<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Changed password - IDS can't connect via SSH in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/changed-password-ids-can-t-connect-via-ssh/m-p/321193#M97287</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;from the sesnor do a "show stat net" and look for the pix. Does the state say "Active" or "Connecting"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also do a show events on the sensor and then stop/start blocking using idm.  You should see any errors nac is having.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try that for starters.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Jan 2005 20:51:09 GMT</pubDate>
    <dc:creator>jlively</dc:creator>
    <dc:date>2005-01-21T20:51:09Z</dc:date>
    <item>
      <title>Changed password - IDS can't connect via SSH</title>
      <link>https://community.cisco.com/t5/network-security/changed-password-ids-can-t-connect-via-ssh/m-p/321191#M97275</link>
      <description>&lt;P&gt;I have a PIX-514 configured for SSH.  I also have a 4210 IDS on the internal network.  At one time I know the IDS would shun (using the firewall).  I believe that if you do a show ssh sessions on the firewall you will always see the IDS as connected.  I changed the passwords on the PIX this morning and I went into the IDS and changed the password under Logical Devices.  I connected back to the PIX and did a show ssh sessions.  The only thing it reported was my session.  If I repeat the command I will sometimes see the ip address of the sensor but the state is 2 and the encryption and username are empty.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Am I right in thinking that the IDS should have a connection at all times?  I know ssh is working because I can connect to the PIX from my desktop.  I know the passwords are right because I've checked and rechecked them.  I even did a sho config from the command line of the IDS and it displays the passwords in plain text so I know the passwords are correct.  Any ideas or things to check?  Thanks.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:14:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changed-password-ids-can-t-connect-via-ssh/m-p/321191#M97275</guid>
      <dc:creator>unionbancorpit</dc:creator>
      <dc:date>2019-03-10T09:14:30Z</dc:date>
    </item>
    <item>
      <title>Re: Changed password - IDS can't connect via SSH</title>
      <link>https://community.cisco.com/t5/network-security/changed-password-ids-can-t-connect-via-ssh/m-p/321192#M97284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I solved my own problem.  I regenerate the known host-key for my PIX and right after that the IDS established the connection.  Not sure what happened but its working now.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jan 2005 20:28:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changed-password-ids-can-t-connect-via-ssh/m-p/321192#M97284</guid>
      <dc:creator>unionbancorpit</dc:creator>
      <dc:date>2005-01-21T20:28:27Z</dc:date>
    </item>
    <item>
      <title>Re: Changed password - IDS can't connect via SSH</title>
      <link>https://community.cisco.com/t5/network-security/changed-password-ids-can-t-connect-via-ssh/m-p/321193#M97287</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;from the sesnor do a "show stat net" and look for the pix. Does the state say "Active" or "Connecting"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also do a show events on the sensor and then stop/start blocking using idm.  You should see any errors nac is having.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try that for starters.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Jan 2005 20:51:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/changed-password-ids-can-t-connect-via-ssh/m-p/321193#M97287</guid>
      <dc:creator>jlively</dc:creator>
      <dc:date>2005-01-21T20:51:09Z</dc:date>
    </item>
  </channel>
</rss>

