01-18-2019 04:15 AM - edited 03-12-2019 07:14 AM
Hi,
I have a Cisco ASA FPR 4110.
I have gained https access to the management IP which was set up in the original set up. I then provisioned the logical device list with my second management IP address and upgraded the asa code on the box. I can access the management IP via SSH, but I should be able to ASDM and https to it and cannot.
I receive the below error from IE: But on Chrome it just says it cannot be reached.
Certificate error: Navigation blocked
Error Code: DLG_FLAGS_INVALID_CA |
On ASDM, it prompts me for a username and password... but from previously configuring a 4100 I press enter as it does not need credentials but still does not log me in. I have tried other usernames and passwords I have set up also, as well as debugging http from the asa and cannot see any errors. Any ideas?
TIA for any help!
01-18-2019 06:48 PM
Have you allocated a separate unique and dedicated management interface for your ASA logical device?
01-21-2019 01:50 AM
Hi Marvin,
Yes I have done this.
01-21-2019 04:51 AM
Have you assigned a free 3DES-AES license on the ASA logical device?
Have you created an RSA private key ("crypto key generate ...")?
If the above are yes, try opening the Java console while launching ASDM. Watch the output of it for errors.
You could also do a packet capture and look for things like SSL/TLS failing to negotiate a common cipher or more details on the certificate failure.
01-21-2019 07:26 AM
Thanks!
I will give this a go this week.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide