cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
661
Views
0
Helpful
11
Replies

ASA 5580 ssh problem suddenly

gasparmenendez
Level 3
Level 3

Hi, I have an ASA 5580 with configured access through ssh. I've been accessing to it since always, but suddenly (noticed today) I can't access any more. I'm receiving this:

ssh -l username 192.168.0.44
Connection closed by 192.168.0.44 port 22

I have another 3 ASA's and I'm accessing them perfectly...

what could have changed???

thanks in advance.

BR

2 Accepted Solutions

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

It's possible some automated system has exhausted the vty lines. You'd have to check that via a console connection. 

View solution in original post

There's a nice article at tunnelsup.com that explains checking the resources, viewing the sessions (as you surmised) and disconnecting them. ('ssh disconnect <session number>')

https://www.tunnelsup.com/how-to-show-and-clear-user-sessions-on-a-cisco-asa/

View solution in original post

11 Replies 11

Marvin Rhoads
Hall of Fame
Hall of Fame

It's possible some automated system has exhausted the vty lines. You'd have to check that via a console connection. 

it makes sense...actually I tried to check vty lines but the command is not the same as in IOS. I think here in ASA is show ssh sessions, is that correct??? but more important: how do I clean vty lines??? in IOS the command is clear vty line #, is the same in here??

thanks in advance.

BR.

There's a nice article at tunnelsup.com that explains checking the resources, viewing the sessions (as you surmised) and disconnecting them. ('ssh disconnect <session number>')

https://www.tunnelsup.com/how-to-show-and-clear-user-sessions-on-a-cisco-asa/

Excellent!!!

I'll check it.

BR.

Hi Marvin, I connected to the ASA via console and did run a couple of commands but shows nothing:

ASA5580# show resource usage resource ssH
Resource               Current        Peak      Limit        Denied Context
ASA5580#

ASA5580# show ssh sessions
ASA5580#

what could be happening???

Do you have multiple contexts?

Which ASA software version is running on the 5580?


Cisco Adaptive Security Appliance Software Version 8.4(5)
Device Manager Version 7.1(1)52

Compiled on Mon 29-Oct-12 10:51 by builders
System image file is "disk0:/asa845-smp-k8.bin"
Config file at boot was "startup-config"

There was a bug in ASA 8.3(2.8) where there were orphaned ssh sessions. But that shouldn't affect your release.

https://bst.cloudapps.cisco.com/bugsearch/bug/CSCtq84364/?referring_site=bugquickviewredir

The bug notes do suggest checking for the session using:

show process | include ssh

I have also seen this sometimes be remedied with a simple reload. Are you able to shcedule that?

ASA5580# show processes | i ssh
Mwe 0x0000000001346b80 0x00007ffe73d1f528 0x00007ffe73cf5828          3 0x00007ffe73d17860 30752/32768 listen/ssh
Mwe 0x00000000012eaddd 0x00007ffe73d3a438 0x00000000040ea310          3 0x00007ffe73d325e0 30200/32768 ssh/timer
ASA5580#

reload the appliance would be my last resource...besides, what if it happens again??? I can't be reloading the ASA every time...

it's very disappointing...

Understood. Perhaps the TAC would be able to advise further. Are you able to open a TAC case?

Hi Marvin,

reload did the job...now is working fine!

but I would like to know what happened....

BR.

Review Cisco Networking for a $25 gift card