02-26-2014 10:34 AM - edited 03-11-2019 08:50 PM
Hi,
Tried logging in via ASDM, but apperantly there is a command I need to run first.
So plugged console cable into my laptop and firewall, ciscoasa> comes up, but I cannot log into it?
I thought username: cisco and password: cisco were the defaults? Any ideas?
Solved! Go to Solution.
02-28-2014 05:54 AM
You don't.- it's the (free) "3DES/AES License" you need - as I noted in my initial post. It just coincidentally appears on the same page as IPS licenses.
The 3DES/AES License allows your ASA to support strong encryption that is built into all modern web browsers. Without it, the https transport cannot negotiate to an acceptably strong cipher suite.
02-26-2014 11:15 AM
Managed to login to the asa via the console, didnt type the enable command.
Have another question, I still cannot access the ASDM via the MGMT port on 192.168.1.1, so I typed the below command as https://supportforums.cisco.com/thread/2198194 suggested:
ssl encryption aes128-sha1 3des-sha1
and I get a message:
The 3DES/AES algorithms require a VPN-3DES-AES activation key
Any ideas?
02-26-2014 02:44 PM
Your ASA was not ordered with the strong encryption option. Assuming you're not in a prohibited country (e.g. North Korea, Iran etc.), you can go the the licensing portal and get the necessary activation key in just a few minutes.
https://tools.cisco.com/SWIFT/LicensingUI/Quickstart
Choose Get New > IPS, Crypto or Other licenses. On the subsequent page choose Security Products > Cisco ASA 3DES/AES License. Provide your serial number and the portal will generate the activation-key you need via e-mail with instructions to install it.
02-27-2014 10:14 AM
Hi,
I went to the above link but I couldnt see an option for IPS.
Can you be more specfic with the instructions.
Start licensing wizard?
02-27-2014 04:21 PM
See the following screen shots (click to enlarge) for Step #1, #2 and #3 following the link I posted above.
02-28-2014 12:54 AM
Marvin, many thanks for that. I dont seem to have these options in the screen shot? logged in etc. Firewall is not registered on my account yet, this why? If so how do I go about this?
02-28-2014 01:08 AM
Was because I was using IE11 ! Tried Firefox and I have the available options.
Anyway, gone through all the steps and get stuck here:
02-28-2014 01:29 AM
Marvin,
Why do I need this IPS license? My old ASA5510 didnt require an IPS license to access the ASDM?
02-28-2014 05:54 AM
You don't.- it's the (free) "3DES/AES License" you need - as I noted in my initial post. It just coincidentally appears on the same page as IPS licenses.
The 3DES/AES License allows your ASA to support strong encryption that is built into all modern web browsers. Without it, the https transport cannot negotiate to an acceptably strong cipher suite.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide