<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cannot ssh or ping or snmp asa8.05 interface in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cannot-ssh-or-ping-or-snmp-asa8-05-interface/m-p/1425520#M730026</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can ping the standby IP:&lt;/P&gt;&lt;P&gt;-bash-2.05b# ping 10.10.2.11&lt;/P&gt;&lt;P&gt;PING 10.10.2.11 (10.10.2.11): 56 data bytes&lt;/P&gt;&lt;P&gt;64 bytes from 10.10.2.11: icmp_seq=0 ttl=253 time=1.756 ms&lt;/P&gt;&lt;P&gt;64 bytes from 10.10.2.11: icmp_seq=1 ttl=253 time=1.362 ms&lt;/P&gt;&lt;P&gt;64 bytes from 10.10.2.11: icmp_seq=2 ttl=253 time=1.418 ms&lt;/P&gt;&lt;P&gt;^C&lt;/P&gt;&lt;P&gt;--- 10.10.2.11 ping statistics ---&lt;/P&gt;&lt;P&gt;3 packets transmitted, 3 packets received, 0% packet loss&lt;/P&gt;&lt;P&gt;round-trip min/avg/max/stddev = 1.362/1.455/1.756/0.138 ms&lt;/P&gt;&lt;P&gt;-bash-2.05b# ping 10.10.2.10&lt;/P&gt;&lt;P&gt;PING 10.10.2.10 (10.10.2.10): 56 data bytes&lt;/P&gt;&lt;P&gt;^C&lt;/P&gt;&lt;P&gt;--- 10.10.2.10 ping statistics ---&lt;/P&gt;&lt;P&gt;9 packets transmitted, 0 packets received, 100% packet loss&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the failover information looks fine:&lt;/P&gt;&lt;P&gt;chASA01# sh fail          &lt;/P&gt;&lt;P&gt;Failover On&lt;/P&gt;&lt;P&gt;Failover unit Primary&lt;/P&gt;&lt;P&gt;Failover LAN Interface: wireless-state-int Ethernet0/3 (up)&lt;/P&gt;&lt;P&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;/P&gt;&lt;P&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;/P&gt;&lt;P&gt;Interface Policy 1&lt;/P&gt;&lt;P&gt;Monitored Interfaces 9 of 250 maximum&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;Version: Ours 8.0(5), Mate 8.0(5)&lt;/P&gt;&lt;P&gt;Last Failover at: 21:10:07 EST Feb 13 2010&lt;/P&gt;&lt;P&gt;        This host: Primary - Active&lt;/P&gt;&lt;P&gt;                Active time: 521780 (sec)&lt;/P&gt;&lt;P&gt;                slot 0: ASA5510 hw/sw rev (2.0/8.0(5)) status (Up Sys)&lt;/P&gt;&lt;P&gt;                  Interface NAC-wifi-dmz2 (10.10.2.10): Normal         &lt;/P&gt;&lt;P&gt;                  Interface management (10.10.1.15): Normal&lt;/P&gt;&lt;P&gt;                slot 1: empty&lt;/P&gt;&lt;P&gt;        Other host: Secondary - Standby Ready&lt;/P&gt;&lt;P&gt;                Active time: 0 (sec)&lt;/P&gt;&lt;P&gt;                slot 0: ASA5510 hw/sw rev (2.0/8.0(5)) status (Up Sys)&lt;/P&gt;&lt;P&gt;                  Interface NAC-wifi-dmz2 (10.10.2.11): Normal&lt;/P&gt;&lt;P&gt;                  Interface management (10.10.1.16): Normal&lt;/P&gt;&lt;P&gt;                slot 1: empty&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 20 Feb 2010 03:25:50 GMT</pubDate>
    <dc:creator>ajamua</dc:creator>
    <dc:date>2010-02-20T03:25:50Z</dc:date>
    <item>
      <title>cannot ssh or ping or snmp asa8.05 interface</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ssh-or-ping-or-snmp-asa8-05-interface/m-p/1425518#M730024</link>
      <description>&lt;P&gt;After I upgraded to 8.05 from 8.04 I lost my ability to monitor and access an interface on my ASA from devices behind the same interface to be monitored. ASA interface NAC-wifi-dmz2 [10.10.2.10] needs to be monitored by 10.12.1.106 via snmp, icmp, &amp;amp; ssh. Server 10.12.1.106 can be reached via 10.10.2.1 and can be ping by ASA interface NAC-wifi-dmz2:&lt;/P&gt;&lt;P&gt;*************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet0/0.402&lt;/P&gt;&lt;P&gt; vlan 402&lt;/P&gt;&lt;P&gt; nameif NAC-wifi-dmz2&lt;/P&gt;&lt;P&gt; security-level 0&lt;/P&gt;&lt;P&gt; ip address 10.10.2.10 255.255.255.0 standby 10.10.2.11 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;chASA01# ping NAC-wifi-dmz2 10.12.1.106&lt;/P&gt;&lt;P&gt;Type escape sequence to abort.