<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ssh connection refused - fwsm in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013880#M937296</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your response. Actually doing that didn't help - still connection refused. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did write mem, and also neither has rebooted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, J&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 May 2008 13:22:13 GMT</pubDate>
    <dc:creator>jigsaw2026</dc:creator>
    <dc:date>2008-05-23T13:22:13Z</dc:date>
    <item>
      <title>ssh connection refused - fwsm</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013878#M937287</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm unable to ssh into our fwsm today - there's nothing in the logs and all ssh commmands are still present - we've had this before and I have to re-generate the rsa key, and I'm fairly certain that's what I need to do now but the old ca commands that I used have been depreciated (fwsm 3.1) so I just wanted to check that I'm doing the right thing! Here's what I'm planning on:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto key zeroize rsa&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WARNING: All RSA keys will be removed.&lt;/P&gt;&lt;P&gt;WARNING: All device certs issued using these keys will also be removed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you really want to remove these keys? [yes/no]: yes&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto key generate rsa general-keys modulus 1024&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this look right?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;J&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:48:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013878#M937287</guid>
      <dc:creator>jigsaw2026</dc:creator>
      <dc:date>2019-03-11T12:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: ssh connection refused - fwsm</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013879#M937292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;and you have the domain name configured also? then the above commands are OK.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you wr mem once the key has been generated?  has the FWSM or 65xx reloaded?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 May 2008 12:00:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013879#M937292</guid>
      <dc:creator>andrew.prince</dc:creator>
      <dc:date>2008-05-23T12:00:39Z</dc:date>
    </item>
    <item>
      <title>Re: ssh connection refused - fwsm</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013880#M937296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your response. Actually doing that didn't help - still connection refused. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas????&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did write mem, and also neither has rebooted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, J&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 May 2008 13:22:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013880#M937296</guid>
      <dc:creator>jigsaw2026</dc:creator>
      <dc:date>2008-05-23T13:22:13Z</dc:date>
    </item>
    <item>
      <title>Re: ssh connection refused - fwsm</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013881#M937300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi J,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What do you get in the output of:&lt;/P&gt;&lt;P&gt;'sh crypto key mypubkey rsa'&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Moreover, what do you get in the output of 'sh run ssh'?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 May 2008 13:32:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013881#M937300</guid>
      <dc:creator>jkampane</dc:creator>
      <dc:date>2008-05-23T13:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: ssh connection refused - fwsm</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013882#M937305</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fwsm# sh crypto key mypubkey rsa&lt;/P&gt;&lt;P&gt;Key pair was generated at: 13:52:06 UTC May 23 2008&lt;/P&gt;&lt;P&gt;Key name: &lt;DEFAULT-RSA-KEY&gt;&lt;/DEFAULT-RSA-KEY&gt;&lt;/P&gt;&lt;P&gt; Usage: General Purpose Key&lt;/P&gt;&lt;P&gt; Modulus Size (bits): 1024&lt;/P&gt;&lt;P&gt; Key Data:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  30819f30 0d06092a 864886f7 0d010101 05000381 8d003081 89028181 00d97565&lt;/P&gt;&lt;P&gt;  428234d5 b58e49d8 2d2ac0b9 08c97e48 f7637111 2287ee58 dfd09941 cb2f87ba&lt;/P&gt;&lt;P&gt;  c0d0dcc0 571cf5d9 7d1e97f0 616cd2ea 9429cc6c 3afa975e 86a4d007 c44a61f7&lt;/P&gt;&lt;P&gt;  3e905ffb 39ad9e07 8f74393d 0bad0c1d fd7eae2c c095260c 9ea22c73 21e3e151&lt;/P&gt;&lt;P&gt;  0a7a4dc0 cad2b173 3097595e f5998cb6 7e6ded99 81ddc892 e6963980 bb020301 0001&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fwsm# sh run  ssh&lt;/P&gt;&lt;P&gt;ssh 1.1.1.1 255.255.255.255 wireless&lt;/P&gt;&lt;P&gt;ssh office 255.255.255.0 inside&lt;/P&gt;&lt;P&gt;ssh timeout 15&lt;/P&gt;&lt;P&gt;ssh version 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;J&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 May 2008 13:46:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013882#M937305</guid>
      <dc:creator>jigsaw2026</dc:creator>
      <dc:date>2008-05-23T13:46:56Z</dc:date>
    </item>
    <item>
      <title>Re: ssh connection refused - fwsm</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013883#M937310</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi J,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess you are trying to ssh to  the FWSM either via the inside or the wireless interface. Can you please confirm that in the first case your IP is within the office subnet and in the second that you are coming from the 1.1.1.1 host?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Moreover, a good idea would be to enable debug ssh 100 on the FWSM, along with loggin in debug level, try to connect and see what you are getting there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally, you will need the following line:&lt;/P&gt;&lt;P&gt;"aaa authentication ssh console LOCAL" along with a username/password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 May 2008 13:51:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013883#M937310</guid>
      <dc:creator>jkampane</dc:creator>
      <dc:date>2008-05-23T13:51:20Z</dc:date>
    </item>
    <item>
      <title>Re: ssh connection refused - fwsm</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013884#M937313</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks John,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Actually I have that auth line in already, it just didn't show up in the command.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I turned on debugging and this came up:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2008-05-23 16:22:25 Local4.Debug x.x.x.x May 23 2008 15:03:26: %FWSM-7-710002: tcp access permitted from x.x.x.x/20067308 to inside:x.x.x.x/ssh&lt;/P&gt;&lt;P&gt;2008-05-23 16:22:25 Local4.Info	x.x.x.x May 23 2008 15:03:26: %FWSM-6-302013: Built inbound TCP connection 0 for inside:x.x.x.x/3739 (10.3.80.100/3739) to inside:x.x.x.x/22 (x.x.x.x/22)&lt;/P&gt;&lt;P&gt;2008-05-23 16:22:25 Local4.Debug x.x.x.x May 23 2008 15:03:26: %FWSM-7-710004: TCP connection limit exceeded from x.x.x.x/3739 to inside:x.x.x.x/ssh&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I found this &lt;A class="jive-link-custom" href="http://www.conft.com/en/US/docs/security/asa/asa80/system/message/logmsgs.pdf" target="_blank"&gt;http://www.conft.com/en/US/docs/security/asa/asa80/system/message/logmsgs.pdf&lt;/A&gt; saying that I need to issue a kill command, but I can see any connections when I run a who (think this might only work for telnet?). Also I can't see any locally-destined traffic when I run show conn all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any ideas would be much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;J&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 May 2008 14:39:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013884#M937313</guid>
      <dc:creator>jigsaw2026</dc:creator>
      <dc:date>2008-05-23T14:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: ssh connection refused - fwsm</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013885#M937318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi J,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hmmmm, it can be a bug. I did some research and I found the following:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsd67334" target="_blank"&gt;http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&amp;amp;bugId=CSCsd67334&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe you can try to upgrade, or you can open a TAC case in order to further investigate.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 May 2008 15:15:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013885#M937318</guid>
      <dc:creator>jkampane</dc:creator>
      <dc:date>2008-05-23T15:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: ssh connection refused - fwsm</title>
      <link>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013886#M937321</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you John, that's very helpful indeed. I will reload for now and look at upgrading.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;J&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 May 2008 10:10:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ssh-connection-refused-fwsm/m-p/1013886#M937321</guid>
      <dc:creator>jigsaw2026</dc:creator>
      <dc:date>2008-05-27T10:10:23Z</dc:date>
    </item>
  </channel>
</rss>

