cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3133
Views
0
Helpful
8
Replies

ASDM cannot access ASA5505

CHUN FAI LAW
Level 1
Level 1

i have test to access the firewall of ASA5510 with ASA845-K8/asa902-k8bin + asdm-712.bin +JAVA6 / 7, is completely no problem

When i try to install a new ASA5505 existing IOS is asdm825-k8 and also asdm-712 with JAVA7 is not allow to access the firewall with ASDM

After i type in username password, it stuck on the page loading , sometimes it will come up with cannnot to the device something like that.

telnet and SSH is no problem, i still can download the IOS with TFTP.

Anyone have the idea of it? if that is the java problem, is difficult to find the older java to downgrade.

I think may be the java problem, because i just to connect with wrong ip and password, it also stuck in this page.

8 Replies 8

jocamare
Level 4
Level 4

Can you confirm that the unit is properly configured to allow the connection?

Mind sharing this?:

show run asdm

show run http

show flash | i .bin

show run all | i ssl_encryption

i have added another photo when i press the RUN ASDM, it got another error.

i will show the report now. PLease wait for me

I can't show the last two command, i choose to show all of them

=~=~=~=~=~=~=~=~=~=~=~= PuTTY log 2013.03.23 08:51:15 =~=~=~=~=~=~=~=~=~=~=~=

ter

ASA5505# terminal len 0

                  ^

ERROR: % Invalid input detected at '^' marker.

ASA5505# terminal len 0               ?

  monitor  Syslog monitor

  no       Turn off syslogging to this terminal

  pager    Control page length for pagination. The page length set here is not

           saved to configuration.

ASA5505# terminal                                  sh run asdm

asdm image disk0:/asdm-645.bin

no asdm history enable

ASA5505# sh run http

http server enable 444

http 192.168.18.0 255.255.255.0 LAN

http 0.0.0.0 0.0.0.0 internet

ASA5505# sh flash | i.bin

                     ^

ERROR: % Invalid input detected at '^' marker.

ASA5505# sh flash | i.bin                  i.bin

                   ^

ERROR: % Invalid input detected at '^' marker.

ASA5505# sh a   run all |i ssl_encryption

                     ^

ERROR: % Invalid input detected at '^' marker.

ASA5505# sh run

: Saved

:

ASA Version 8.2(5)

!

hostname ASA5505

enable password 2KFQnbNIdI.2KYOU encrypted

passwd 2KFQnbNIdI.2KYOU encrypted

names

!

interface Ethernet0/0

!

interface Ethernet0/1

switchport access vlan 2

!

interface Ethernet0/2

switchport access vlan 2

!

interface Ethernet0/3

shutdown

!

interface Ethernet0/4

shutdown

!

interface Ethernet0/5

shutdown

<--- More --->

!

interface Ethernet0/6

shutdown

!

interface Ethernet0/7

shutdown

!

interface Vlan1

nameif internet

security-level 0

ip address 10X.247.161.XXX 255.255.255.252

!

interface Vlan2

nameif LAN

security-level 100

ip address 192.168.18.254 255.255.255.0

!

ftp mode passive

object-group network Web_server

object-group network Nat

object-group network pop3

object-group network smtp

object-group service 5900

object-group service 8443

<--- More --->

object-group network 8443_168

object-group network SSH

object-group network 5900_168

object-group service DM_INLINE_TCP_1 tcp

port-object eq pop3

port-object eq smtp

object-group service DM_INLINE_SERVICE_1

access-list Internet_access_in extended deny ip any any

access-list Lan_access_in extended permit ip 192.168.18.0 255.255.255.0 any

access-list Lan_access_in extended deny ip any any

pager lines 24

mtu internet 1500

mtu LAN 1500

icmp unreachable rate-limit 1 burst-size 1

asdm image disk0:/asdm-645.bin

no asdm history enable

arp timeout 14400

access-group Lan_access_in in interface LAN

route internet 0.0.0.0 0.0.0.0 124.244.208.1 1

timeout xlate 3:00:00

timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02

timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00

timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00

timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute

<--- More --->

timeout tcp-proxy-reassembly 0:01:00

timeout floating-conn 0:00:00

dynamic-access-policy-record DfltAccessPolicy

aaa authentication ssh console LOCAL

aaa authentication http console LOCAL

http server enable 444

http 192.168.18.0 255.255.255.0 LAN

http 0.0.0.0 0.0.0.0 internet

no snmp-server location

no snmp-server contact

crypto ipsec security-association lifetime seconds 28800

crypto ipsec security-association lifetime kilobytes 4608000

telnet timeout 5

ssh 0.0.0.0 0.0.0.0 internet

ssh 192.168.18.0 255.255.255.0 LAN

ssh timeout 5

console timeout 0

management-access LAN

threat-detection basic-threat

threat-detection statistics access-list

no threat-detection statistics tcp-intercept

webvpn

username cisco password 3USUcOPFUiMCO4Jk encrypted

<--- More --->

username itadmin password M5SKGxQcWvugHZqs encrypted

!

class-map inspection_default

match default-inspection-traffic

!

!

policy-map type inspect dns preset_dns_map

parameters

  message-length maximum client auto

  message-length maximum 512

policy-map global_policy

class inspection_default

  inspect dns preset_dns_map

  inspect ftp

  inspect h323 h225

  inspect h323 ras

  inspect ip-options

  inspect netbios

  inspect rsh

  inspect rtsp

  inspect skinny 

  inspect esmtp

  inspect sqlnet

  inspect sunrpc

<--- More --->

  inspect tftp

  inspect sip 

  inspect xdmcp

!

service-policy global_policy global

prompt hostname context

no call-home reporting anonymous

call-home

profile CiscoTAC-1

  no active

  destination address http https://tools.cisco.com/its/service/oddce/services/DDCEService

  destination address email callhome@cisco.com

  destination transport-method http

  subscribe-to-alert-group diagnostic

  subscribe-to-alert-group environment

  subscribe-to-alert-group inventory periodic monthly

  subscribe-to-alert-group configuration periodic monthly

  subscribe-to-alert-group telemetry periodic daily

Cryptochecksum:5f4fd23c149351a064901cafe5b059d7

: end

ASA5505#

I just try to download to JAVA6, it work fine.

Hi Chun,

To be able to use ASDM with JAVA 7, you may need to update the ASDM version to 7.1.

HTH.

Portu.

i try to use 7.1 ASDM already but i fail

But i am working fine with that, in ASA5510 but not in 5505

Should i use IOS 825-k8 with asdm7.1?

From the configuration i can see that we are not using the 7.1 version, it might be uploaded to flash but not being used by the unit.

Try this:

no asdm image disk0:/asdm-645.bin

asdm image disk0:/asdm-712.bin

Then from a Java 7 computer, try to access ASDM.

Is there any different between

asdm image disk0:/asdm-712.bin

asdm image flash:/asdm-712.bin?

because i do the second one normally

Review Cisco Networking for a $25 gift card