cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4036
Views
5
Helpful
19
Replies

Terminal Service Gateway 1000 console connection issue.

nailaalam
Level 1
Level 1

Hi All,
We have recently configured a TSG 1100 but we have not been lucky in getting ssh/telnet access on any Console port connected to it yet.
For the config,we have configured a loopback address and a few ip hosts commands to map the loopback to host devices with port number starting 2033.
Just wondered if there is anything obvious we are missing here?
Below is the sample config:

 

ip host CON2 2033 172.29.2.100

###########################

TSG1#show run | s line
line con 0
stopbits 1
line aux 0
stopbits 1
line 0/1/0 0/1/31
login authentication AAA
transport input all
line vty 0 4
login authentication AAA
transport input ssh
line vty 5 15
login authentication AAA
transport input ssh

#############################

Loopback1 172.29.2.100 YES manual up up

#########################

TSG1#telnet 172.29.2.100 2033
Trying 172.29.2.100, 2033 ... Open
CC


++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+ +
+ It is a criminal offence, liable to prosecution under the Computer +
+ Misuse Act, to access, use or copy any programs or data on this +
+ system without authorisation. Passing this point will imply you +
+ you have read and understood this notice and are an authourised +
+ user. Unauthourised users should disconnect immediately. +
+ +
+
+ +
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

 

Username:admin
Password:
ctrl-shift-6-x(as no connection made the console of the connected device)
TSG1#show sessions
Conn Host Address Byte Idle Conn Name
]* 1 172.29.2.100 172.29.2.100 0 0 172.29.2.100

##############################

TSG1#show line 33

Tty Line Typ Tx/Rx A Modem Roty AccO AccI Uses Noise Overruns Int
*0/1/31 33 TTY 9600/9600 - - - - - 9 0 0/0 -

Line 0/1/31, Location: "", Type: "xterm"
Length: 24 lines, Width: 80 columns
Baud rate (TX/RX) is 9600/9600, no parity, 2 stopbits, 8 databits
Status: Ready, Connected, Active
Capabilities: none
Modem state: Ready
Modem hardware state: noCTS noDSR DTR noRTS
Special Chars: Escape Hold Stop Start Disconnect Activation
^^x none - - none
Timeouts: Idle EXEC Idle Session Modem Answer Session Dispatch
00:10:00 never none not set
Idle Session Disconnect Warning
never
Login-sequence User Response
00:00:30
Autoselect Initial Wait
not set
Modem type is unknown.
Session limit is not set.
Time since activation: 00:03:01
Editing is enabled.
History is enabled, history size is 10.
DNS resolution in show commands is enabled
Full user help is disabled
Allowed input transports are pad telnet rlogin ssh.
Allowed output transports are pad telnet rlogin ssh.
Preferred transport is telnet.
Shell: enabled
Shell trace: off
No output characters are padded
No special data dispatching characters

#####################################

TSG1# show interfaces async 0/1/31
Async0/1/31 is up, line protocol is down
Hardware is C1100TG-A-32
MTU 1500 bytes, BW 9 Kbit/sec, DLY 0 usec,
reliability 1/255, txload 1/255, rxload 1/255
Encapsulation ASYNC, loopback not set
Keepalive not set
DTR is pulsed for 5 seconds on reset
Last input never, output never, output hang never
Last clearing of "show interface" counters never
Input queue: 0/375/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/0 (size/max)
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
0 packets input, 0 bytes, 0 no buffer
Received 0 broadcasts (0 IP multicasts)
0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
2 packets output, 2 bytes, 0 underruns
Output 0 broadcasts (0 IP multicasts)
0 output errors, 0 collisions, 1 interface resets
0 unknown protocol drops
0 output buffer failures, 0 output buffers swapped out
0 carrier transitions
DCD=down DSR=down DTR=down RTS=down CTS=down


Autoselect Initial Wait
not set

##################################
the weird thing is that the Banner displayed after telnet is that of the TSG itself and not of the device connected.
any thoughts as scratching my head over this issue.

19 Replies 19

Mark Elsen
Hall of Fame
Hall of Fame

 

 - Ref : https://www.cisco.com/c/en/us/td/docs/cloud-systems-management/network-automation-and-management/terminal-services-gateways/sw-config/tg1100swcfg-xe-17-2-book.pdf

  start reading from Using SSH to Access Console and verify the configuration accordingly.

 M.



