<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA cannot logon w/ ADSM (SSH is OK) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-cannot-logon-w-adsm-ssh-is-ok/m-p/1930351#M436178</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;unfortunately the result is the same -- "contacting the device" is all I get...&lt;/P&gt;&lt;P&gt;I can access the page from the browser (as I could before), I can start the java ADSM, enter my credentials, then freeze...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 May 2012 09:27:00 GMT</pubDate>
    <dc:creator>johanhofmans</dc:creator>
    <dc:date>2012-05-23T09:27:00Z</dc:date>
    <item>
      <title>ASA cannot logon w/ ADSM (SSH is OK)</title>
      <link>https://community.cisco.com/t5/network-security/asa-cannot-logon-w-adsm-ssh-is-ok/m-p/1930349#M436176</link>
      <description>&lt;P&gt;all,&lt;/P&gt;&lt;P&gt;since yesterday, I cannot logon with adsm anymore.&lt;/P&gt;&lt;P&gt;when I run adsm, I type in my pw, and the screen keeps displaying "contacting the device". No timeout, just stays this way.&lt;/P&gt;&lt;P&gt;I've updated the java version, no luck.&lt;/P&gt;&lt;P&gt;I can connect with SSH with no problem.&lt;/P&gt;&lt;P&gt;device = asa5550, 8.2(1) asdm 6.2(1)&lt;/P&gt;&lt;P&gt;pieces of the config:&lt;/P&gt;&lt;P&gt;--- &lt;/P&gt;&lt;P&gt;BE01NF21#sh run all ssl&lt;/P&gt;&lt;P&gt;ssl server-version any&lt;/P&gt;&lt;P&gt;ssl client-version any&lt;/P&gt;&lt;P&gt;ssl encryption rc4-sha1 aes128-sha1 aes256-sha1 3des-sha1&lt;/P&gt;&lt;P&gt;BE01NF21#sh asp table socket&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Protocol&amp;nbsp; Socket&amp;nbsp;&amp;nbsp;&amp;nbsp; Local Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Foreign Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; State&lt;/P&gt;&lt;P&gt;SSL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 000028ef&amp;nbsp; 192.168.126.1:443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0:*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LISTEN&lt;/P&gt;&lt;P&gt;TCP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 000047df&amp;nbsp; 192.168.126.1:22&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0.0.0.0:*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LISTEN&lt;/P&gt;&lt;P&gt;TCP&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0123e588&amp;nbsp; 192.168.126.1:22&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.126.3:26807&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ESTAB&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;(126.1 is the interface I connect to)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;output of debug http 255:&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;HTTP: processing ASDM request [/admin/version.prop] with cookie-based authentication (aware_webvpn_conf.re2c:398)&lt;/P&gt;&lt;P&gt;HTTP: check admin session. Cookie index [-1][0]&lt;/P&gt;&lt;P&gt;HTTP: client certificate required = 0&lt;/P&gt;&lt;P&gt;--- no further output&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On another ASA device the debug output is different (asdm does work with this device):&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;HTTP: processing ASDM request [/admin/version.prop] (aware_webvpn_conf.re2c:417)&lt;/P&gt;&lt;P&gt;HTTP: Do not check session. Reasons: not required=[0], no AAA=[1], IPv6=[0] &lt;/P&gt;&lt;P&gt;HTTP: session verified =&amp;nbsp; [0]&lt;/P&gt;&lt;P&gt;HTTP: processing GET URL '/admin/version.prop' from host&lt;/P&gt;&lt;P&gt;etc...&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;notice that there is no "with cookie-based authentication" here -- is this relevant?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rebooting the device is not really an option... Does anyone have another idea ??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;THANKS !!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:10:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cannot-logon-w-adsm-ssh-is-ok/m-p/1930349#M436176</guid>
      <dc:creator>johanhofmans</dc:creator>
      <dc:date>2019-03-11T23:10:21Z</dc:date>
    </item>
    <item>
      <title>ASA cannot logon w/ ADSM (SSH is OK)</title>
      <link>https://community.cisco.com/t5/network-security/asa-cannot-logon-w-adsm-ssh-is-ok/m-p/1930350#M436177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have any webvpn configured on port 443? Try enabling ASDM access onany other port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;https server enable 8443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and then access from browser:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://"&gt;http://&lt;/A&gt;&lt;SPAN&gt;&lt;ASA ip="" address=""&gt;:8443&lt;/ASA&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 09:18:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cannot-logon-w-adsm-ssh-is-ok/m-p/1930350#M436177</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-05-23T09:18:02Z</dc:date>
