<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Problem with ASA SSH after 8.4.5 upgrade in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/problem-with-asa-ssh-after-8-4-5-upgrade/m-p/2144827#M416564</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you running in failover? You might want to remove the SSH commands from the ASA and re-add them. I strongly suggest you to try that. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Juan Lombana&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Mar 2013 22:40:37 GMT</pubDate>
    <dc:creator>julomban</dc:creator>
    <dc:date>2013-03-27T22:40:37Z</dc:date>
    <item>
      <title>Problem with ASA SSH after 8.4.5 upgrade</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-ssh-after-8-4-5-upgrade/m-p/2144821#M416547</link>
      <description>&lt;P&gt;Good Afternoon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are having issues with SSH to our ASA 5510 after upgrading to 8.4.5.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the SSH Debug logs we get:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mwe 0x08eff6e8 0xad5ed19c 0xad5e93b4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 0xad5e9460 14888/16384 listen/ssh&lt;BR /&gt;ASA-USNOR-01# Device ssh opened successfully.&lt;BR /&gt;SSH0: SSH client: IP = '172.16.10.8'&amp;nbsp; interface # = 4&lt;BR /&gt;SSH: host key initialised&lt;BR /&gt;SSH0: starting SSH control process&lt;BR /&gt;SSH-1031171653: Exchanging versions - SSH-2.0-Cisco-1.25&lt;/P&gt;&lt;P&gt;SSH-1031171653: send SSH message: outdata is NULL&lt;/P&gt;&lt;P&gt;server version string:SSH-2.0-Cisco-1.25SSH-1031171653: receive SSH message: 83 (83)&lt;BR /&gt;SSH-1031171653: client version is - SSH-2.0-PuTTY_Release_0.62&lt;/P&gt;&lt;P&gt;client version string:SSH-2.0-PuTTY_Release_0.62SSH0: begin server key generation&lt;BR /&gt;SSH0: complete server key generation, elapsed time = 520 ms&lt;/P&gt;&lt;P&gt;SSH2 -1031171653: SSH2_MSG_KEXINIT sent&lt;BR /&gt;SSH2 -1031171653: SSH2_MSG_KEXINIT received&lt;BR /&gt;SSH2: kex: client-&amp;gt;server aes256-cbc hmac-sha1 none&lt;BR /&gt;SSH2: kex: server-&amp;gt;client aes256-cbc hmac-sha1 none&lt;BR /&gt;SSH2 -1031171653: expecting SSH2_MSG_KEXDH_INIT&lt;BR /&gt;SSH2 -1031171653: SSH2_MSG_KEXDH_INIT received&lt;BR /&gt;SSH2 -1031171653: signature length 271&lt;BR /&gt;SSH2: kex_derive_keys complete&lt;BR /&gt;SSH2 -1031171653: newkeys: mode 1&lt;BR /&gt;SSH2 -1031171653: SSH2_MSG_NEWKEYS sent&lt;BR /&gt;SSH2 -1031171653: waiting for SSH2_MSG_NEWKEYS&lt;BR /&gt;SSH2 -1031171653: newkeys: mode 0&lt;BR /&gt;SSH2 -1031171653: SSH2_MSG_NEWKEYS received&lt;BR /&gt;SSH2 -1031171653: authentication failed for&amp;nbsp; (code=1)SSH-1031171653: Session disconnected by SSH server - error 0x0d "Rejected by server"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The correct ACL's are set, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:51:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-ssh-after-8-4-5-upgrade/m-p/2144821#M416547</guid>
      <dc:creator>IT Services</dc:creator>
      <dc:date>2020-02-21T12:51:18Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA SSH after 8.4.5 upgrade</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-ssh-after-8-4-5-upgrade/m-p/2144822#M416550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Seems like the authentication part is failing based on the debug output above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you authenticating locally for the SSH session or via Radius/Tacacs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it's via Radius or Tacacs, can you please check to see if you can authenticate from the ASA using the "test" command.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 04:33:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-ssh-after-8-4-5-upgrade/m-p/2144822#M416550</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2013-03-22T04:33:21Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA SSH after 8.4.5 upgrade</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-ssh-after-8-4-5-upgrade/m-p/2144823#M416553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Jennifer,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply. It is not giving me the chance to even authenticate. It refuses the connection the second the login prompt shows.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have tried both RADIUS and LOCAL authentication to no avail.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am just looking for an idea other than rebooting the ASA, which might be my last resort.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 12:43:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-ssh-after-8-4-5-upgrade/m-p/2144823#M416553</guid>
      <dc:creator>IT Services</dc:creator>
      <dc:date>2013-03-22T12:43:42Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA SSH after 8.4.5 upgrade</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-ssh-after-8-4-5-upgrade/m-p/2144824#M416555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;base on the information, unfortunately rebooting will be the best bet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Mar 2013 21:31:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-ssh-after-8-4-5-upgrade/m-p/2144824#M416555</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2013-03-22T21:31:36Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with ASA SSH after 8.4.5 upgrade</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-ssh-after-8-4-5-upgrade/m-p/2144825#M416558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you tried regeneration of your RSA key on the ASA? ("crypto key generate rsa").&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also verify you still have ssh allowed on the target interface from your host network.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Mar 2013 18:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-ssh-after-8-4-5-upgrade/m-p/2144825#M416558</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2013-03-24T18:43:11Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA SSH after 8.4.5 upgrade</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-ssh-after-8-4-5-upgrade/m-p/2144826#M416561</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yes all this has been done and verified. I even tried changing the key size.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Mar 2013 17:14:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-ssh-after-8-4-5-upgrade/m-p/2144826#M416561</guid>
      <dc:creator>IT Services</dc:creator>
      <dc:date>2013-03-27T17:14:17Z</dc:date>
    </item>
    <item>
      <title>Problem with ASA SSH after 8.4.5 upgrade</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-ssh-after-8-4-5-upgrade/m-p/2144827#M416564</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you running in failover? You might want to remove the SSH commands from the ASA and re-add them. I strongly suggest you to try that. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Juan Lombana&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please rate helpful posts.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Mar 2013 22:40:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-ssh-after-8-4-5-upgrade/m-p/2144827#M416564</guid>
      <dc:creator>julomban</dc:creator>
      <dc:date>2013-03-27T22:40:37Z</dc:date>
    </item>
    <item>
      <title>I know this is very old, but</title>
      <link>https://community.cisco.com/t5/network-security/problem-with-asa-ssh-after-8-4-5-upgrade/m-p/2144828#M416567</link>
      <description>&lt;P&gt;I know this is very old, but just had the same issue and found this post when I searched the error.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The issue is aaa authentication, see log below&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;%ASA-6-605004: Login denied from 192.168.199.201/55819 to management:192.168.199.100/ssh for user "*****"&lt;BR /&gt;%ASA-6-315011: SSH session from 192.168.199.201 on interface management for user "*****" disconnected by SSH server, reason: "Rejected by server" (0x0d)&lt;BR /&gt;%ASA-6-302014: Teardown TCP connection 44 for management:192.168.199.201/55819 to identity:192.168.199.100/22 duration 0:00:55 bytes 1159 TCP FINs&lt;BR /&gt;%ASA-5-111008: User 'enable_15' executed the 'aaa authentication ssh console LOCAL' command.&lt;BR /&gt;%ASA-5-111010: User 'enable_15', running 'CLI' from IP 192.168.199.201, executed 'aaa authentication ssh console LOCAL'&lt;BR /&gt;%ASA-6-302013: Built inbound TCP connection 45 for management:192.168.199.201/55989 (192.168.199.201/55989) to identity:192.168.199.100/22 (192.168.199.100/22)&lt;BR /&gt;%ASA-6-113012: AAA user authentication Successful : local database : user = cisco&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Adding the following to config resolves the issue&amp;nbsp;:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;aaa authentication ssh console LOCAL&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2016 20:06:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/problem-with-asa-ssh-after-8-4-5-upgrade/m-p/2144828#M416567</guid>
      <dc:creator>NeilGouws</dc:creator>
      <dc:date>2016-05-31T20:06:11Z</dc:date>
    </item>
  </channel>
</rss>