-- Let everything happen to you  
       Beauty and terror
      Just keep going    
       No feeling is final
Reiner Maria Rilke (1899)

Thanks Marc but i dont see anything new in that section,i have transport input all so wheter i try telnet or ssh,that should work to the remote router/switch?

 

Hello,

 

also, post the full configuration of your router. 

TSG1#show running-config
Building configuration...

Current configuration : 10977 bytes
!
! Last configuration change at 16:06:16 UTC Fri Feb 4 2022 by u30630
! NVRAM config last updated at 11:23:44 UTC Fri Feb 4 2022 by u30630
!
version 17.2
service timestamps debug datetime msec
service timestamps log datetime msec
service call-home
platform qfp utilization monitor load 80
platform punt-keepalive disable-kernel-core
!
hostname TSG1
!
boot-start-marker
boot-end-marker
!
!
logging console informational
enable secret 9 jjhgjhgjgtrresezd6787yjhjhj
!
aaa new-model
!
!
aaa group server tacacs+ YBS_AAA
server-private 1.1.1.1 timeout 60 key 7 8788yghhgjkhgjkhgjgjhgjhgjgj
server-private 2.2.2.2 timeout 60 key 7 8788yghhgjkhgjkhgjgjhgjhgjgj
ip tacacs source-interface GigabitEthernet0/0/0
!
aaa authentication fail-message ^CCC

 

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+ +
+ The logon information you supplied is incorrect. +
+ +
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++


