<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: why cant i telnet? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113632#M892581</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. You can do something like the below configuration which excludes those addresses. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip local pool A-Pool 172.30.0.10-172.30.0.254 mask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For testing purposes, try changing the pool to the above address range and let me know if it works. If it works, we know the pool was causing the issue, if not we can troubleshoot this further. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Pls rate if it helps*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 10 Dec 2008 03:48:51 GMT</pubDate>
    <dc:creator>ajagadee</dc:creator>
    <dc:date>2008-12-10T03:48:51Z</dc:date>
    <item>
      <title>why cant i telnet?</title>
      <link>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113624#M892566</link>
      <description>&lt;P&gt;I am unable to telnet to our ASA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the config is as follows&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;telnet timeout 5&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 inside&lt;/P&gt;&lt;P&gt;ssh timeout 5&lt;/P&gt;&lt;P&gt;console timeout 0&lt;/P&gt;&lt;P&gt;threat-detection basic-threat&lt;/P&gt;&lt;P&gt;threat-detection statistics access-list&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am logged into the switch that this is connected to&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 14:23:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113624#M892566</guid>
      <dc:creator>nygenxny123</dc:creator>
      <dc:date>2019-03-11T14:23:00Z</dc:date>
    </item>
    <item>
      <title>Re: why cant i telnet?</title>
      <link>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113625#M892568</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Enable packet capture on the inside interface to check the packet flow. Other option is to check connection build's and teardown but you need to enable "logging buffered debug"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2008 17:52:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113625#M892568</guid>
      <dc:creator>vvarakan</dc:creator>
      <dc:date>2008-12-09T17:52:41Z</dc:date>
    </item>
    <item>
      <title>Re: why cant i telnet?</title>
      <link>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113626#M892570</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sadly..we are using asdm 6.0 with the known bug and cant access it now&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;would that debug cause a huge load on my asa?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;its at a remote site and i dont want to have it hang and get stuck&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2008 18:28:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113626#M892570</guid>
      <dc:creator>nygenxny123</dc:creator>
      <dc:date>2008-12-09T18:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: why cant i telnet?</title>
      <link>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113627#M892572</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Was this working before or is this a new set up. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you post the configuration from the ASA along with the source and destination IP Address that you are telnetting from. Make sure that you can ping the ASA inside interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2008 19:12:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113627#M892572</guid>
      <dc:creator>ajagadee</dc:creator>
      <dc:date>2008-12-09T19:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: why cant i telnet?</title>
      <link>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113628#M892574</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;its an old setup that was never really e utilized..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;here is the attached config..i edited some outside IP's..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My ip is 192.168.133.4 and i log into 192.168.4.2..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which has a vlan address of 172.30.0.1 configured on it&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2008 21:12:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113628#M892574</guid>
      <dc:creator>nygenxny123</dc:creator>
      <dc:date>2008-12-09T21:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: why cant i telnet?</title>
      <link>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113629#M892577</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try adding:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;management-access inside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See if that helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2008 21:49:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113629#M892577</guid>
      <dc:creator>John Blakley</dc:creator>
      <dc:date>2008-12-09T21:49:46Z</dc:date>
    </item>
    <item>
      <title>Re: why cant i telnet?</title>
      <link>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113630#M892579</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK, configuration really helps. I don't think the below configuration is valid. You have an inside ip address of 172.30.0.2/16 and then you have configured a pool of ip addresses for the VPN Client, which is 172.30.0.x/24, which is overlapping with inside interface. This could be the issue that you are having issues accessing the inside interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/1&lt;/P&gt;&lt;P&gt; nameif inside&lt;/P&gt;&lt;P&gt; security-level 100&lt;/P&gt;&lt;P&gt; ip address 172.30.0.2 255.255.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip local pool A-Pool 172.30.0.1-172.30.0.254 mask 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Depending on your set up, you need to change the VPN Pool to a different subnet and make the necessary changes to the Split Tunnel ACL, NAT 0, etc and then try to telnet to the inside interface and see if it works. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Pls rate if it helps*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Dec 2008 22:06:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113630#M892579</guid>
      <dc:creator>ajagadee</dc:creator>
      <dc:date>2008-12-09T22:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: why cant i telnet?</title>
      <link>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113631#M892580</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;is there a way to exclude the address from the pool?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Dec 2008 03:00:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113631#M892580</guid>
      <dc:creator>nygenxny123</dc:creator>
      <dc:date>2008-12-10T03:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: why cant i telnet?</title>
      <link>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113632#M892581</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. You can do something like the below configuration which excludes those addresses. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip local pool A-Pool 172.30.0.10-172.30.0.254 mask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For testing purposes, try changing the pool to the above address range and let me know if it works. If it works, we know the pool was causing the issue, if not we can troubleshoot this further. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Arul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Pls rate if it helps*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Dec 2008 03:48:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113632#M892581</guid>
      <dc:creator>ajagadee</dc:creator>
      <dc:date>2008-12-10T03:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: why cant i telnet?</title>
      <link>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113633#M892582</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes the Pool changed worked!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would think that the ASA would look for the .2 address so there wouldn't be any issues&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thx&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Dec 2008 21:01:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/why-cant-i-telnet/m-p/1113633#M892582</guid>
      <dc:creator>nygenxny123</dc:creator>
      <dc:date>2008-12-10T21:01:32Z</dc:date>
    </item>
  </channel>
</rss>