&lt;/P&gt;&lt;P&gt;Sending 5, 100-byte ICMP Echos to 10.12.1.106, timeout is 2 seconds:&lt;/P&gt;&lt;P&gt;!!!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;chASA01# sh route NAC-wifi-dmz2 10.12.1.106 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gateway of last resort is 64.125.212.1 to network 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.10.2.0 255.255.255.0 is directly connected, NAC-wifi-dmz2&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.0 255.0.0.0 [1/0] via 10.10.2.1, NAC-wifi-dmz2&lt;/P&gt;&lt;P&gt;S&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.12.1.106 255.255.255.255 [1/0] via 10.10.2.1, NAC-wifi-dmz2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;chASA01# sh run | in snmp&lt;/P&gt;&lt;P&gt;snmp-server host NAC-wifi-dmz2 10.12.1.106 community *****&lt;/P&gt;&lt;P&gt;snmp-server community *****&lt;/P&gt;&lt;P&gt;snmp-server enable traps snmp authentication linkup linkdown coldstart&lt;/P&gt;&lt;P&gt;**************************************************************************************&lt;/P&gt;&lt;P&gt;chASA01# sh run | in ssh &lt;/P&gt;&lt;P&gt;ssh 10.12.1.0 255.255.255.0 NAC-wifi-dmz2&lt;/P&gt;&lt;P&gt;ssh 10.12.1.106 255.255.255.255 NAC-wifi-dmz2&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;chASA01# sh run icmp&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;icmp unreachable rate-limit 1 burst-size 1&lt;/P&gt;&lt;P&gt;icmp permit any NAC-wifi-dmz2&lt;/P&gt;&lt;P&gt;icmp permit host 10.12.1.106 echo-reply NAC-wifi-dmz2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;chASA01(config)# sh run access-group&lt;/P&gt;&lt;P&gt;access-group 105 in interface NAC-wifi-dmz2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;chASA01(config)# sh run | in access-list 105&lt;/P&gt;&lt;P&gt;access-list 105 extended permit tcp any any &lt;/P&gt;&lt;P&gt;access-list 105 extended permit icmp any any &lt;/P&gt;&lt;P&gt;access-list 105 extended permit udp any any &lt;/P&gt;&lt;P&gt;access-list 105 extended permit gre any any &lt;/P&gt;&lt;P&gt;access-list 105 extended permit esp any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*************************************************************************************&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I try to connect via snmp, ping &amp;amp; ssh from 10.12.1.106 I get this messages:&lt;/P&gt;&lt;P&gt;%ASA-2-106006: Deny inbound UDP from 10.12.1.106/58078 to 10.10.2.10/161 on interface NAC-wifi-dmz2&lt;/P&gt;&lt;P&gt;%ASA-2-106001: Inbound TCP connection denied from 10.12.1.106/39112 to 10.10.2.10/22 flags SYN&amp;nbsp; on interface NAC-wifi-dmz2&lt;/P&gt;&lt;P&gt;%ASA-3-106014: Deny inbound icmp src NAC-wifi-dmz2:10.12.1.106 dst NAC-wifi-dmz2:10.10.2.10 (type 8, code 0)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone help me figure out what the problem here is?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:12:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ssh-or-ping-or-snmp-asa8-05-interface/m-p/1425518#M730024</guid>
      <dc:creator>ajamua</dc:creator>
      <dc:date>2019-03-11T17:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: cannot ssh or ping or snmp asa8.05 interface</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ssh-or-ping-or-snmp-asa8-05-interface/m-p/1425519#M730025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;does "sh fail" status show ok?&lt;/P&gt;&lt;P&gt;Are you able to ping the standby IP 10.10.2.11 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;remove this icmp permit host 10.12.1.106 echo-reply NAC-wifi-dmz2 and try the ping again. That line only lets the firewall ping the host and not the other way around.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Feb 2010 00:57:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ssh-or-ping-or-snmp-asa8-05-interface/m-p/1425519#M730025</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-02-20T00:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: cannot ssh or ping or snmp asa8.05 interface</title>
      <link>https://community.cisco.com/t5/network-security/cannot-ssh-or-ping-or-snmp-asa8-05-interface/m-p/1425520#M730026</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can ping the standby IP:&lt;/P&gt;&lt;P&gt;-bash-2.05b# ping 10.10.2.11&lt;/P&gt;&lt;P&gt;PING 10.10.2.11 (10.10.2.11): 56 data bytes&lt;/P&gt;&lt;P&gt;64 bytes from 10.10.2.11: icmp_seq=0 ttl=253 time=1.756 ms&lt;/P&gt;&lt;P&gt;64 bytes from 10.10.2.11: icmp_seq=1 ttl=253 time=1.362 ms&lt;/P&gt;&lt;P&gt;64 bytes from 10.10.2.11: icmp_seq=2 ttl=253 time=1.418 ms&lt;/P&gt;&lt;P&gt;^C&lt;/P&gt;&lt;P&gt;--- 10.10.2.11 ping statistics ---&lt;/P&gt;&lt;P&gt;3 packets transmitted, 3 packets received, 0% packet loss&lt;/P&gt;&lt;P&gt;round-trip min/avg/max/stddev = 1.362/1.455/1.756/0.138 ms&lt;/P&gt;&lt;P&gt;-bash-2.05b# ping 10.10.2.10&lt;/P&gt;&lt;P&gt;PING 10.10.2.10 (10.10.2.10): 56 data bytes&lt;/P&gt;&lt;P&gt;^C&lt;/P&gt;&lt;P&gt;--- 10.10.2.10 ping statistics ---&lt;/P&gt;&lt;P&gt;9 packets transmitted, 0 packets received, 100% packet loss&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the failover information looks fine:&lt;/P&gt;&lt;P&gt;chASA01# sh fail          &lt;/P&gt;&lt;P&gt;Failover On&lt;/P&gt;&lt;P&gt;Failover unit Primary&lt;/P&gt;&lt;P&gt;Failover LAN Interface: wireless-state-int Ethernet0/3 (up)&lt;/P&gt;&lt;P&gt;Unit Poll frequency 1 seconds, holdtime 15 seconds&lt;/P&gt;&lt;P&gt;Interface Poll frequency 5 seconds, holdtime 25 seconds&lt;/P&gt;&lt;P&gt;Interface Policy 1&lt;/P&gt;&lt;P&gt;Monitored Interfaces 9 of 250 maximum&lt;/P&gt;&lt;P&gt;failover replication http&lt;/P&gt;&lt;P&gt;Version: Ours 8.0(5), Mate 8.0(5)&lt;/P&gt;&lt;P&gt;Last Failover at: 21:10:07 EST Feb 13 2010&lt;/P&gt;&lt;P&gt;        This host: Primary - Active&lt;/P&gt;&lt;P&gt;                Active time: 521780 (sec)&lt;/P&gt;&lt;P&gt;                slot 0: ASA5510 hw/sw rev (2.0/8.0(5)) status (Up Sys)&lt;/P&gt;&lt;P&gt;                  Interface NAC-wifi-dmz2 (10.10.2.10): Normal         &lt;/P&gt;&lt;P&gt;                  Interface management (10.10.1.15): Normal&lt;/P&gt;&lt;P&gt;                slot 1: empty&lt;/P&gt;&lt;P&gt;        Other host: Secondary - Standby Ready&lt;/P&gt;&lt;P&gt;                Active time: 0 (sec)&lt;/P&gt;&lt;P&gt;                slot 0: ASA5510 hw/sw rev (2.0/8.0(5)) status (Up Sys)&lt;/P&gt;&lt;P&gt;                  Interface NAC-wifi-dmz2 (10.10.2.11): Normal&lt;/P&gt;&lt;P&gt;                  Interface management (10.10.1.16): Normal&lt;/P&gt;&lt;P&gt;                slot 1: empty&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 20 Feb 2010 03:25:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cannot-ssh-or-ping-or-snmp-asa8-05-interface/m-p/1425520#M730026</guid>
      <dc:creator>ajamua</dc:creator>
      <dc:date>2010-02-20T03:25:50Z</dc:date>
    </item>
  </channel>
</rss>

