10-10-2024 12:47 AM
Hi,
We have a cisco 4221 router. When I try accessing its GUI page on https://192.168.10.1 its not letting me access that.
What all I have tried and not working is as follows:
Please help me with that.
PS: I am not a network expert. I am amateur at it. But I can manage configuration through GUI.
10-10-2024 01:53 AM
Hi
What type of errors you see when you try to access? I believe you also need to specify secure port right after the ip address. This could also be a certificate issue. Can you actually ping this ip? or SSH using the same ip address?
Thank you
10-10-2024 04:02 AM
These are the screenshots of the three browsers.
I don't think if any port number is needed. How to verify that?
I can ping this IP.
10-10-2024 04:38 AM - edited 10-10-2024 04:38 AM
Still same issue. I have tried with different computer as well.
10-10-2024 05:10 AM
Are you sure you have HTTPS enabled on the device? Did you try using only HTTP?
Also, try to use the browser in incognito mode.
10-10-2024 05:27 AM
I tried HTTP and its forcibly redirecting to HTTPS. And yes I have tried incognito mode as well.
10-10-2024 05:39 AM
This redirect is on the browser and you can disable it. Lastly, browser are presenting this odd behavior due security to force to use HTTPS but, sometimes we need HTTP.
10-10-2024 05:42 AM
I tried turning off redirects but still no luck.
10-10-2024 05:47 AM
Then, you need to get a console cable and connect to the device using CLI. We need to see the configuration in order to help you to fix it.
Only one question, you tried to disable redirect but it did not disable or it did but you also can not access using HTTP?
We need to check IF HTTP/HTTPS is enabled on the device and which configuration it has.
10-10-2024 06:06 AM
I tried one thing. I installed PuTTY and entered the IP 192.168.10.1 and then the credentials and it was authenticated. Is there any command I can run there to provide the details you asked? I’m asking this because finding a console cable will be another challenge for me.
10-10-2024 06:09 AM
If you have access via Putty, not necessary console.
If you are logged via Putty, please run the command "show run" and press enter.
Take the whole output and share here please.
10-10-2024 11:54 AM
There is no command like that. See the error screenshot attached.
10-10-2024 11:58 AM
you need to type "enable" then you are going to get in the prompt with # at the end.
There you can run the command "show run"
10-10-2024 12:07 PM
Thanks. Here is the output
SHOW RUN
Building configuration...
Current configuration : 1692 bytes
!
! Last configuration change at 18:49:21 UTC Thu Oct 10 2024
!
version 16.8
service timestamps debug datetime msec
service timestamps log datetime msec
platform qfp utilization monitor load 80
no platform punt-keepalive disable-kernel-core
!
hostname Router
!
boot-start-marker
boot-end-marker
!
!
enable password cisco@123
!
no aaa new-model
!
!
ip dhcp pool WIFI
network 192.168.10.0 255.255.255.0
default-router 192.168.10.1
dns-server 8.8.8.8
!
!
!
!
!
!
!
!
!
!
subscriber templating
!
!
!
!
!
!
!
multilink bundle-name authenticated
!
!
!
!
!
license udi pid ISR4221/K9 sn FGL2421LVK4
no license smart enable
diagnostic bootup level minimal
!
spanning-tree extend system-id
!
!
!
username cisco password 0 cisco@123
!
redundancy
mode none
!
!
!
!
!
vlan internal allocation policy ascending
!
!
!
!
!
!
!
!
!
!
!
!
!
!
interface GigabitEthernet0/0/0
ip address 192.168.1.100 255.255.255.0
ip nat outside
negotiation auto
!
interface GigabitEthernet0/0/1
no ip address
shutdown
negotiation auto
!
interface GigabitEthernet0/1/0
!
interface GigabitEthernet0/1/1
!
interface GigabitEthernet0/1/2
!
interface GigabitEthernet0/1/3
!
interface Vlan1
ip address 192.168.10.1 255.255.255.0
ip helper-address 192.168.10.1
ip nat inside
!
ip nat inside source list 10 interface GigabitEthernet0/0/0 overload
ip forward-protocol nd
ip http server
ip http authentication local
ip http secure-server
ip route 0.0.0.0 0.0.0.0 192.168.1.1
!
!
access-list 10 permit any
!
!
!
!
control-plane
!
!
line con 0
transport input none
stopbits 1
line vty 0 4
login local
transport input telnet
!
wsma agent exec
!
wsma agent config
!
wsma agent filesys
!
wsma agent notify
!
!
end
Router#show logging
Syslog logging: enabled (0 messages dropped, 2 messages rate-limited, 0 flushes, 0 overruns, xml disabled, filtering disabled)
No Active Message Discriminator.
No Inactive Message Discriminator.
Console logging: level debugging, 87 messages logged, xml disabled,
filtering disabled
Monitor logging: level debugging, 0 messages logged, xml disabled,
filtering disabled
Buffer logging: level debugging, 87 messages logged, xml disabled,
filtering disabled
Exception Logging: size (4096 bytes)
Count and timestamp logging messages: disabled
Persistent logging: disabled
No active filter modules.
