<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASDM access from specific IP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asdm-access-from-specific-ip/m-p/2078852#M392146</link>
    <description>&lt;P&gt;I do have one other question first.&amp;nbsp; What's the effect of the &lt;/P&gt;&lt;PRE style="font-size: 15px; color: #000000;"&gt;&lt;STRONG&gt;crypto key zeroize rsa&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt; command, and then &lt;/P&gt;&lt;PRE style="font-size: 15px; color: #000000;"&gt;&lt;STRONG&gt;crypto key generate rsa modulus 1024&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt; while I'm SSH'd to the ASA?&amp;nbsp; Can I do it?&amp;nbsp; Or do i need to be consoled in or connected a different way?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK, it's a customers ASA 5510:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 8.4(1)&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-641.bin&lt;/P&gt;&lt;P&gt;asdm history enable&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;http 10.1.1.83 255.255.255.255 inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;http 10.1.1.82 255.255.255.255 inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Shouldn't that right there be enough to access ASDM from either host .82 or .83?&amp;nbsp; Because I cannot.&amp;nbsp; But if I add&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 inside, then I of course can.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:52:38 GMT</pubDate>
    <dc:creator>WStoffel1</dc:creator>
    <dc:date>2019-03-12T00:52:38Z</dc:date>
    <item>
      <title>ASDM access from specific IP</title>
      <link>https://community.cisco.com/t5/network-security/asdm-access-from-specific-ip/m-p/2078852#M392146</link>
      <description>&lt;P&gt;I do have one other question first.&amp;nbsp; What's the effect of the &lt;/P&gt;&lt;PRE style="font-size: 15px; color: #000000;"&gt;&lt;STRONG&gt;crypto key zeroize rsa&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt; command, and then &lt;/P&gt;&lt;PRE style="font-size: 15px; color: #000000;"&gt;&lt;STRONG&gt;crypto key generate rsa modulus 1024&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt; while I'm SSH'd to the ASA?&amp;nbsp; Can I do it?&amp;nbsp; Or do i need to be consoled in or connected a different way?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK, it's a customers ASA 5510:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ASA Version 8.4(1)&lt;/P&gt;&lt;P&gt;asdm image disk0:/asdm-641.bin&lt;/P&gt;&lt;P&gt;asdm history enable&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;http 10.1.1.83 255.255.255.255 inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;http 10.1.1.82 255.255.255.255 inside&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Shouldn't that right there be enough to access ASDM from either host .82 or .83?&amp;nbsp; Because I cannot.&amp;nbsp; But if I add&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 inside, then I of course can.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea why?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:52:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-access-from-specific-ip/m-p/2078852#M392146</guid>
      <dc:creator>WStoffel1</dc:creator>
      <dc:date>2019-03-12T00:52:38Z</dc:date>
    </item>
    <item>
      <title>ASDM access from specific IP</title>
      <link>https://community.cisco.com/t5/network-security/asdm-access-from-specific-ip/m-p/2078853#M392149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will not loose ssh connectivity to the device when you run the following commands :&lt;/P&gt;&lt;PRE style="font-size: 15px; color: #000000;"&gt;&lt;STRONG&gt;crypto key zeroize rsa&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE style="font-size: 15px; color: #000000;"&gt;&lt;STRONG&gt;crypto key generate rsa modulus 1024&lt;/STRONG&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you close the ssh session before running the second command, then you will loose connectivity over ssh and should get a console connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And with the asdm and http configuration you specified, you should be able to access the ASA on ASDM from .82 or .83.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would not need the command 'http 0.0.0.0 0.0.0.0 inside' for this to work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is not working, check the inside interface IP address and verify if it can reach .82 or .83 by running ping tests.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Narayana&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Jan 2013 01:54:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-access-from-specific-ip/m-p/2078853#M392149</guid>
      <dc:creator>V S Narayana Chivukula</dc:creator>
      <dc:date>2013-01-26T01:54:42Z</dc:date>
    </item>
    <item>
      <title>ASDM access from specific IP</title>
      <link>https://community.cisco.com/t5/network-security/asdm-access-from-specific-ip/m-p/2078854#M392152</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can SSH to the ASA from both those addresses so there is connectivity.&amp;nbsp; Do i specifically need ICMP for anything?&amp;nbsp; I don't have access to this site till Monday morning again so i can't test anything now.&amp;nbsp; thanks for the input though.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Inside interface is on the same network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 10.1.1.249 255.0.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface properties from one of the machines above:&lt;/P&gt;&lt;P&gt;Intel(R) 82578DM Gigabit Network Connection | 10.1.1.83 | 255.0.0.0 | 10.1.1.251&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 26 Jan 2013 11:39:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asdm-access-from-specific-ip/m-p/2078854#M392152</guid>
      <dc:creator>WStoffel1</dc:creator>
      <dc:date>2013-01-26T11:39:59Z</dc:date>
    </item>
  </channel>
</rss>

