<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA 5585 cannot connect to context active in failover group 2 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-5585-cannot-connect-to-context-active-in-failover-group-2/m-p/1755577#M493849</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried regenerating the key with no luck so I got fed up and just rebooted the pair of firewalls.&amp;nbsp; Lucky for me these are a new deployment and don't go live until this weekend!&amp;nbsp; &lt;SPAN __jive_emoticon_name="devil" __jive_macro_name="emoticon" class="jive_macro jive_macro_emoticon" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything is working as expected now.&amp;nbsp; I can SSH into all the active contexts between the two firewalls and failover groups.&amp;nbsp; I am thinking that there may still be a bug with the failover.&amp;nbsp; Everything on this seemed to be working fine until after I tested the failover by forcing the groups back and forth between the two firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wish I could find some more in depth documentation on active/active mode and the methodology for sharing keys, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The good thing in all this is that ASDM and console access was working correctly so that I could get into the various contexts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 11 Nov 2011 15:35:16 GMT</pubDate>
    <dc:creator>John Galietta</dc:creator>
    <dc:date>2011-11-11T15:35:16Z</dc:date>
    <item>
      <title>ASA 5585 cannot connect to context active in failover group 2</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-cannot-connect-to-context-active-in-failover-group-2/m-p/1755573#M493830</link>
      <description>&lt;P&gt;I am setting up a new pair of ASA 5585's in a multi-context, active/active failover design.&amp;nbsp; I cannot create management SSH connection to the contexts that are assigned to failover group 2.&amp;nbsp; With all the security contexts that are assigned to failover group 1 I can SSH to the inside interface IP and login without a problem.&amp;nbsp; When I try to do that to the group 2 contexts there is no response from the firewall at all, PuTTY just times out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My firewalls are running version 8.2(4).&amp;nbsp; The contexts seem to be functioning normally in all other respects.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 21:47:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-cannot-connect-to-context-active-in-failover-group-2/m-p/1755573#M493830</guid>
      <dc:creator>John Galietta</dc:creator>
      <dc:date>2019-03-11T21:47:50Z</dc:date>
    </item>
    <item>
      <title>ASA 5585 cannot connect to context active in failover group 2</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-cannot-connect-to-context-active-in-failover-group-2/m-p/1755574#M493834</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Take a look at this document that provides some additional troubleshooting steps for narrowing down this type of problem:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/docs/DOC-13012"&gt;https://supportforums.cisco.com/docs/DOC-13012#Unable_to_ssh&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Nov 2011 14:29:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-cannot-connect-to-context-active-in-failover-group-2/m-p/1755574#M493834</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2011-11-11T14:29:39Z</dc:date>
    </item>
    <item>
      <title>ASA 5585 cannot connect to context active in failover group 2</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-cannot-connect-to-context-active-in-failover-group-2/m-p/1755575#M493839</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for the suggestions Mike but I am still stumped.&amp;nbsp; I am running 8.2(4) and it is supposed to have the issues refered to in that doc fixed.&amp;nbsp; I did check the asp sockets and the firewall is listening on port 22.&amp;nbsp; I tried deleting and restoring the SSH config but that had no affect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am able to SSH to the standby IP address for the context, but I cannot connect to the active one.&amp;nbsp; On a capture done on the active context I do see the packets coming in from the PC to port 22 of the context IP but I am not seeing any response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could this be an rsa key issue between the active and standby context?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Nov 2011 15:07:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-cannot-connect-to-context-active-in-failover-group-2/m-p/1755575#M493839</guid>
      <dc:creator>John Galietta</dc:creator>
      <dc:date>2011-11-11T15:07:00Z</dc:date>
    </item>
    <item>
      <title>ASA 5585 cannot connect to context active in failover group 2</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-cannot-connect-to-context-active-in-failover-group-2/m-p/1755576#M493845</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To rule that out you can just generate a new key on the problem contexts. You can use the following command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto key generate rsa mod 1024&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Nov 2011 15:17:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-cannot-connect-to-context-active-in-failover-group-2/m-p/1755576#M493845</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2011-11-11T15:17:40Z</dc:date>
    </item>
    <item>
      <title>ASA 5585 cannot connect to context active in failover group 2</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-cannot-connect-to-context-active-in-failover-group-2/m-p/1755577#M493849</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried regenerating the key with no luck so I got fed up and just rebooted the pair of firewalls.&amp;nbsp; Lucky for me these are a new deployment and don't go live until this weekend!&amp;nbsp; &lt;SPAN __jive_emoticon_name="devil" __jive_macro_name="emoticon" class="jive_macro jive_macro_emoticon" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything is working as expected now.&amp;nbsp; I can SSH into all the active contexts between the two firewalls and failover groups.&amp;nbsp; I am thinking that there may still be a bug with the failover.&amp;nbsp; Everything on this seemed to be working fine until after I tested the failover by forcing the groups back and forth between the two firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wish I could find some more in depth documentation on active/active mode and the methodology for sharing keys, etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The good thing in all this is that ASDM and console access was working correctly so that I could get into the various contexts.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Nov 2011 15:35:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-cannot-connect-to-context-active-in-failover-group-2/m-p/1755577#M493849</guid>
      <dc:creator>John Galietta</dc:creator>
      <dc:date>2011-11-11T15:35:16Z</dc:date>
    </item>
    <item>
      <title>ASA 5585 cannot connect to context active in failover group 2</title>
      <link>https://community.cisco.com/t5/network-security/asa-5585-cannot-connect-to-context-active-in-failover-group-2/m-p/1755578#M493853</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Interesting. If the issue returns, please open a TAC case for this so it can be investigated. Otherwise, I would suggest trying the latest 8.2.5 image to rule out any known bugs since this isn't live yet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 11 Nov 2011 15:38:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-5585-cannot-connect-to-context-active-in-failover-group-2/m-p/1755578#M493853</guid>
      <dc:creator>mirober2</dc:creator>
      <dc:date>2011-11-11T15:38:11Z</dc:date>
    </item>
  </channel>
</rss>

