM&gt; After that, disconnect from ssh, connect to console, enable &lt;/P&gt;&lt;P&gt;debug aaa authentication, connect again through ssh and see what's happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;Are there any historical logs I can check when successfully conntect using ssh?&lt;/PRE&gt;&lt;P&gt;Yes, you can enable logging to buffer, i.e. &lt;EM&gt;logging buffer debugging. &lt;/EM&gt;The log will be saved to the buffer and you'll be able to see it later. Alternatively you can save logs to any syslog servers, but i don't think you need it here)&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Apr 2013 16:00:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183818#M358485</guid>
      <dc:creator>Andrew Phirsov</dc:creator>
      <dc:date>2013-04-15T16:00:04Z</dc:date>
    </item>
    <item>
      <title>ASA5520 - can't connect with putty</title>
      <link>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183819#M358486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andrew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all the info - it is very much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I had to send the 'no logging console' command from the ASDM because I still can't get ssh access.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, once that was done, I ran the 'debug aaa authentication' command and got a '&lt;SPAN style="font-size: 10pt;"&gt;Resetting 10.116.0.3's numtries' message.&amp;nbsp; That IP is our ACS, so I'll start looking there.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Thanks again for your help.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Alex&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Apr 2013 17:01:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183819#M358486</guid>
      <dc:creator>Alex Sykes</dc:creator>
      <dc:date>2013-04-15T17:01:25Z</dc:date>
    </item>
    <item>
      <title>ASA5520 - can't connect with putty</title>
      <link>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183820#M358487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You said it was local authentication and now you are dealing with an ACS problem, you can share the asa setup to review it ,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 15 Apr 2013 18:19:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183820#M358487</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-15T18:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5520 - can't connect with putty</title>
      <link>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183821#M358488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Please accept my apologies - I didn't realise the ACS was used for this authentication.&amp;nbsp; I'm very new to Cisco products and I'm having difficulty learning on a production network.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Attached is the ASA config as requested.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, the ACS has the following messages in the logs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Failure Reason &amp;gt; Authentication Failure Code Lookup&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Failure Reason : 22056 Subject not found in the applicable identity store(s).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The help I'm receiving really is appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 15:53:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183821#M358488</guid>
      <dc:creator>Alex Sykes</dc:creator>
      <dc:date>2013-04-16T15:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5520 - can't connect with putty</title>
      <link>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183822#M358489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Alex,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does not look like the SSH sessions are being sent to the AAA server for authentication it's being authenticated locally,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you add :&lt;/P&gt;&lt;P&gt;username cisco password cisco&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An try to authenticate as a test with those&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Apr 2013 16:45:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183822#M358489</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2013-04-16T16:45:28Z</dc:date>
    </item>
    <item>
      <title>Re: ASA5520 - can't connect with putty</title>
      <link>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183823#M358490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've managed to find a workaround by setting SSH authentication to local only - not ACS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for you time and effort in helping me with this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Alex&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Apr 2013 15:52:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa5520-can-t-connect-with-putty/m-p/2183823#M358490</guid>
      <dc:creator>Alex Sykes</dc:creator>
      <dc:date>2013-04-19T15:52:35Z</dc:date>
    </item>
  </channel>
</rss>

