<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Quirky one: Logging in  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/quirky-one-logging-in/m-p/1177709#M859916</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Handsy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did do a debug before your reply and I got:&lt;/P&gt;&lt;P&gt;SSH2 0: waiting for SSH2_MSG_NEWKEYSSSH0: TCP read failed, error code = 0x86300003 "TCP connection closed"&lt;/P&gt;&lt;P&gt;SSH0: receive SSH message: [no message ID: variable *data is NULL]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SSH2 0: Unexpected mesg type receivedSSH0: Session disconnected by SSH server - error 0x00 "Internal error"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;... but as it's a/hrs here I thought "stuff it" and rebooted. It is not the first time it has gone down since the weekend tho. Then when I tried my trusty linux SSH I was again denied but this time with the good looking "WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I deleted the key in known_hosts and now I am back in. But I don't understand it as telnet would not work either, now it does of course. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hate 'fixing' things with a reboot ... it's so, like, microsoft &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers anyways,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 May 2009 09:04:34 GMT</pubDate>
    <dc:creator>m.surtees</dc:creator>
    <dc:date>2009-05-12T09:04:34Z</dc:date>
    <item>
      <title>Quirky one: Logging in</title>
      <link>https://community.cisco.com/t5/network-security/quirky-one-logging-in/m-p/1177707#M859914</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm not sure what's missing here. I moved a FW over the weekend and now only have console access. It's a 5520 running 8.0(3). From the config I have the usual:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssh scopy enable&lt;/P&gt;&lt;P&gt;ssh 10.x.0.0 255.255.0.0 Axx&lt;/P&gt;&lt;P&gt;ssh timeout 10&lt;/P&gt;&lt;P&gt;ssh version 2&lt;/P&gt;&lt;P&gt;telnet 10.x.0.0 255.255.0.0 Axx&lt;/P&gt;&lt;P&gt;telnet timeout 120&lt;/P&gt;&lt;P&gt;management-access Axx &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- I've zeroized and regenerated the rsa key.&lt;/P&gt;&lt;P&gt;- The Axx int is up and up and I can ping it from the 10.x.0.0 network. Axx is also the inside interface security-100. Managemnet0/0 is in shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The following logs are generated when telneting and ssh respectively (same except for d-port):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;17:03:03: %ASA-6-302013: Built inbound TCP connection 8100 for ASG:10.x.14.14/1898 (10.x.14.14/1898) to NP Identity Ifc:10.x.109.10/23 (10.x.109.10/23)&lt;/P&gt;&lt;P&gt;17:03:03: %ASA-6-302014: Teardown TCP connection 8100 for ASG:10.x.14.14/1898 to NP Identity Ifc:10.x.109.10/23 duration 0:00:00 bytes 0 TCP Reset-I&lt;/P&gt;&lt;P&gt;17:19:41: %ASA-6-302013: Built inbound TCP connection 8270 for ASG:10.x.0.60/33251 (10.x.0.60/33251) to NP Identity Ifc:10.x.109.10/22 (10.x.109.10/22)&lt;/P&gt;&lt;P&gt;17:19:41: %ASA-6-302014: Teardown TCP connection 8270 for ASG:10.x.0.60/33251 to NP Identity Ifc:10.x.109.10/22 duration 0:00:00 bytes 0 TCP Reset-I&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From PuTTY I just get "Network error: Software caused connection abort". From OpenSSH_3.9p1, OpenSSL 0.9.7a Feb 19 2003 I get a "ssh_exchange_identification: read: Connection reset by peer" and back to bash prompt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Both these clients worked fine on this FW before the power-down and move and still work on all other ASAs and PIXs and ... Very little luck finding anything on Web.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help much appreciated&lt;/P&gt;&lt;P&gt;- Mike&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 15:30:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/quirky-one-logging-in/m-p/1177707#M859914</guid>
      <dc:creator>m.surtees</dc:creator>
      <dc:date>2019-03-11T15:30:37Z</dc:date>
    </item>
    <item>
      <title>Re: Quirky one: Logging in</title>
      <link>https://community.cisco.com/t5/network-security/quirky-one-logging-in/m-p/1177708#M859915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you enabled 'debug ssh' yet?&lt;/P&gt;&lt;P&gt;Lots of useful data printed back to screen when attempting login that may help you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 May 2009 08:49:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/quirky-one-logging-in/m-p/1177708#M859915</guid>
      <dc:creator>handsy</dc:creator>
      <dc:date>2009-05-12T08:49:43Z</dc:date>
    </item>
    <item>
      <title>Re: Quirky one: Logging in</title>
      <link>https://community.cisco.com/t5/network-security/quirky-one-logging-in/m-p/1177709#M859916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Handsy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did do a debug before your reply and I got:&lt;/P&gt;&lt;P&gt;SSH2 0: waiting for SSH2_MSG_NEWKEYSSSH0: TCP read failed, error code = 0x86300003 "TCP connection closed"&lt;/P&gt;&lt;P&gt;SSH0: receive SSH message: [no message ID: variable *data is NULL]&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SSH2 0: Unexpected mesg type receivedSSH0: Session disconnected by SSH server - error 0x00 "Internal error"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;... but as it's a/hrs here I thought "stuff it" and rebooted. It is not the first time it has gone down since the weekend tho. Then when I tried my trusty linux SSH I was again denied but this time with the good looking "WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!" &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I deleted the key in known_hosts and now I am back in. But I don't understand it as telnet would not work either, now it does of course. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hate 'fixing' things with a reboot ... it's so, like, microsoft &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers anyways,&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 May 2009 09:04:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/quirky-one-logging-in/m-p/1177709#M859916</guid>
      <dc:creator>m.surtees</dc:creator>
      <dc:date>2009-05-12T09:04:34Z</dc:date>
    </item>
    <item>
      <title>Re: Quirky one: Logging in</title>
      <link>https://community.cisco.com/t5/network-security/quirky-one-logging-in/m-p/1177710#M859917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;haha, how very annoying &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;glad you got it fixed though&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 May 2009 09:09:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/quirky-one-logging-in/m-p/1177710#M859917</guid>
      <dc:creator>handsy</dc:creator>
      <dc:date>2009-05-12T09:09:32Z</dc:date>
    </item>
  </channel>
</rss>