^C
aaa authentication login default group AAA local
aaa authentication enable default group AAA enable
!
!
!
!
!
!
aaa session-id common
ip arp entry learn 10240
!
ip host CON2 2033 172.29.2.100
ip name-server 1.1.1.1 2.2.2.2
ip domain lookup source-interface GigabitEthernet0/0/0
ip domain name abc.com
!
!
!
login on-success log
!
!
!
!
!
!
!
subscriber templating
multilink bundle-name authenticated
!
!
!
crypto pki trustpoint TP-self-signed-1723348571
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1723348571
revocation-check none
rsakeypair TP-self-signed-1723348571
!
crypto pki trustpoint SLA-TrustPoint
enrollment pkcs12
revocation-check crl
!
!
crypto pki certificate chain TP-self-signed-1723348571
certificate self-signed 01
30820330 30820218 A0030201 02020101 300D0609 2A864886 F70D0101 05050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31373233 33343835 3731301E 170D3139 31323130 31363035
34335A17 0D333030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 37323333
34383537 31308201 22300D06 092A8648 86F70D01 01010500 0382010F 00308201
0A028201 0100A57A E8ECAC30 19C44730 9D3995B5 B76C285C 1B9E443F A4C33E6E
DB3A419B A0CFB9EC AB968E0D 52C645AA 4196B318 8016C44F 7DFB70B5 E188E7F0
FA444EFD 10F089D6 E0F874C0 51B422D9 666E3354 C11AC6AD 797BE9E3 DED3D854
301F0603 551D2304 18301680 14B6C397 6AE431A0 ABBA2275 2E4728F2 FA980992
17301D06 03551D0E 04160414 B6C3976A E431A0AB BA22752E 4728F2FA 98099217
300D0609 2A864886 F70D0101 05050003 82010100 427BE2CE 15BEE9D2 935C6302
6D6B891A 6BE8D02E 6AB872F5 E030F01E CEAA0AF9 B2A1E968 C82DC6FC CCCE8067
FC2B03F2 370CC48A F374A77C B52C925D 4C77006D 5C6B353D 233771F2 EC4D1168
C0E491C9 4636BC5A 9BBCB4BC 9D72E369 44290405 2EC73527 51D944B0 98439463
9EF6A652 D4C94C27 AC3308CE C73868AD 01C849E2 8914F31C E2AE54BA 0F2889CB
06518D0E 2840B087 4AE25ACD D684634D DEA0E049 CD0D1323 65990744 7ACD105B
7C0A8584 DDD81144 04B90DF1 A7845199 C46215DA 1881DF5D EB70C3A5 912EBD86
2D72069A FB5F10B4 79CEAEEC 892EC4CD 8E21E9AE
quit
crypto pki certificate chain SLA-TrustPoint
certificate ca 01
30820321 30820209 A0030201 02020101 300D0609 2A864886 F70D0101 0B050030
32310E30 0C060355 040A1305 43697363 6F312030 1E060355 04031317 43697363
6F204C69 63656E73 696E6720 526F6F74 20434130 1E170D31 33303533 30313934
3834375A 170D3338 30353330 31393438 34375A30 32310E30 0C060355 040A1305
43697363 6F312030 1E060355 04031317 43697363 6F204C69 63656E73 696E6720
526F6F74 20434130 82012230 0D06092A 864886F7 0D010101 05000382 010F0030
68E69491 20F320E7 948E71D7 4BC8E00F 539BA42B 42C68BB7 C7479096 B4CB2D62
C55F0D76 61F9A4CD 3D992327 A8BB03BD 4E6D7069 7CBADF8B DF5F4368 95135E44
DFC7C6CF 04DD7FD1 02030100 01A34230 40300E06 03551D0F 0101FF04 04030201
06300F06 03551D13 0101FF04 05300301 01FF301D 0603551D 0E041604 1449DC85
4B3D31E5 1B3E6A17 606AF333 3D3B4C73 E8300D06 092A8648 86F70D01 010B0500
03820101 00507F24 D3932A66 86025D9F E838AE5C 6D4DF6B0 49631C78 240DA905
604EDCDE FF4FED2B 77FC460E CD636FDB DD44681E 3A5673AB 9093D3B1 6C9E3D8B
D98987BF E40CBD9E 1AECA0C2 2189BB5C 8FA85686 CD98B646 5575B146 8DFC66A8
467A3DF4 4D565700 6ADF0F0D CF835015 3C04FF7C 21E878AC 11BA9CD2 55A9232C
418616A9 4093E049 4D10AB75 27E86F73 932E35B5 8862FDAE 0275156F 719BB2F0
D697DF7F 28
quit
!
!
license udi pid C1100TG-1N24P32A sn FGL2452L6N5
memory free low-watermark processor 139228
!
diagnostic bootup level minimal
!
spanning-tree extend system-id
!
username admin privilege 15 secret 9 $9$59ShjhgjhgjhB5nU$h00AytwM/LJ1j0Rp.Uh1CKdp7v267DWB7dcsltAwCCo
!
redundancy
!
!
vlan internal allocation policy ascending
!
!
!
!
!
!
interface Loopback1
ip address 172.29.2.100 255.255.255.255
!
interface GigabitEthernet0/0/0
ip address 172.29.0.30 255.255.254.0
negotiation auto
!
interface GigabitEthernet0/0/1
no ip address
shutdown
negotiation auto
!
interface GigabitEthernet0/2/0
!
interface GigabitEthernet0/2/1
!
interface GigabitEthernet0/2/2
!
interface GigabitEthernet0/2/3
!
interface GigabitEthernet0/2/4
!
interface GigabitEthernet0/2/5
!
interface GigabitEthernet0/2/6
!
interface GigabitEthernet0/2/7
!
interface GigabitEthernet0/2/8
!
interface GigabitEthernet0/2/9
!
interface GigabitEthernet0/2/10
!
interface GigabitEthernet0/2/11
!
interface GigabitEthernet0/2/12
!
interface GigabitEthernet0/2/13
!
interface GigabitEthernet0/2/14
!
interface GigabitEthernet0/2/15
!
interface GigabitEthernet0/2/16
!
interface GigabitEthernet0/2/17
!
interface GigabitEthernet0/2/18
!
interface GigabitEthernet0/2/19
!
interface GigabitEthernet0/2/20
!
interface GigabitEthernet0/2/21
!
interface GigabitEthernet0/2/22
!
interface GigabitEthernet0/2/23
!
interface Vlan1
no ip address
!
interface Async0/1/0
no ip address
!
interface Async0/1/1
no ip address
!
interface Async0/1/2
no ip address
!
interface Async0/1/3
no ip address
!
interface Async0/1/4
no ip address
!
interface Async0/1/5
no ip address
!
interface Async0/1/6
no ip address
!
interface Async0/1/7
no ip address
!
interface Async0/1/8
no ip address
!
interface Async0/1/9
no ip address
!
interface Async0/1/10
no ip address
!
interface Async0/1/11
no ip address
!
interface Async0/1/12
no ip address
!
interface Async0/1/13
no ip address
!
interface Async0/1/14
no ip address
!
interface Async0/1/15
no ip address
!
interface Async0/1/16
no ip address
!
interface Async0/1/17
no ip address
!
interface Async0/1/18
no ip address
!
interface Async0/1/19
no ip address
!
interface Async0/1/20
no ip address
!
interface Async0/1/21
no ip address
!
interface Async0/1/22
no ip address
!
interface Async0/1/23
no ip address
!
interface Async0/1/24
no ip address
!
interface Async0/1/25
no ip address
!
interface Async0/1/26
no ip address
!
interface Async0/1/27
no ip address
!
interface Async0/1/28
no ip address
!
interface Async0/1/29
no ip address
!
interface Async0/1/30
no ip address
!
interface Async0/1/31
no ip address
!
ip default-gateway 172.29.1.254
ip forward-protocol nd
ip ftp source-interface GigabitEthernet0/0/0
no ip http server
ip http authentication local
no ip http secure-server
ip route 0.0.0.0 0.0.0.0 172.29.1.254
ip ssh time-out 10
ip ssh version 2
!
!
ip access-list standard SNMP_RO
20 permit 10.4.44.90
!
ip access-list extended TerminalAccess
10 permit tcp 10.30.180.0 0.0.0.255 any eq 22
20 permit tcp host 10.4.44.16 any eq 22
30 permit tcp 10.30.85.0 0.0.0.255 any eq 22
40 permit tcp 10.34.86.0 0.0.0.255 any eq 22
50 permit tcp host 10.4.44.13 any eq 22
60 permit tcp 10.3.9.0 0.0.0.127 any eq 22
70 permit tcp 10.6.9.0 0.0.0.127 any eq 22
!
!
!
snmp-server engineID remote 10.4.44.90 87868767867868760
snmp-server group Network v3 auth
snmp-server group Network v3 priv
snmp-server community abcd! An RO SNMP_RO
snmp-server enable traps snmp linkdown linkup
snmp-server host 10.4.44.90 version 3 auth oob-snmpv3-user
!
tacacs-server directed-request
!
!
!
control-plane
!
banner login ^CCC


