cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1858
Views
0
Helpful
11
Replies

SSH into ASR 4321 Not Working

NETAD
Level 4
Level 4

Hello, running into a weird issue with SSH into a router an ASR 4321. It's timing out from remote sites while it works from the local site. We can ping the router, so we know routing is there but ssh and telnet timeout. Not ACLs at all on the router. I captured and attached is what I see. Please assist. Router is running 15.5(2)s

11 Replies 11

marce1000
VIP
VIP

 

 - What if the remote sites impose restrictions for reaching your ASR trough SSH (such as fire-walling for both Internet and  or Intranet traffic).

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

There isn’t any. We’re able to ssh to the switch downstream from the router just fine.

Hello


@NETAD wrote:

There isn’t any. We’re able to ssh to the switch downstream from the router just fine.


So you can ssh/telnet from the rtr but not to the router correct?

sh management-interface
sh run | sec line


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

laporte-r1#sh run | sec control-plane
control-plane
laporte-r1#

jmperlewitz
Level 1
Level 1

Check which protocols are allowed for the control plane..  You can allow only explicit protocols and sources to the control plane which does not use ACLs.  Can you paste the following:

 

sh run | sec control-plane

laporte-r1#sh run | sec control-plane
control-plane
laporte-r1#
Nothing there

curious if you ever figured this out? I'm having a similar issue where i can log into the router from the same segment in the Mgmt-vrf or local peerings.  Although, I can't ssh to this router from remote networks but I can get into routers/switches from remote networks in the same segment. 

If you would post a sanitized copy of your configuration we might be better able to identify the issue.

HTH

Rick

Will do later today. Thanks Rich.

I will take a look at it when you get the config posted.

HTH

Rick

Still unable to. I will post my config and see if Rich can help. 

 

Review Cisco Networking products for a $25 gift card