<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't access ASA 5506 (https or ASDM) after changing LAN IP addresses in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3728560#M9446</link>
    <description>&lt;P&gt;Show run | include http&lt;/P&gt;
&lt;P&gt;show run | include ssh&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 19 Oct 2018 12:11:37 GMT</pubDate>
    <dc:creator>Alex Pfeil</dc:creator>
    <dc:date>2018-10-19T12:11:37Z</dc:date>
    <item>
      <title>Can't access ASA 5506 (https or ASDM) after changing LAN IP addresses</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3727465#M9397</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;
&lt;P&gt;I'm new to the ASA5506 and am setting one up as a firewall for our office.&amp;nbsp; I originally set it up via ASDM and one of the things I did was to change the LAN IP addresses, since then I cannot access the firewall at &lt;STRONG&gt;http://'new address'/admin&lt;/STRONG&gt; or &lt;STRONG&gt;https://'new address'/admin&lt;/STRONG&gt; or via ASDM from the laptop I originally used with ASDM at the original address.&amp;nbsp; However, if I use a different PC on the same LAN, I can get to&amp;nbsp;&lt;SPAN&gt;&lt;STRONG&gt;https://'new address'/admin&lt;/STRONG&gt; and via ASDM.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I've been setting up the rest of the firewall config via the&amp;nbsp;console port&amp;nbsp;and everything else seems to be working fine.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I've read another discussion&amp;nbsp;and perhaps this may be a certificate problem, but if so I don't know how to fix it.&amp;nbsp; Does anyone know if that might be the problem or could it be something else?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Mike&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:22:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3727465#M9397</guid>
      <dc:creator>mike_t</dc:creator>
      <dc:date>2020-02-21T16:22:20Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access ASA 5506 (https or ASDM) after changing LAN IP addresses</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3727483#M9402</link>
      <description>Show run | i http&lt;BR /&gt;You usually have commands:&lt;BR /&gt;Http inside x.x.x.x subnetMask &lt;BR /&gt;Or&lt;BR /&gt;Http management&lt;BR /&gt;&lt;BR /&gt;It can also be SSL issue.&lt;BR /&gt;&lt;BR /&gt;Please mark helpful posts.</description>
      <pubDate>Wed, 17 Oct 2018 23:00:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3727483#M9402</guid>
      <dc:creator>Alex Pfeil</dc:creator>
      <dc:date>2018-10-17T23:00:46Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access ASA 5506 (https or ASDM) after changing LAN IP addresses</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3727485#M9439</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Are the 2 PCs on&amp;nbsp; the same network i.e. same ip address range? Can you ping the "new ip address" from the PC that is not working? What ip addresses are configured to access the firewall e.g. http x.x.x.x x.x.x.x inside?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;
&lt;P&gt;John&lt;/P&gt;</description>
      <pubDate>Wed, 17 Oct 2018 23:02:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3727485#M9439</guid>
      <dc:creator>johnd2310</dc:creator>
      <dc:date>2018-10-17T23:02:05Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access ASA 5506 (https or ASDM) after changing LAN IP addresses</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3727486#M9440</link>
      <description>&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-device-manager/116403-configure-asdm-00.html#anc9" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/adaptive-security-device-manager/116403-configure-asdm-00.html#anc9&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Look at the SSL portion of this document.&lt;BR /&gt;&lt;BR /&gt;Please mark helpful posts.</description>
      <pubDate>Wed, 17 Oct 2018 23:02:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3727486#M9440</guid>
      <dc:creator>Alex Pfeil</dc:creator>
      <dc:date>2018-10-17T23:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access ASA 5506 (https or ASDM) after changing LAN IP addresses</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3727508#M9441</link>
      <description>&lt;P&gt;sho run | i http gives&lt;/P&gt;
&lt;PRE&gt;http server enable
http 192.168.0.0 255.255.0.0 inside_1
http 192.168.0.0 255.255.0.0 inside_2
http 192.168.0.0 255.255.0.0 inside_3
http 192.168.0.0 255.255.0.0 inside_4
http 192.168.0.0 255.255.0.0 inside_5
http 192.168.0.0 255.255.0.0 inside_6
http 192.168.0.0 255.255.0.0 inside_7&lt;/PRE&gt;
&lt;P&gt;the original laptop is at 192.168.2.64, the new one is 192.168.2.69, both can ping&amp;nbsp; the ASA at 192.168.2.1&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Thu, 18 Oct 2018 00:37:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3727508#M9441</guid>
      <dc:creator>mike_t</dc:creator>
      <dc:date>2018-10-18T00:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access ASA 5506 (https or ASDM) after changing LAN IP addresses</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3727509#M9442</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;yes, both PCs are in the same address range and can ping all hosts that are on that network including the ASA&lt;/P&gt;
&lt;P&gt;Result of &lt;STRONG&gt;sho run http&lt;/STRONG&gt; is&lt;/P&gt;
&lt;PRE&gt;http server enable
http 192.168.0.0 255.255.0.0 inside_1
http 192.168.0.0 255.255.0.0 inside_2
http 192.168.0.0 255.255.0.0 inside_3
http 192.168.0.0 255.255.0.0 inside_4
http 192.168.0.0 255.255.0.0 inside_5
http 192.168.0.0 255.255.0.0 inside_6
http 192.168.0.0 255.255.0.0 inside_7&lt;/PRE&gt;
&lt;P&gt;MIke&lt;/P&gt;</description>
      <pubDate>Thu, 18 Oct 2018 00:40:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3727509#M9442</guid>
      <dc:creator>mike_t</dc:creator>
      <dc:date>2018-10-18T00:40:44Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access ASA 5506 (https or ASDM) after changing LAN IP addresses</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3727520#M9443</link>
      <description>&lt;P&gt;Thanks for that link, but I've not found anything there that helps.&amp;nbsp; It says&amp;nbsp;"&lt;SPAN&gt;open the ASDM from another machine. If you succeed, the issue is is probably at the application level".&amp;nbsp; &amp;nbsp;But then I'm not sure where to go.&amp;nbsp; There is an 'Application&amp;nbsp;Software' section in that document, and one of the steps is "Open the ASDM launch page from another machine. If it launches, it means that the issue is with the client machine in question".&amp;nbsp; So (as suspected) there is an issue on the original client machine, but I can't work out what and how to fix it&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Mike&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Oct 2018 01:35:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3727520#M9443</guid>
      <dc:creator>mike_t</dc:creator>
      <dc:date>2018-10-18T01:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access ASA 5506 (https or ASDM) after changing LAN IP addresses</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3727746#M9444</link>
      <description>&lt;P&gt;1. Make sure you are allowing your computer IP address to the correct interface with the http command on the asa.&lt;/P&gt;
&lt;P&gt;2. Make sure you have the SSL command on the asa.&lt;/P&gt;
&lt;P&gt;Here is an example:&lt;/P&gt;
&lt;P&gt;ssl server-version tlsv1&lt;BR /&gt;ssl client-version tlsv1&lt;BR /&gt;ssl cipher default custom "DES-CBC3-SHA:AES128-SHA:AES256-SHA"&lt;BR /&gt;ssl cipher tlsv1 custom "DES-CBC3-SHA:AES128-SHA:AES256-SHA"&lt;BR /&gt;ssl cipher tlsv1.1 medium&lt;BR /&gt;ssl cipher tlsv1.2 medium&lt;BR /&gt;ssl cipher dtlsv1 custom "DES-CBC3-SHA:AES128-SHA:AES256-SHA"&lt;BR /&gt;ssl dh-group group2&lt;BR /&gt;ssl ecdh-group group19&lt;BR /&gt;ssl certificate-authentication fca-timeout 2&lt;BR /&gt;&amp;nbsp;no ssl-server-check&lt;/P&gt;
&lt;P&gt;3. Make sure you have the asdm image command.&lt;/P&gt;
&lt;P&gt;Here is an example:&lt;/P&gt;
&lt;P&gt;asdm image disk0:/asdm.bin&lt;/P&gt;
&lt;P&gt;4. Check the version of the asa you are running.&lt;/P&gt;
&lt;P&gt;5. Check the version of the asdm you are running.&lt;/P&gt;
&lt;P&gt;6. Check the version of java that you are running.&lt;/P&gt;
&lt;P&gt;Here is an example:&lt;/P&gt;
&lt;P&gt;If you are running the latest version of asa and asdm code, you should have the latest java installed.&lt;/P&gt;
&lt;P&gt;7. You can also go into the advanced options in internet explorer, scroll down near the bottom and verify what your SSL/TLS values are set to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please mark helpful posts.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Oct 2018 10:36:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3727746#M9444</guid>
      <dc:creator>Alex Pfeil</dc:creator>
      <dc:date>2018-10-18T10:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access ASA 5506 (https or ASDM) after changing LAN IP addresses</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3728238#M9445</link>
      <description>&lt;P&gt;Thanks Alex&lt;/P&gt;
&lt;P&gt;Just for further info - I tried SSH via PuTTY and had the same result (connection refused on the original laptop, and no problem on the new PCs), so it doesn't look like an ASDM / Java issue.&amp;nbsp; But just to confirm, here are the responses to your points&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/293775"&gt;@Alex Pfeil&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;1. Make sure you are allowing your computer IP address to the correct interface with the http command on the asa.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Yes - reported in previous posts&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;2. Make sure you have the SSL command on the asa.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Here is the result of &lt;STRONG&gt;sho run all ssl&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;ssl server-version tlsv1&lt;/P&gt;
&lt;P&gt;ssl client-version tlsv1&lt;/P&gt;
&lt;P&gt;ssl cipher default medium&lt;/P&gt;
&lt;P&gt;ssl cipher tlsv1 medium&lt;/P&gt;
&lt;P&gt;ssl cipher tlsv1.1 medium&lt;/P&gt;
&lt;P&gt;ssl cipher tlsv1.2 medium&lt;/P&gt;
&lt;P&gt;ssl cipher dtlsv1 medium&lt;/P&gt;
&lt;P&gt;ssl dh-group group2&lt;/P&gt;
&lt;P&gt;ssl ecdh-group group19&lt;/P&gt;
&lt;P&gt;ssl trust-point ASDM_Launcher_Access_TrustPoint_0 inside&lt;/P&gt;
&lt;P&gt;ssl trust-point ASDM_Launcher_Access_TrustPoint_0 inside vpnlb-ip&lt;/P&gt;
&lt;P&gt;ssl certificate-authentication fca-timeout 2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;3. Make sure you have the asdm image command.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I have &lt;STRONG&gt;asdm image disk0:/asdm-782.bin&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;4. Check the version of the asa you are running.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;9.8(2)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;5. Check the version of the asdm you are running.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;7.8(2)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;6. Check the version of java that you are running.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Version 8 Update 181 (build 1.9.0_181-b13)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;7. You can also go into the advanced options in internet explorer, scroll down near the bottom and verify what your SSL/TLS values are set to.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I tend to use Chrome rather than IE, but IE has "Use TLS 1.0", "Use TLS 1.1" and "Use TLS 1.2" checked&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for you help&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Thu, 18 Oct 2018 21:22:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3728238#M9445</guid>
      <dc:creator>mike_t</dc:creator>
      <dc:date>2018-10-18T21:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access ASA 5506 (https or ASDM) after changing LAN IP addresses</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3728560#M9446</link>
      <description>&lt;P&gt;Show run | include http&lt;/P&gt;
&lt;P&gt;show run | include ssh&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Oct 2018 12:11:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3728560#M9446</guid>
      <dc:creator>Alex Pfeil</dc:creator>
      <dc:date>2018-10-19T12:11:37Z</dc:date>
    </item>
    <item>
      <title>Re: Can't access ASA 5506 (https or ASDM) after changing LAN IP addresses</title>
      <link>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3729406#M9447</link>
      <description>&lt;P&gt;&lt;STRONG&gt;sho run | i http&lt;/STRONG&gt;&lt;/P&gt;
&lt;PRE&gt;http server enable
http 192.168.0.0 255.255.0.0 inside_1
http 192.168.0.0 255.255.0.0 inside_2
http 192.168.0.0 255.255.0.0 inside_3
http 192.168.0.0 255.255.0.0 inside_4
http 192.168.0.0 255.255.0.0 inside_5
http 192.168.0.0 255.255.0.0 inside_6
http 192.168.0.0 255.255.0.0 inside_7
  destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService
  destination transport-method http
&lt;/PRE&gt;
&lt;P&gt;&lt;STRONG&gt;sho run | i ssh&lt;/STRONG&gt;&lt;/P&gt;
&lt;PRE&gt;aaa authentication ssh console LOCAL
ssh stricthostkeycheck
ssh 192.168.0.0 255.255.0.0 outside
ssh 192.168.0.0 255.255.0.0 inside_1
ssh 192.168.0.0 255.255.0.0 inside_2
ssh 192.168.0.0 255.255.0.0 inside_3
ssh 192.168.0.0 255.255.0.0 inside_4
ssh 192.168.0.0 255.255.0.0 inside_5
ssh 192.168.0.0 255.255.0.0 inside_6
ssh 192.168.0.0 255.255.0.0 inside_7
ssh timeout 5
ssh key-exchange group dh-group1-sha1&lt;/PRE&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Sun, 21 Oct 2018 20:24:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/can-t-access-asa-5506-https-or-asdm-after-changing-lan-ip/m-p/3729406#M9447</guid>
      <dc:creator>mike_t</dc:creator>
      <dc:date>2018-10-21T20:24:38Z</dc:date>
    </item>
  </channel>
</rss>

