cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
701
Views
0
Helpful
5
Replies

SSH Failing to connect

andrewjballard
Level 1
Level 1

Hello,

I recently upgraded my firewalls to 8.2(4), since then we have had an issue connecting to remote hosts vis ssh.  (this upgrade may be a red herring as it didn't effect ssh on another site)

the problem is from inside i can start an ssh session to a remote host throught the firewall.  I see the SYN, then the SYN ACK, but the ACK never seems to pass through the firewall.  The result is that the remote host keeps sending the SYN ACK's and the inside host keeps sending the ACK until the connection times out.

What is also strange about this is that if i telnet to the remote host using port 22 i can connect.

Any suggestions on where to look for a reolution would be very much appreciated.

Thanks

5 Replies 5

are you able to SSH to the same remote host by-passing the ASA? from another location I mean.

lcaruso
Level 6
Level 6

sh log

if message about cannot fetch crypto keys, regenerate....

crypto key generate rsa modulus 2048

If i try to connect from a different site through a firewall running the same ios level, the connection is successful.

I am also not seeing any messages about crypto keys, and i can ssh to the firewall itself.

After working with Cisco TAC to resolve the issue, the fix was to upgrade to

8.2.4.2 IOS.

Now ssh traffic can pass through the firewall.

good to hear. Thanks for sharing.

Review Cisco Networking for a $25 gift card