++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+ +
+ It is a criminal offence, liable to prosecution under the Computer +
+ Misuse Act, to access, use or copy any programs or data on this +
+ system without authorisation. Passing this point will imply you +
+ you have read and understood this notice and are an authourised +
+ user. Unauthourised users should disconnect immediately. +
+ +
+
+ +
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++


^C
!
line con 0
stopbits 1
line aux 0
stopbits 1
line 0/1/0 0/1/31
login authentication AAA
transport input all
line vty 0 4
login authentication AAA
transport input ssh
line vty 5 15
login authentication AAA
transport input ssh
!
call-home
! If contact email address in call-home is configured as sch-smart-licensing@cisco.com
! the email address configured in Cisco Smart License Portal will be used as contact email address to send SCH notifications.
contact-email-addr sch-smart-licensing@cisco.com
profile "CiscoTAC-1"
active
destination transport-method http
ntp server 10.90.4.9 source GigabitEthernet0/0/0
ntp server time-pnp.cisco.com.
ntp server pool.ntp.org
!
!
!
!
!
end

TSG1#

Hello,

 

the only thing in your configuration that looks wrong is this line:

 

ip default-gateway 172.29.1.254

 

Remove that line from the configuration.

 

Other than that, line 33 corresponds to interface Async0/1/31...you could try another port (and corresponding line...

got the default gateway removed,sorry about that silly mistake,now i only have the ip route command..that being removed,i tested access to CON2 using ip host CON2 2033 172.29.2.100 but still no luck after being prompted for username and password,the problem is,im getting the banner of the TSG instead of the connected switch,so i doubt this is working...

Hello,

 

since you make a connection, but only with the local TSG, it almost appears that you never make the connection with whatever is hooked up to async port 0/1/31. Stupid question to ask maybe, but what cable are you using ?

Hi George,
Im using the octel cable that got delivered with the TSG.Did you mean to ask that?

Hello,

 

indeed. That appears to be the right cable. Can you test on any other other ports (e.g. interface Async0/1/0, which would be line 2002 ) ?

Also, I am not sure which debug async commands are available ?

 

TSG1100#debug async ?

il try that and let you know if i have any output

im in the DC right now,itl need planning a visit

nailaalam
Level 1
Level 1

the other end is a switch configured as
SW1#show run | s line
line con 0
login authentication AAA
transport preferred ssh
stopbits 1
line aux 0
stopbits 1
line vty 0 4
login authentication AAA
transport input ssh
line vty 5 15
login authentication AAA
transport input ssh

Hello,

 

does it work with local authentication ?

 

line con 0
login local
transport preferred ssh
stopbits 1
line aux 0
stopbits 1
line vty 0 4
login local
transport input ssh
line vty 5 15
login local
transport input ssh