<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to Access the AIP SSM through ASDM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-access-the-aip-ssm-through-asdm/m-p/2078788#M54340</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Many, many thanks K.&amp;nbsp;&amp;nbsp;&amp;nbsp; I'll give it a shot.&amp;nbsp;&amp;nbsp; jc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Dec 2012 14:27:47 GMT</pubDate>
    <dc:creator>jimmyc_2</dc:creator>
    <dc:date>2012-12-05T14:27:47Z</dc:date>
    <item>
      <title>Unable to Access the AIP SSM through ASDM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-the-aip-ssm-through-asdm/m-p/2078782#M54334</link>
      <description>&lt;H3&gt;CISCO Recommendations below:&lt;/H3&gt;&lt;H3&gt;&lt;A name="asdm" target="_blank"&gt;Unable to Access the AIP SSM through ASDM&lt;/A&gt;&lt;/H3&gt;&lt;P&gt;&lt;STRONG&gt;Problem:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;This error message is seen on the GUI.&lt;/P&gt;&lt;BLOCKQUOTE class="jive-quote"&gt;&lt;PRE&gt;Error connecting to sensor. Error Loading Sensor error&lt;/PRE&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;STRONG&gt;Solution:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Check the IPS SSM management interface is &lt;TT&gt;up/down&lt;/TT&gt;, and check its configured IP address, subnet mask and default gateway. This is the interface to access the Cisco Adaptive Security Device Manager (ASDM) Software from the local machine. Try to ping the management interface IP address of IPS SSM from the local machine that you want to access the ASDM. If unable to ping check the ACLs on the sensor&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I tried everything recommended above. I can ping the ASDM host from the FW and from the SSM-10 module. Likewise, I can ping the SSM from the ASDM, and the host machine. I opened the ACLs as wide as possible. I changed IP addresses and masks several times. The management port of the ASA and the SSM, and the PC, are on the same subnet.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A packet trace from the PC to the SSM shows it being blocked by ACL rule, yet I've opened everything wide.&amp;nbsp;&amp;nbsp; I've seen this type of issue before, and it was solved by applying Dual static NAT, but I'm not sure how to do that if all the IPs are on the same subnet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tried everything, need some high-level help.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:50:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-the-aip-ssm-through-asdm/m-p/2078782#M54334</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2019-03-10T12:50:33Z</dc:date>
    </item>
    <item>
      <title>Unable to Access the AIP SSM through ASDM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-the-aip-ssm-through-asdm/m-p/2078783#M54335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a ASA5585-SSP-IPS20 and am having the same problem. Because the ASA does not have a separate route table for the management interface I have to use a default-route on my inside interface. According to this link: &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/quick_start/ips/ips_qsg.html"&gt;http://www.cisco.com/en/US/docs/security/asa/quick_start/ips/ips_qsg.html&lt;/A&gt;&lt;SPAN&gt; I have to configure the management interface of the IPS module in the same VLAN as the inside interface. I have done this and can now&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Ping the IPS host-ip&lt;/P&gt;&lt;P&gt;2. SSH to the IPS&lt;/P&gt;&lt;P&gt;3. Connect to the IPS through https and download the IDM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, a wireshark shows that the connection is immediatly terminated by the IPS with FIN. I'm out of ideas and will have to call TAC in the morning.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2012 06:05:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-the-aip-ssm-through-asdm/m-p/2078783#M54335</guid>
      <dc:creator>k-schwartz</dc:creator>
      <dc:date>2012-12-04T06:05:58Z</dc:date>
    </item>
    <item>
      <title>Unable to Access the AIP SSM through ASDM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-the-aip-ssm-through-asdm/m-p/2078784#M54336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for the reply, let me know what is said.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2012 14:10:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-the-aip-ssm-through-asdm/m-p/2078784#M54336</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2012-12-04T14:10:41Z</dc:date>
    </item>
    <item>
      <title>Unable to Access the AIP SSM through ASDM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-the-aip-ssm-through-asdm/m-p/2078785#M54337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;k-schwartz wrote:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;...&lt;/P&gt; &lt;P&gt;1. Ping the IPS host-ip&lt;/P&gt;&lt;P&gt;2. SSH to the IPS&lt;/P&gt;&lt;P&gt;3. Connect to the IPS through https and download the IDM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, a wireshark shows that the connection is immediatly terminated by the IPS with FIN. I'm out of ideas and will have to call TAC in the morning.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am experiencing the exact same issue with a brand new ASA5515X that I'm setting up.&amp;nbsp; I am using the management0/0 interface for communicating with both the ASA and the AIP-SSM (software-based on this device).&amp;nbsp; I've got two separate IP addresses, one for each.&amp;nbsp; My workstation is directly connected to the same interface.&amp;nbsp; I can ping both ASA and AIP interface addresses, ssh to them both, and access both of them over HTTPS.&amp;nbsp; However, when the ASDM applet attempts to communicate, I get a drop.&amp;nbsp;&amp;nbsp; As k-schwartz said, it doesn't even get to the application layer, the AIP doesn't like something in the SSL negotiation from ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Comparing a capture from a browser (which does work) it appears that the AIP does not like TLS.&amp;nbsp; The opening gambit from both browser and ADSM is to request TLS, but the browser includes a couple of extra flags (renegotiation_info and status_request).&amp;nbsp; The browser reconnects two more times, the last of which is the SSLv3 request which then causes the AIP to send the server cert and continue negotiation.&amp;nbsp; The AIP just drops the connection from ASDM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure how to tweak ASDM SSL and or AIP TLS settings.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2012 19:18:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-the-aip-ssm-through-asdm/m-p/2078785#M54337</guid>
      <dc:creator>rrich-oberlin</dc:creator>
      <dc:date>2012-12-04T19:18:20Z</dc:date>
    </item>
    <item>
      <title>Unable to Access the AIP SSM through ASDM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-the-aip-ssm-through-asdm/m-p/2078786#M54338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I broke open a second new ASA, and have a very similar issue.&amp;nbsp;&amp;nbsp;&amp;nbsp; ASDM will not connect to the sensor.&amp;nbsp;&amp;nbsp; Access list is wide open.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 04 Dec 2012 21:11:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-the-aip-ssm-through-asdm/m-p/2078786#M54338</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2012-12-04T21:11:03Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Access the AIP SSM through ASDM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-the-aip-ssm-through-asdm/m-p/2078787#M54339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The IDM software that comes with ASDM does not support java 1.7. The ASA portion of ASDM supports 1.7 but launching the IPS applet only works with 1.6. The TAC enginner suggested I use the IME (IPS Manager Express) that is available for free on Cisco's website (&lt;A href="http://www.cisco.com/en/US/products/ps9610/tsd_products_support_general_information.html" rel="nofollow"&gt;http://www.cisco.com/en/US/products/ps9610/tsd_products_support_general_information.html&lt;/A&gt;).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been playing around with it today and so far it seems to work pretty well. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 04:43:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-the-aip-ssm-through-asdm/m-p/2078787#M54339</guid>
      <dc:creator>k-schwartz</dc:creator>
      <dc:date>2012-12-05T04:43:04Z</dc:date>
    </item>
    <item>
      <title>Unable to Access the AIP SSM through ASDM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-the-aip-ssm-through-asdm/m-p/2078788#M54340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Many, many thanks K.&amp;nbsp;&amp;nbsp;&amp;nbsp; I'll give it a shot.&amp;nbsp;&amp;nbsp; jc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Dec 2012 14:27:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-the-aip-ssm-through-asdm/m-p/2078788#M54340</guid>
      <dc:creator>jimmyc_2</dc:creator>
      <dc:date>2012-12-05T14:27:47Z</dc:date>
    </item>
    <item>
      <title>Unable to Access the AIP SSM through ASDM</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-access-the-aip-ssm-through-asdm/m-p/2078789#M54341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I know this thread is about a year old, but just wanted to add that after upgrading the SSM to the latest version (7.1(8)E4), I could connect to it via ASDM just fine.&amp;nbsp; Java version is 1.7.0_25 and ASDM version is 7.1(4)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/5/5/167553-IDM_7.1.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IDM Express definitely seems to offer a higher level of monitoring though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Nov 2013 20:21:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-access-the-aip-ssm-through-asdm/m-p/2078789#M54341</guid>
      <dc:creator>johnnylingo</dc:creator>
      <dc:date>2013-11-25T20:21:59Z</dc:date>
    </item>
  </channel>
</rss>

