<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SSH stopped working on ASA5520 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssh-stopped-working-on-asa5520/m-p/1922628#M453194</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only bug related to management connections I have run into was with 8.2(1) or 8.2(2) where a single Failover event of the firewall pair would cause problems with the management connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried changing the active firewall or is it too risky/problematic considering the network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The bug I mentioned was this i guess (just looked in the Bug Toolkit)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;CSCti72411&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="5" cellspacing="2" style="width: 100%;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD colspan="2" style="font-size: 88%; padding: 8px 8px 8px 8px;"&gt;&lt;STRONG&gt; ASA 8.2.3 may not accept management connections after failover. &lt;/STRONG&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="font-size: 88%; padding: 0px 8px 8px 8px;" valign="top"&gt;&lt;STRONG&gt;Symptom:&lt;/STRONG&gt;&lt;BR /&gt;ASA may not accept new management connections even though everything is&lt;BR /&gt;properly configured. SSH and ASDM may fail when connecting to the inside&lt;BR /&gt;interface while working when connecting to the outside and DMZ interfaces. All&lt;BR /&gt;management connections work to the standby unit if this is a failover pair.&lt;P&gt;&lt;/P&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;:&lt;/STRONG&gt;&lt;BR /&gt;This was first found on ASA 8.2.3 and after failover. &lt;P&gt;&lt;/P&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;BR /&gt;Downgrade to previous version of code.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't see your software version in the list "Fixed In". Though I think we still have Failover pairs in same software level as yours and havent run into this problem after the last (and only time so far) time. And one would think that the newer version (compared to 8.2(3)) would fix the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Fixed-In &lt;/P&gt;&lt;P&gt;&lt;A href="http://tools.cisco.com/Support/BugToolKit/images/Field%20Definitions.html" rel="nofollow" target="_blank"&gt; &lt;IMG alt="Fixed-in" border="0" height="14" id="Fixed_Image" name="Fixed_Image" src="http://tools.cisco.com/Support/BugToolKit/images/icon_info.gif" style="text-decoration: none;" width="13" /&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 8.2(3.5)&lt;/P&gt;&lt;P&gt; 8.2(4)&lt;/P&gt;&lt;P&gt; 8.3(2.5)&lt;/P&gt;&lt;P&gt; 8.4(1)&lt;/P&gt;&lt;P&gt; 100.7(9.1)M&lt;/P&gt;&lt;P&gt; 100.5(5.40)M&lt;/P&gt;&lt;P&gt; 100.7(0.54)M&lt;/P&gt;&lt;P&gt; 100.7(5.18)M&lt;/P&gt;&lt;P&gt; 8.2(3.104)&lt;/P&gt;&lt;P&gt; 8.2(3.220)&lt;/P&gt;&lt;P&gt; 100.7(6.6)M&lt;/P&gt;&lt;P&gt; 100.7(8.1)M&lt;/P&gt;&lt;P&gt; 8.4(0.99)&lt;/P&gt;&lt;P&gt; 8.1(2.49)&lt;/P&gt;&lt;P&gt; 8.6(0.0) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 Mar 2012 20:43:43 GMT</pubDate>
    <dc:creator>Jouni Forss</dc:creator>
    <dc:date>2012-03-28T20:43:43Z</dc:date>
    <item>
      <title>SSH stopped working on ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/ssh-stopped-working-on-asa5520/m-p/1922627#M453193</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can no longer SSH to a primary active firewall. It had all of a sudden stopped working.&amp;nbsp; However I am able to SSH to the secondary standby firewall without any problems. I did try to regenerate the RSA key on the primary fw, but still unable to connect. The only way I can connect to it is by using telnet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I ran the "show asp table socket" command and I'm seeing port 22 listening on the primary IP address (not the standby), foreign address is 0.0.0.0:*. &lt;/P&gt;&lt;P&gt;I did a packet capture on port 22 on the inside inside, seeing my request hit the fw and then right away a reset back from the fw. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;version&lt;/STRONG&gt; 8.2.(5) &lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;model&lt;/STRONG&gt; ASA5520 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone know if I'm hitting a bug in the software version I'm running? Or what else can I check before rebooting the primary fw? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:48:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-stopped-working-on-asa5520/m-p/1922627#M453193</guid>
      <dc:creator>johng231</dc:creator>
      <dc:date>2019-03-11T22:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: SSH stopped working on ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/ssh-stopped-working-on-asa5520/m-p/1922628#M453194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only bug related to management connections I have run into was with 8.2(1) or 8.2(2) where a single Failover event of the firewall pair would cause problems with the management connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried changing the active firewall or is it too risky/problematic considering the network?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The bug I mentioned was this i guess (just looked in the Bug Toolkit)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;CSCti72411&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;TABLE border="0" cellpadding="5" cellspacing="2" style="width: 100%;"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD colspan="2" style="font-size: 88%; padding: 8px 8px 8px 8px;"&gt;&lt;STRONG&gt; ASA 8.2.3 may not accept management connections after failover. &lt;/STRONG&gt; &lt;/TD&gt;&lt;/TR&gt;&lt;TR&gt;&lt;TD style="font-size: 88%; padding: 0px 8px 8px 8px;" valign="top"&gt;&lt;STRONG&gt;Symptom:&lt;/STRONG&gt;&lt;BR /&gt;ASA may not accept new management connections even though everything is&lt;BR /&gt;properly configured. SSH and ASDM may fail when connecting to the inside&lt;BR /&gt;interface while working when connecting to the outside and DMZ interfaces. All&lt;BR /&gt;management connections work to the standby unit if this is a failover pair.&lt;P&gt;&lt;/P&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;STRONG&gt;Conditions&lt;/STRONG&gt;:&lt;/STRONG&gt;&lt;BR /&gt;This was first found on ASA 8.2.3 and after failover. &lt;P&gt;&lt;/P&gt;&lt;STRONG&gt;Workaround:&lt;/STRONG&gt;&lt;BR /&gt;Downgrade to previous version of code.