<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic My ASA 5505 stops accepting SSH connections after a few days in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/my-asa-5505-stops-accepting-ssh-connections-after-a-few-days/m-p/961910#M941610</link>
    <description>&lt;P&gt;I have an ASA 5505 running v8.03 firmware that after a few days of uptime stops accepting SSH connections.&lt;/P&gt;&lt;P&gt;My SSH setup is pretty simple, just:&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;ssh timeout 60&lt;/P&gt;&lt;P&gt;I get the following messages in my syslog when SSH stops working:&lt;/P&gt;&lt;P&gt;(yyy.y.yyy.y is my SSH client's IP, xxx.xxx.xxx.xx is the ASA firewall IP)&lt;/P&gt;&lt;P&gt;02-29 09:05:22	Local4.Info	xxx.xxx.xxx.xx	Feb 29 2008 09:08:30: %ASA-6-302013: Built inbound TCP connection 495222 for outside:yyy.y.yyy.y/56782 (yyy.y.yyy.y/56782) to NP Identity Ifc:xxx.xxx.xxx.xx/22 (xxx.xxx.xxx.xx/22)&lt;/P&gt;&lt;P&gt;2008-02-29 09:05:22	Local4.Notice	xxx.xxx.xxx.xx	Feb 29 2008 09:08:30: %ASA-5-321001: Resource 'ssh' limit of 5 reached for context 'single_vf'&lt;/P&gt;&lt;P&gt;2008-02-29 09:05:22	Local4.Info	xxx.xxx.xxx.xx	Feb 29 2008 09:08:30: %ASA-6-302014: Teardown TCP connection 495222 for outside:yyy.y.yyy.y/56782 to NP Identity Ifc:xxx.xxx.xxx.xx/22 duration 0:00:00 bytes 0 TCP FINs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone have any ideas on what causes this and how to fix?  (I've been rebooting the ASA to fix it which seems drastic)&lt;/P&gt;&lt;P&gt;I don't have any problems on any of my other ASA boxes, but they are running 8.02...so maybe this is something specific to 8.03?&lt;/P&gt;&lt;P&gt;(or maybe the box is under a DOS SSH attack which is using up all the SSH process resources?)&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 12:10:50 GMT</pubDate>
    <dc:creator>thomasdzubin</dc:creator>
    <dc:date>2019-03-11T12:10:50Z</dc:date>
    <item>
      <title>My ASA 5505 stops accepting SSH connections after a few days</title>
      <link>https://community.cisco.com/t5/network-security/my-asa-5505-stops-accepting-ssh-connections-after-a-few-days/m-p/961910#M941610</link>
      <description>&lt;P&gt;I have an ASA 5505 running v8.03 firmware that after a few days of uptime stops accepting SSH connections.&lt;/P&gt;&lt;P&gt;My SSH setup is pretty simple, just:&lt;/P&gt;&lt;P&gt;ssh 0.0.0.0 0.0.0.0 outside&lt;/P&gt;&lt;P&gt;ssh timeout 60&lt;/P&gt;&lt;P&gt;I get the following messages in my syslog when SSH stops working:&lt;/P&gt;&lt;P&gt;(yyy.y.yyy.y is my SSH client's IP, xxx.xxx.xxx.xx is the ASA firewall IP)&lt;/P&gt;&lt;P&gt;02-29 09:05:22	Local4.Info	xxx.xxx.xxx.xx	Feb 29 2008 09:08:30: %ASA-6-302013: Built inbound TCP connection 495222 for outside:yyy.y.yyy.y/56782 (yyy.y.yyy.y/56782) to NP Identity Ifc:xxx.xxx.xxx.xx/22 (xxx.xxx.xxx.xx/22)&lt;/P&gt;&lt;P&gt;2008-02-29 09:05:22	Local4.Notice	xxx.xxx.xxx.xx	Feb 29 2008 09:08:30: %ASA-5-321001: Resource 'ssh' limit of 5 reached for context 'single_vf'&lt;/P&gt;&lt;P&gt;2008-02-29 09:05:22	Local4.Info	xxx.xxx.xxx.xx	Feb 29 2008 09:08:30: %ASA-6-302014: Teardown TCP connection 495222 for outside:yyy.y.yyy.y/56782 to NP Identity Ifc:xxx.xxx.xxx.xx/22 duration 0:00:00 bytes 0 TCP FINs&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone have any ideas on what causes this and how to fix?  (I've been rebooting the ASA to fix it which seems drastic)&lt;/P&gt;&lt;P&gt;I don't have any problems on any of my other ASA boxes, but they are running 8.02...so maybe this is something specific to 8.03?&lt;/P&gt;&lt;P&gt;(or maybe the box is under a DOS SSH attack which is using up all the SSH process resources?)&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 12:10:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/my-asa-5505-stops-accepting-ssh-connections-after-a-few-days/m-p/961910#M941610</guid>
      <dc:creator>thomasdzubin</dc:creator>
      <dc:date>2019-03-11T12:10:50Z</dc:date>
    </item>
    <item>
      <title>Re: My ASA 5505 stops accepting SSH connections after a few days</title>
      <link>https://community.cisco.com/t5/network-security/my-asa-5505-stops-accepting-ssh-connections-after-a-few-days/m-p/961911#M941612</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It's a bug in the v8.03 software - Cisco Bug Toolkit recommends a downgrade to 7.x&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Feb 2008 20:38:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/my-asa-5505-stops-accepting-ssh-connections-after-a-few-days/m-p/961911#M941612</guid>
      <dc:creator>jason.henderson</dc:creator>
      <dc:date>2008-02-29T20:38:19Z</dc:date>
    </item>
    <item>
      <title>Re: My ASA 5505 stops accepting SSH connections after a few days</title>
      <link>https://community.cisco.com/t5/network-security/my-asa-5505-stops-accepting-ssh-connections-after-a-few-days/m-p/961912#M941615</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks... here are the details in case anyone else runs into it:&lt;/P&gt;&lt;P&gt;CSCsm68097 Bug Details  &lt;/P&gt;&lt;P&gt; ASA 8.0.x - SSH resource exhausted preventing further sessions  &lt;/P&gt;&lt;P&gt;Symptom:&lt;/P&gt;&lt;P&gt;Under a rare occurance, SSH sessions for management access can become locked preventing further SSH connections to be established to the ASA. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Conditions:&lt;/P&gt;&lt;P&gt;ASA 8.0(2), 8.0(3)&lt;/P&gt;&lt;P&gt;SSH enabled&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Workaround:&lt;/P&gt;&lt;P&gt;A reload will clear the hanged SSH sessions.&lt;/P&gt;&lt;P&gt;-other types of connections still function (telnet,console)&lt;/P&gt;&lt;P&gt;-downgrade to 7.x code &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Feb 2008 21:19:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/my-asa-5505-stops-accepting-ssh-connections-after-a-few-days/m-p/961912#M941615</guid>
      <dc:creator>thomasdzubin</dc:creator>
      <dc:date>2008-02-29T21:19:40Z</dc:date>
    </item>
  </channel>
</rss>