    </item>
    <item>
      <title>ASA cannot logon w/ ADSM (SSH is OK)</title>
      <link>https://community.cisco.com/t5/network-security/asa-cannot-logon-w-adsm-ssh-is-ok/m-p/1930351#M436178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;unfortunately the result is the same -- "contacting the device" is all I get...&lt;/P&gt;&lt;P&gt;I can access the page from the browser (as I could before), I can start the java ADSM, enter my credentials, then freeze...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 09:27:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cannot-logon-w-adsm-ssh-is-ok/m-p/1930351#M436178</guid>
      <dc:creator>johanhofmans</dc:creator>
      <dc:date>2012-05-23T09:27:00Z</dc:date>
    </item>
    <item>
      <title>ASA cannot logon w/ ADSM (SSH is OK)</title>
      <link>https://community.cisco.com/t5/network-security/asa-cannot-logon-w-adsm-ssh-is-ok/m-p/1930352#M436179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you re-isnatll the ASDM launcher on the machine??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible for you to upgrade to latest ASDM software like 6.4.7 or 6.4.9, they are available on cisco site.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 09:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cannot-logon-w-adsm-ssh-is-ok/m-p/1930352#M436179</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-05-23T09:43:11Z</dc:date>
    </item>
    <item>
      <title>ASA cannot logon w/ ADSM (SSH is OK)</title>
      <link>https://community.cisco.com/t5/network-security/asa-cannot-logon-w-adsm-ssh-is-ok/m-p/1930353#M436180</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;asdm 647 now&lt;/P&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; still the same. I'm getting the impression that something is wrong internally and a reboot could solve it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other thoughts?&lt;/P&gt;&lt;P&gt;it's very much appreciated - i hate to have to tell my cio that i have to reboot this device - uptime 3yrs+ now! ...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 10:09:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cannot-logon-w-adsm-ssh-is-ok/m-p/1930353#M436180</guid>
      <dc:creator>johanhofmans</dc:creator>
      <dc:date>2012-05-23T10:09:36Z</dc:date>
    </item>
    <item>
      <title>ASA cannot logon w/ ADSM (SSH is OK)</title>
      <link>https://community.cisco.com/t5/network-security/asa-cannot-logon-w-adsm-ssh-is-ok/m-p/1930354#M436181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have any command like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa authentication http console LOCAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;can you remove it and try again.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;is it same with the launcher and browser??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 10:24:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cannot-logon-w-adsm-ssh-is-ok/m-p/1930354#M436181</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-05-23T10:24:38Z</dc:date>
    </item>
    <item>
      <title>ASA cannot logon w/ ADSM (SSH is OK)</title>
      <link>https://community.cisco.com/t5/network-security/asa-cannot-logon-w-adsm-ssh-is-ok/m-p/1930355#M436182</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;YES! I indeed had this "aaa authentication http console LOCAL"&lt;/P&gt;&lt;P&gt;Once I removed it, I could logon again.&lt;/P&gt;&lt;P&gt;But to my knowledge, this command was always there - very strange that this now was causing issues...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;THANKS !!!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 10:30:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cannot-logon-w-adsm-ssh-is-ok/m-p/1930355#M436182</guid>
      <dc:creator>johanhofmans</dc:creator>
      <dc:date>2012-05-23T10:30:51Z</dc:date>
    </item>
    <item>
      <title>ASA cannot logon w/ ADSM (SSH is OK)</title>
      <link>https://community.cisco.com/t5/network-security/asa-cannot-logon-w-adsm-ssh-is-ok/m-p/1930356#M436183</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That's great!!!!!!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's the reason - &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtt45397"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCtt45397&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;BR /&gt;Varun Rao &lt;BR /&gt;Security Team, &lt;BR /&gt;Cisco TAC&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 May 2012 10:59:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cannot-logon-w-adsm-ssh-is-ok/m-p/1930356#M436183</guid>
      <dc:creator>varrao</dc:creator>
      <dc:date>2012-05-23T10:59:32Z</dc:date>
    </item>
  </channel>
</rss>