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't see your software version in the list "Fixed In". Though I think we still have Failover pairs in same software level as yours and havent run into this problem after the last (and only time so far) time. And one would think that the newer version (compared to 8.2(3)) would fix the problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;Fixed-In &lt;/P&gt;&lt;P&gt;&lt;A href="http://tools.cisco.com/Support/BugToolKit/images/Field%20Definitions.html" rel="nofollow" target="_blank"&gt; &lt;IMG alt="Fixed-in" border="0" height="14" id="Fixed_Image" name="Fixed_Image" src="http://tools.cisco.com/Support/BugToolKit/images/icon_info.gif" style="text-decoration: none;" width="13" /&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 8.2(3.5)&lt;/P&gt;&lt;P&gt; 8.2(4)&lt;/P&gt;&lt;P&gt; 8.3(2.5)&lt;/P&gt;&lt;P&gt; 8.4(1)&lt;/P&gt;&lt;P&gt; 100.7(9.1)M&lt;/P&gt;&lt;P&gt; 100.5(5.40)M&lt;/P&gt;&lt;P&gt; 100.7(0.54)M&lt;/P&gt;&lt;P&gt; 100.7(5.18)M&lt;/P&gt;&lt;P&gt; 8.2(3.104)&lt;/P&gt;&lt;P&gt; 8.2(3.220)&lt;/P&gt;&lt;P&gt; 100.7(6.6)M&lt;/P&gt;&lt;P&gt; 100.7(8.1)M&lt;/P&gt;&lt;P&gt; 8.4(0.99)&lt;/P&gt;&lt;P&gt; 8.1(2.49)&lt;/P&gt;&lt;P&gt; 8.6(0.0) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2012 20:43:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-stopped-working-on-asa5520/m-p/1922628#M453194</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-03-28T20:43:43Z</dc:date>
    </item>
    <item>
      <title>Re: SSH stopped working on ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/ssh-stopped-working-on-asa5520/m-p/1922629#M453195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I failed it over and the SSH works now. I'll wait and see if it occurs again. Is there a version of the 8.2.x that's stable where this doesn't happen? I went with 8.2.x code so I can have the latest VPN features as I'm using the ASA5520 only for VPN endpoints. I don't want to have to downgrade back to 7.2.5(GD). This bug seems to be a common problem with a lot of the 8.x versions.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2012 13:36:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-stopped-working-on-asa5520/m-p/1922629#M453195</guid>
      <dc:creator>johng231</dc:creator>
      <dc:date>2012-03-29T13:36:56Z</dc:date>
    </item>
    <item>
      <title>SSH stopped working on ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/ssh-stopped-working-on-asa5520/m-p/1922630#M453196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We ran into the SSH management problem after Failover on a ASA pair that were running 8.2(1)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We updated the pair to 8.2(2) which it has been ever since without problems&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But then again, on another customer we ran into a problem with software 8.2(2) which encountered a bug where ASA wouldnt forward traffic anymore to a L2L VPN connection.Specifically the customer had 2 networks that connected to remote site. Other ones traffic worked flawlesly, others traffic either got dropped on the ASA or "thrown" straight to Internet without encryption/encapsulation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The L2L VPN problem was corrected by doing simple Failover. Though we updated to 8.2(5) which has worked fine ever since.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our other customer has 8.2 software and almost 20 L2L VPNs and has yet to face similiar problem with same software so its either really really random or the ASA hardware model (customers have different hw model of ASAs) has something to do with it...can' really say for sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And if the above wasn't enough confusing for you &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; We also have a failover pair running still in 8.2(1) which hasnt faced this SSH management problem even when failover happens either because of manual failover or failover because of network connectivity problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2012 13:58:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-stopped-working-on-asa5520/m-p/1922630#M453196</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-03-29T13:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: SSH stopped working on ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/ssh-stopped-working-on-asa5520/m-p/1922631#M453197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It sounds like any of the 8x code is very buggy still. I'm going to proceed and downgrade back to 7.2.5(GD). We don't run into any of these problems and it seems to be a very stable code. We just won't get the other features and the use of the higher ASDM versions in the 8x. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 29 Mar 2012 14:24:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-stopped-working-on-asa5520/m-p/1922631#M453197</guid>
      <dc:creator>johng231</dc:creator>
      <dc:date>2012-03-29T14:24:41Z</dc:date>
    </item>
    <item>
      <title>Re: SSH stopped working on ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/ssh-stopped-working-on-asa5520/m-p/1922632#M453198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just want to let everyone know it happened again on version 8.2.5. The problem is also with 8.2.5 now. I've opened up a case about this. I'll downgrade back to 7.2.5(GD). &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2012 13:12:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-stopped-working-on-asa5520/m-p/1922632#M453198</guid>
      <dc:creator>johng231</dc:creator>
      <dc:date>2012-04-05T13:12:49Z</dc:date>
    </item>
    <item>
      <title>SSH stopped working on ASA5520</title>
      <link>https://community.cisco.com/t5/network-security/ssh-stopped-working-on-asa5520/m-p/1922633#M453199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How about trying software 8.2(4) thats listed in the "Fixed in" that I copied earlier?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or is the software available for download even. Atleast we dont have it on any ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Jouni&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 05 Apr 2012 13:17:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-stopped-working-on-asa5520/m-p/1922633#M453199</guid>
      <dc:creator>Jouni Forss</dc:creator>
      <dc:date>2012-04-05T13:17:56Z</dc:date>
    </item>
  </channel>
</rss>

