Hello,
I have a strange problem where the active FW in a HA pair (5585X-SSP40 ASA 9.4.2) is passing through traffic okay but SSH is not getting to the FW.
The SSH config is setup to accept from any source (0.0.0.0/0) and this works to the secondary standby.
The management routes point to the correct destinations as the secondary/standby is reachable using the synced config from remote SSH terminals. I can ping the secondary management IP but not the primary.
For a few hours I could SSH directly from the management switch in the same VLAN as the ASA management IP but this has stopped now also. When on the primary SSH'd from the local switch I can ping out beyond the VLAN.
Fail over state shows the affected device for management access is primary and the peer is standby ready.
Before I go and raise a Cisco TAC and cause myself a realm of grief with our client I wondered if anyone out there has had similar issues and can recommend anything to look at.
Regards
Grant