<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FWSM management problem? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fwsm-management-problem/m-p/1259942#M827687</link>
    <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;We have a pair of FWSM Modules (running 4.0.4) within a pair of VSS 6509-E. Traffic is passing OK, management is OK to the primary FWSM (i.e SSH, SNMP) but we cannot get SSH or SNMP management to the secondary FWSM. My questions is whether this is normal, or should remote access be possible - and if so are additional commands required? (fyi the firewall is pingable so routing is good) &lt;/P&gt;&lt;P&gt;Thanks very much &lt;/P&gt;&lt;P&gt;Rob &lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 16:09:17 GMT</pubDate>
    <dc:creator>rob.hicks1</dc:creator>
    <dc:date>2019-03-11T16:09:17Z</dc:date>
    <item>
      <title>FWSM management problem?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-management-problem/m-p/1259942#M827687</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;We have a pair of FWSM Modules (running 4.0.4) within a pair of VSS 6509-E. Traffic is passing OK, management is OK to the primary FWSM (i.e SSH, SNMP) but we cannot get SSH or SNMP management to the secondary FWSM. My questions is whether this is normal, or should remote access be possible - and if so are additional commands required? (fyi the firewall is pingable so routing is good) &lt;/P&gt;&lt;P&gt;Thanks very much &lt;/P&gt;&lt;P&gt;Rob &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:09:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-management-problem/m-p/1259942#M827687</guid>
      <dc:creator>rob.hicks1</dc:creator>
      <dc:date>2019-03-11T16:09:17Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM management problem?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-management-problem/m-p/1259943#M827700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To answer your question, no, this is not normal--you should be able to access your standby FWSM via management protocols like SSH and SNMP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can access the Active unit just fine and you're able to ping the Standby unit, it sounds like your config is OK. I would start by accessing the Standby unit using the 'session slot &lt;SLOT&gt; proc 1' command at the 6509 and checking to make sure the configuration synced normally. At a minimum, you would need something similar to this:&lt;/SLOT&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;! Applied to the appropriate firewall interface&lt;/P&gt;&lt;P&gt;ip address x.x.x.a 255.255.255.0 standby x.x.x.b&lt;/P&gt;&lt;P&gt;! Applied globally&lt;/P&gt;&lt;P&gt;ssh x.x.x.0 255.255.255.0 &lt;INTERFACE_NAME&gt;&lt;/INTERFACE_NAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the config looks OK, I would enable SSH debugging ('debug ssh 15') and try again to connect to the Standby unit. The debug messages that get printed to the screen may give you some insight into what is going on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Aug 2009 12:01:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-management-problem/m-p/1259943#M827700</guid>
      <dc:creator>robertson.michael</dc:creator>
      <dc:date>2009-08-25T12:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: FWSM management problem?</title>
      <link>https://community.cisco.com/t5/network-security/fwsm-management-problem/m-p/1259944#M827740</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As suggested I ran a debug and got the following output :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"firewallabc(config)# Device ssh opened successfully.&lt;/P&gt;&lt;P&gt;SSH0: SSH client: IP = '1.2.3.4'  interface # = 2&lt;/P&gt;&lt;P&gt;SSH: unable to retrieve default host public key.  Please create a default RSA key pair before using SSH&lt;/P&gt;&lt;P&gt;SSH0: Session disconnected by SSH server - error 0x00 "Internal error"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I reset the RSA key and can now management the secondary FWSM via SSH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Aug 2009 13:55:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fwsm-management-problem/m-p/1259944#M827740</guid>
      <dc:creator>rob.hicks1</dc:creator>
      <dc:date>2009-08-25T13:55:05Z</dc:date>
    </item>
  </channel>
</rss>

