<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA 5505 SSH Access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5505-ssh-access/m-p/1129604#M419027</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would also suggest configuring 'debug ssh 255' and watching the output that is generated when you try to connect via SSH. Another one that may shed some light is 'debug npshim 15'. I would recommend enabling these as 2 separate tests (i.e. 'debug ssh 255', test, 'undebug all', 'debug npshim 15', test, 'undebug all').&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take a look through that output and see if it has any explanation as to why the reset is being sent. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 29 Aug 2008 00:59:58 GMT</pubDate>
    <dc:creator>robertson.michael</dc:creator>
    <dc:date>2008-08-29T00:59:58Z</dc:date>
    <item>
      <title>ASA 5505 SSH Access</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssh-access/m-p/1129602#M419022</link>
      <description>&lt;P&gt;I remotely manage an ASA 5505.  In the past, I have been able to access the public interface via SSH.  I upgraded the ASA from 8.0.3 to 8.0.4.  Since the upgrade, I have not been able to access the ASA public (outside) interface with SSH.  I do have ASDM access.  From the ASDM, I see the SSH connection has the TCP 3way handshake then the ASA sends a reset.  From the logs, I see a Built and Teardown.  I have not found any other logs.  I have zeroized and regenerated the RSA key.  Still no SSH connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ideas?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 10:58:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssh-access/m-p/1129602#M419022</guid>
      <dc:creator>rmeans</dc:creator>
      <dc:date>2020-02-21T10:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 SSH Access</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssh-access/m-p/1129603#M419024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sounds like you have already done what is recommended  by regenerating RSA keys, have you tried connecting from a different host to rule out ssh client issues. I have also upgraded to 8.0.4 and have seen couple of strange things not exactly related to ssh  but waiting for it to happen again to repor it in forum..  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you still have this statement if using local user databse  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;B&gt;aaa authentication ssh console LOCAL&lt;/B&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also try  a telnet test from the outside host see if you get back screen ok&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.i.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet  &lt;ASA_OUTSIDE_IP&gt;  22&lt;/ASA_OUTSIDE_IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if no joy try disabling and re enable ssh on outside interface&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;no ssh  &lt;OUTSIDE_HOST_IP&gt; 255.255.255.255 outside &lt;/OUTSIDE_HOST_IP&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then re-enter ssh statement &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Aug 2008 21:05:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssh-access/m-p/1129603#M419024</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2008-08-21T21:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 SSH Access</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssh-access/m-p/1129604#M419027</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rick,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would also suggest configuring 'debug ssh 255' and watching the output that is generated when you try to connect via SSH. Another one that may shed some light is 'debug npshim 15'. I would recommend enabling these as 2 separate tests (i.e. 'debug ssh 255', test, 'undebug all', 'debug npshim 15', test, 'undebug all').&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take a look through that output and see if it has any explanation as to why the reset is being sent. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Aug 2008 00:59:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssh-access/m-p/1129604#M419027</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2008-08-29T00:59:58Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 SSH Access</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssh-access/m-p/1129605#M419029</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please try the following:- &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* ssh 0.0.0.0 0.0.0.0 outside &lt;/P&gt;&lt;P&gt;just to make sure there is translation device on path connecting to ASA outside interface &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* Also regenerate the key &lt;/P&gt;&lt;P&gt;cryto key generate rsa modulus 1024&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* Collect "debug ssh 255" that will confirm if any request is reaching ASA or not&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* Since you are able to access ASDM. Please check the under device we have ssh option checked for authetication from local database &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;check for command &lt;/P&gt;&lt;P&gt;aaa authentication ssh console LOCAL &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* If there is no user on local database pls use pix as username and cisco as password &lt;/P&gt;&lt;P&gt;and enable password blank .. or use configured password&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;* If still things not working send the debug outputs and logs while ssh to firewall &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this will help&lt;/P&gt;&lt;P&gt;manjeet &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Aug 2008 10:23:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssh-access/m-p/1129605#M419029</guid>
      <dc:creator>manjesin</dc:creator>
      <dc:date>2008-08-29T10:23:55Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 SSH Access</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssh-access/m-p/1129606#M419032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have tried to regen the key (no luck), I have confirmed AAA.  I haven't been able to issue any debug commands.  I only have ASDM access.  The CLI from ASDM doesn't allow debug.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I plan to go to the site later today.  I should have console access.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Aug 2008 12:53:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssh-access/m-p/1129606#M419032</guid>
      <dc:creator>rmeans</dc:creator>
      <dc:date>2008-08-29T12:53:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 SSH Access</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssh-access/m-p/1129607#M419035</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe you have some stuck connections, if its not a production box, try a 'clear local-host all'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Farrukh&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Aug 2008 17:44:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssh-access/m-p/1129607#M419035</guid>
      <dc:creator>Farrukh Haroon</dc:creator>
      <dc:date>2008-08-29T17:44:48Z</dc:date>
    </item>
    <item>
      <title>Re: ASA 5505 SSH Access</title>
      <link>https://community.cisco.com/t5/network-security/asa-5505-ssh-access/m-p/1129608#M419038</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I tested one last time before leaving for the new site, SSH access failed.  I went to the site.  Connected to the internal network and tried to SSH to the ASA inside interface.  SSH access worked.  I was prompted to accepted the new key and I was in (I had generated a new RSA key the other day).  I then remotely connected back to my home network.  Connected to the ASA outside interface (SSH).  It worked.  Again, I was prompted to accept the new key and I was in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sadly I didn't capture any debug information.  Thank you for the ideas.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Aug 2008 19:26:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5505-ssh-access/m-p/1129608#M419038</guid>
      <dc:creator>rmeans</dc:creator>
      <dc:date>2008-08-29T19:26:01Z</dc:date>
    </item>
  </channel>
</rss>

