cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
994
Views
2
Helpful
8
Replies

Cisco FMC Cli showing Access Denied while trying SSH

King_1988
Level 1
Level 1

Hi,

We have changed the FMC password from GUI. We are not able to access CLI with local users and showing 'Access Denied'. Previously we could access with same password of GUI.

We don't have any LDAP or RADIUS. Please guide to solve this issue.

 

1 Accepted Solution

Accepted Solutions

If you no longer have the cli password then there is no way to reset it from the GUI, even as admin.

In such a case, you would need to perform password recovery from the console. Here is a link to the procedure to do that:

https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118631-technote-firesight-00.html#toc-hId-241494136

View solution in original post

8 Replies 8

Marvin Rhoads
Hall of Fame
Hall of Fame

Local FMC users other than the admin built-in user are only supported with external authentication.

@Marvin Rhoads  I understand. GUI is accessible after changing the password of local user (example: admin) but why not  CLI is not accessible? Before changing the password CLI was accessible but now it is showing 'Access Denied' while trying SSH

@King_1988 please note the following:

"admin user—The management center supports two different internal admin users: one for the web interface, and another with CLI access. The system initialization process synchronizes the passwords for these two admin accounts so they start out the same, but they are tracked by different internal mechanisms and may diverge after initial configuration. See the Getting Started Guide for your model for more information on system initialization. To change the password for the web interface admin, use System > Users > Users. To change the password for the CLI admin, use the management center CLI command configure password ."

Reference: https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/admin/720/management-center-admin-72/system-users.html#id_63534

Hi Marvin,

The problem is i can't access the cli as it is showing 'Access Denied' after giving password. 

You would need to use the old admin password and not the new admin GUI password to access the CLI

--
Please remember to select a correct answer and rate helpful posts

Tried. But still not happening. Is there any other way from GUI to solve the issue as CLI can't be accessible.

If you no longer have the cli password then there is no way to reset it from the GUI, even as admin.

In such a case, you would need to perform password recovery from the console. Here is a link to the procedure to do that:

https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118631-technote-firesight-00.html#toc-hId-241494136

Thanks Marvin. After performing password recovery the issue solved.

Review Cisco Networking for a $25 gift card