cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
5342
Views
0
Helpful
12
Replies

enable to access ASA5510 from my PC

fadelelali
Level 1
Level 1

hello 

i have ASA5510 with https enabled ,i can ping from my PC but when i try to access the GUI it gives me this error:

This page can’t be displayed

Turn on TLS 1.0, TLS 1.1, and TLS 1.2 in Advanced settings and try connecting to https://192.168.15.100 again. If this error persists, it is possible that this site uses an unsupported protocol or cipher suite such as RC4 (link for the details), which is not considered secure. Please contact your site administrator.

all these are enabled on my computer,i tried from explorer and from Fox with no hope.

any support i highly appreciated.

Thanks

2 Accepted Solutions

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

Check the ASA activation-key via console and make sure it has the free 3DES-AES license installed.

Use this command:

show activation-key

View solution in original post

Please remove the following lines as:

1. it is telling the ASA to authenticate your client with a certificate while the aaa command tells it to use the local user database.

2. It is unnecessarily restricting the http encryption method to a less secure one than your browser may want to negotiate.

ssl certificate-authentication interface insidemgt port 443
ssl encryption 3des-sha1

View solution in original post

12 Replies 12

Marvin Rhoads
Hall of Fame
Hall of Fame

Check the ASA activation-key via console and make sure it has the free 3DES-AES license installed.

Use this command:

show activation-key

Yes,it's not installed.i will install it and check it again.

Thanks alot

guys

i really can't understand this problem,i spend 2 days without any hope.i create key and trusted and enroll it with self-signed and i export this key to my windows operating system (added to the certification root folder ),when i access the appliance it gives 401 unauthorized (Certification error,invalid cerification),what could be the problem?

i appreciate your support.

Thanks

fadelelali  ,

Aditya asked you 2 days ago to share some output. That would be helpful.

You are using terms that don't exactly make sense to me - like export key to Windows - do you mean SSL certificate? A certificate and a key are very different things.

Finally if you could share some screen shots of the errors you are seeing perhaps it would help from things being lost in translation.

Dear 

Sorry for not sharing the outpout as the first problem solved when i activated the 3DES-AES license

now i am send all these outpout and i hope you can support me in ordered to find the problem:

1-the Txt file is the running configuration file on the machine.

2-one photo is the error i am facing,which is the "certification is invalide".according to my configuration the certificate created is selfsigned and it's 2048bits and it's named ASA1T.when i try to access the unit it shows me the certificate has 1024bits and it's not trusted and it's not in the trust root,but if you look to the second photo you can see that the certificate is well exported to the certification root folder and it's trusted.dont know why when i try to access the router it's like using different certificate file?

3-i restarted the machine and the PC many times and i after every update i do reload .

Thanks alot for your support

Please remove the following lines as:

1. it is telling the ASA to authenticate your client with a certificate while the aaa command tells it to use the local user database.

2. It is unnecessarily restricting the http encryption method to a less secure one than your browser may want to negotiate.

ssl certificate-authentication interface insidemgt port 443
ssl encryption 3des-sha1

Dear

Great,thanks alot.i removed these lines and it works.

Regards

I had faced this issue. ASDM login fails authenticate the user because of ssl certificate. After removing "suri71-asa(config)# no ssl certificate-authentication interface outside port 443", ASDM access worked.

Thanks for valuable info.

Thanks,

removal of ssl certs worked fine

Dear

3DES-AES installed and active,now when i try to log in from browser it shows "401 unauthorized" certification untrusted,i createded key and trusted and then exported to my local machine and it still says the certification is untrusted.

i checked java and i did exception list for the ASA IP adress.but with no hope ?? 

any support is highly appreciated.

Thanks alot

Dear

3DES-AES installed and active,now when i try to log in from browser it shows "401 unauthorized" certification untrusted,i createded key and trusted and then exported to my local machine and it still says the certification is untrusted.

i checked java and i did exception list for the ASA IP adress.but with no hope ?? 

any support is highly appreciated.

Thanks alot

Aditya Ganjoo
Cisco Employee
Cisco Employee

Hi,

Can you share the output of show run all ssl and show version from the ASA ?

Regards,

Aditya

Please rate helpful posts and mark correct answers.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card