Trap logging: level informational, 77 message lines logged
Logging Source-Interface: VRF Name:
Log Buffer (4096 bytes):
: ONEP: Service set Base was enabled by Default
*Oct 10 18:49:11.687: %CRYPTO_ENGINE-5-KEY_ADDITION: A key named TP-self-signed- 1236578148 has been generated or imported
*Oct 10 18:49:16.036: %SYS-2-PRIVCFG_DECRYPT: Successfully apply the private con fig file
*Oct 10 18:49:16.332: %SYS-5-CONFIG_I: Configured from memory by console
*Oct 10 18:49:16.346: %IOSXE_OIR-6-REMSPA: SPA removed from subslot 0/0, interfa ces disabled
*Oct 10 18:49:16.346: %IOSXE_OIR-6-REMSPA: SPA removed from subslot 0/1, interfa ces disabled
*Oct 10 18:49:16.357: %SPA_OIR-6-OFFLINECARD: SPA (ISR4221-2x1GE) offline in sub slot 0/0
*Oct 10 18:49:16.364: %SPA_OIR-6-OFFLINECARD: SPA (NIM-ES2-4) offline in subslot 0/1
*Oct 10 18:49:16.369: %IOSXE_OIR-6-INSCARD: Card (fp) inserted in slot F0
*Oct 10 18:49:16.369: %IOSXE_OIR-6-ONLINECARD: Card (fp) online in slot F0
*Oct 10 18:49:16.413: %IOSXE_OIR-6-INSCARD: Card (cc) inserted in slot 0
*Oct 10 18:49:16.414: %IOSXE_OIR-6-ONLINECARD: Card (cc) online in slot 0
*Oct 10 18:49:16.600: %IOSXE_OIR-6-INSSPA: SPA inserted in subslot 0/0
*Oct 10 18:49:16.604: %IOSXE_OIR-6-INSSPA: SPA inserted in subslot 0/1
*Oct 10 18:49:19.023: %SYS-5-RESTART: System restarted --
Cisco IOS Software [Fuji], ISR Software (X86_64_LINUX_IOSD-UNIVERSALK9_IAS-M), V ersion 16.8.1, RELEASE SOFTWARE (fc3)
Technical Support: http://www.cisco.com/techsupport
Copyright (c) 1986-2018 by Cisco Systems, Inc.
Compiled Tue 27-Mar-18 13:43 by mcpre
*Oct 10 18:49:19.050: %SSH-5-ENABLED: SSH 1.99 has been enabled
*Oct 10 18:49:19.125: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is OFF
*Oct 10 18:49:19.125: %CRYPTO-6-GDOI_ON_OFF: GDOI is OFF
*Oct 10 18:49:19.389: %CRYPTO_ENGINE-5-KEY_ADDITION: A key named TP-self-signed- 1236578148.server has been generated or imported
*Oct 10 18:49:24.065: %SPA_OIR-6-ONLINECARD: SPA (ISR4221-2x1GE) online in subsl ot 0/0
*Oct 10 18:49:25.062: %CRYPTO-6-ISAKMP_ON_OFF: ISAKMP is OFF
*Oct 10 18:49:25.063: %CRYPTO-6-GDOI_ON_OFF: GDOI is OFF
*Oct 10 18:49:25.981: %LINK-3-UPDOWN: Interface GigabitEthernet0/0/0, changed st ate to down
*Oct 10 18:49:26.766: %PNP-6-PNP_DISCOVERY_STOPPED: PnP Discovery stopped (Start up Config Present)
*Oct 10 18:49:27.000: %CRYPTO_ENGINE-5-KEY_ADDITION: A key named CISCO_IDEVID_SU DI has been generated or imported
*Oct 10 18:49:27.031: %PKI-2-NON_AUTHORITATIVE_CLOCK: PKI timers have not been i nitialized due to non-authoritative system clock. Ensure system clock is configu red/updated.
*Oct 10 18:49:29.032: %SPA_OIR-6-ONLINECARD: SPA (NIM-ES2-4) online in subslot 0 /1
*Oct 10 18:49:30.994: %LINK-3-UPDOWN: Interface GigabitEthernet0/1/0, changed st ate to down
*Oct 10 18:49:31.005: %LINK-3-UPDOWN: Interface GigabitEthernet0/1/1, changed st ate to down
*Oct 10 18:49:31.011: %LINK-3-UPDOWN: Interface GigabitEthernet0/1/2, changed st ate to down
*Oct 10 18:49:31.016: %LINK-3-UPDOWN: Interface GigabitEthernet0/1/3, changed st ate to down
*Oct 10 18:49:33.923: %LINK-3-UPDOWN: Interface GigabitEthernet0/1/0, changed st ate to up
*Oct 10 18:49:34.923: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEth ernet0/1/0, changed state to up
*Oct 10 18:49:36.919: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan1, cha nged state to up
*Oct 10 19:05:16.111: SSH-1: Not an SSH session connection block
*Oct 10 19:05:16.111: SSH-1: Not an SSH session connection block
*Oct 10 19:05:16.111: SSH-1: Not an SSH session connection block
*Oct 10 19:05:16.111: SSH-1: Not an SSH session connection block
*Oct 10 19:05:16.112: SSH-1: Not an SSH session connection block
*Oct 10 19:05:16.112: SSH-1: Not an SSH session connection block
*Oct 10 19:05:16.112: SSH-1: Not an SSH session connection block
*Oct 10 19:11:04.562: SSH-1: Not an SSH session connection block
*Oct 10 19:11:04.562: SSH-1: Not an SSH session connection block
*Oct 10 19:11:04.562: SSH-1: Not an SSH session connection block
*Oct 10 19:11:04.562: SSH-1: Not an SSH session connection block
*Oct 10 19:11:04.562: SSH-1: Not an SSH session connection block
*Oct 10 19:11:04.562: SSH-1: Not an SSH session connection block
*Oct 10 19:11:04.562: SSH-1: Not an SSH session connection block
10-10-2024 11:52 AM
This is how I disabled but it still redirects.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide