<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: unable to SSH to CISCO ASA ( ASA software running on FTD-2110 Appliance) in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3813463#M6715</link>
    <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if https is working as it was confirmed that he had access to ASDM than it means the key are generated.&lt;/P&gt;&lt;P&gt;i am curious how is is accessing the ASDM. i am under the impression the ASDM is access able if you only enable the https only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 mgmt&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;now if these above command are configured he will have access to ASDM even without doing the config of local username. having said that if you check the logs he showed. their is unknow username. which point there is no local database configured&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 04 Mar 2019 11:54:46 GMT</pubDate>
    <dc:creator>Sheraz.Salim</dc:creator>
    <dc:date>2019-03-04T11:54:46Z</dc:date>
    <item>
      <title>unable to SSH to CISCO ASA ( ASA software running on FTD-2110 Appliance)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3813417#M6668</link>
      <description>&lt;P&gt;Hello Everyone.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have installed CISCO ASA Version 9.10(1).11 on a FTD-2110 appliance.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This appliance answer on both 192.168.45.1 and 192.168.45.45.&amp;nbsp;&lt;/P&gt;&lt;P&gt;To get to the firepower software you go to 192.168.45.45(then from there you can access the asa) or to get straight to asa you can open ASDM and connect to 192.168.45.1.&amp;nbsp;&lt;/P&gt;&lt;P&gt;HTTP and ASDM works, SSH isn't.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have configured SSH as shown in Cisco documentation and it's doesn't work.&lt;/P&gt;&lt;P&gt;tried to solve this myself with no success.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Related Configuration:&amp;nbsp;&lt;/P&gt;&lt;P&gt;ciscoasa(config)# show running-config all ssh&lt;BR /&gt;ssh stricthostkeycheck&lt;BR /&gt;ssh 192.168.45.0 255.255.255.0 management&lt;BR /&gt;ssh timeout 5&lt;BR /&gt;ssh version 2&lt;BR /&gt;ssh cipher encryption medium&lt;BR /&gt;ssh cipher integrity medium&lt;BR /&gt;ssh key-exchange group dh-group1-sha1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Local Username was configured and the following command&amp;nbsp;&lt;/P&gt;&lt;PRE&gt;aaa authentication ssh console LOCAL&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;I see the Drops on ASDM ( ssh access file show the drops on ASDM).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anybody come across this and solve this?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:53:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3813417#M6668</guid>
      <dc:creator>ariel2424</dc:creator>
      <dc:date>2020-02-21T16:53:24Z</dc:date>
    </item>
    <item>
      <title>Re: unable to SSH to CISCO ASA ( ASA software running on FTD-2110 Appliance)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3813427#M6669</link>
      <description>&lt;P&gt;have to define a local user on ASA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;username admin priv 15 password cisco123&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 10:28:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3813427#M6669</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-03-04T10:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: unable to SSH to CISCO ASA ( ASA software running on FTD-2110 Appliance)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3813441#M6712</link>
      <description>&lt;P&gt;Did you generate an rsa key?&lt;/P&gt;
&lt;PRE&gt;conf t
crypto key generate rsa mod 2048&lt;BR /&gt;end&lt;/PRE&gt;</description>
      <pubDate>Mon, 04 Mar 2019 10:54:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3813441#M6712</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-03-04T10:54:43Z</dc:date>
    </item>
    <item>
      <title>Re: unable to SSH to CISCO ASA ( ASA software running on FTD-2110 Appliance)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3813463#M6715</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/326046"&gt;@Marvin Rhoads&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if https is working as it was confirmed that he had access to ASDM than it means the key are generated.&lt;/P&gt;&lt;P&gt;i am curious how is is accessing the ASDM. i am under the impression the ASDM is access able if you only enable the https only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;http server enable&lt;/P&gt;&lt;P&gt;http 0.0.0.0 0.0.0.0 mgmt&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;now if these above command are configured he will have access to ASDM even without doing the config of local username. having said that if you check the logs he showed. their is unknow username. which point there is no local database configured&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 11:54:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3813463#M6715</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-03-04T11:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: unable to SSH to CISCO ASA ( ASA software running on FTD-2110 Appliance)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3813472#M6717</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/287680"&gt;@Sheraz.Salim&lt;/a&gt;&amp;nbsp;- good point.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have also seen users lately using old putty clients and newer ASA software whereby the ssh negotiation fails due to lack of support for newer key exchanges in the library used by the client software. That problem would affect ssh but not ASDM (which uses ssl/tls libraries included in the end user's Java installation).&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 12:06:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3813472#M6717</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-03-04T12:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: unable to SSH to CISCO ASA ( ASA software running on FTD-2110 Appliance)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3813510#M6720</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;As a mention previously Local username and password is defined. I don't know why this error appeared&amp;nbsp;&lt;/P&gt;&lt;P&gt;http server is enable by default on the ASA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 13:23:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3813510#M6720</guid>
      <dc:creator>ariel2424</dc:creator>
      <dc:date>2019-03-04T13:23:21Z</dc:date>
    </item>
    <item>
      <title>Re: unable to SSH to CISCO ASA ( ASA software running on FTD-2110 Appliance)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3813513#M6723</link>
      <description>&lt;P&gt;Hi Marvin,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using the latest Putty version.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 13:25:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3813513#M6723</guid>
      <dc:creator>ariel2424</dc:creator>
      <dc:date>2019-03-04T13:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: unable to SSH to CISCO ASA ( ASA software running on FTD-2110 Appliance)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3813572#M6728</link>
      <description>&lt;P&gt;OK - good to know.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd try a packet capture during an attempted connection to see what's going on. Open it up in Wireshark and have a look at the back and forth.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2019 14:59:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3813572#M6728</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-03-04T14:59:19Z</dc:date>
    </item>
    <item>
      <title>Re: unable to SSH to CISCO ASA ( ASA software running on FTD-2110 Appliance)</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3877319#M6730</link>
      <description>YES !&lt;BR /&gt;Had the issue last year: from my notes:&lt;BR /&gt;I had SSH issues in 9.9.1 plain vanilla&lt;BR /&gt;I then Upgraded to 9.9.1.3 interim, only to hit a new failover bug&lt;BR /&gt;I then upgraded to 9.9.1.4 interim … and be happy !&lt;BR /&gt;&lt;BR /&gt;The SSH issue could as workaround be fixed by reload, this was before I upgraded&lt;BR /&gt;sad if the bug has been drop over in the 9.10 track ... try get the latest Interim and upgrade the bundle&lt;BR /&gt;</description>
      <pubDate>Fri, 21 Jun 2019 09:56:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-ssh-to-cisco-asa-asa-software-running-on-ftd-2110/m-p/3877319#M6730</guid>
      <dc:creator>mbilgrav</dc:creator>
      <dc:date>2019-06-21T09:56:16Z</dc:date>
    </item>
  </channel>
</rss>

