cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3736
Views
2
Helpful
18
Replies

Cisco 9115AXI EWC cannot access to WebUI remotely

JohnAJ
Level 1
Level 1

Hi all, 

 

I have an issue with my Cisco 9115AXI EWC where I can't access via WebUI. I have enable the http and http-secure server as well but failed.

I have saw the traffic that pass through the firewall (Palo Alto), it shows that the application incomplete and status is aged-out. There is no blocking in the firewall since all the traffic is allow for this IP management segment for the EWC.

 

Anyone facing this issue before and give suggestion, if any? 

18 Replies 18

marce1000
VIP
VIP

 

 - Does it work from a local-perspective, the palo alto message is for instance discussed in this thread :

                  https://live.paloaltonetworks.com/t5/general-topics/aged-out-in-allowed-traffic-logs/td-p/295534

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

Hi marce1000, 

 

what i understand on the article, means the traffic going to the EWC WebUI is using different route, then when it comes back, it using other route?

 

But I dont think thats the issue since we have also switches and routers there, and if I am trying accessing their WebUI, somehow, it success.

 

I was thinking its the bug on the version, I have downgrade and upgrade as well to the latest version, however, still not solve the problem.

 

Any suggestion where I can check? 

Are you able to access the WebUI from a local subnet or even from the same subnet? Validate if that is working first or not.
-Scott
*** Please rate helpful posts ***

Hi Scott, 

 

Yes, I am able to access from same subnet.

 

 

Then there is nothing wrong with from what I can tell. If you can access the WebUI from another vlan that doesn’t hit your FW just you L3, then you know that the WebUI is functioning and must be your infrastructure.
-Scott
*** Please rate helpful posts ***

 

  - What error do you get ? Also can you then ping the 9115 (e.g.)

 M.



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

Hi Marce1000, 

 

There is no error I get from the browser, its just that keep loading and display at below "Waiting for 10.62.31.254"

 

I can ping without any ping drop and able to SSH remotely on the same PC that I use to access the WebUI.

 

 

 

 - Make sure that no local rules such as ACL or other prevent this remote access WebUI access. In that respect, using SSH check the device logs when this is attempted. Also try wget to fetch the page , and turn on debugging , this may give more insights (too).

                          https://linux.die.net/man/1/wget

  M.

 



-- ' 'Good body every evening' ' this sentence was once spotted on a logo at the entrance of a Weight Watchers Club !

Can you ping the EWC remotely? (in other words does it have a route back to the remote user?)

Hi rrudling, 

 

Sorry for the late feedback. Yes I can ping the EWC and I also able to access via SSH remotely. I also suspecting the issue is either from the Palo Alto remote site or the local site. However, the Firewall team inform they have allow all the session and not blocking it. Not sure how to troubleshoot on this, currently, I am using SSH to configure the EWC remotely. I will use GUI when Im at site.

Hi marce1000, 

 

sorry for the late reply. I might can use this way also to see if the traffic is really reaching the EWC. Will try it later. thanks!

Marcel B
Level 1
Level 1

Hello JohnAJ,

i know this thread is two years old, but did you get solved the problem finally?

I have a similiar situation with three Sophos firewalls instead of PaloAlto and a IPSec Tunnel between Headquarter and Branch Offices. Local access in same subnet or from other subnet behind the same firewall, no problem. But if I try to access the EWCs behind the firewalls at the branch offices over the IPSec Tunnel, no way. Curios thing, if i connect to firewall at HQ by VPN from external, i can access the EWCs behind the walls in the branch offices. I am currently at this with Sophos Support, they are analyzing packet captures from all three walls.

best regards

Marcel

Have you got a packet capture of the PC you're trying to access the GUI from?
Do you get *any* reply from the EWC?
Just an idea (in case it's fragmentation related - since you mention IPSEC): try "ip tcp mss 1250" on the EWC?
And if your firewall supports TCP MSS adjust then set that to 1250 too (your remote VPN might be doing that which is why it works)

Hello Rich R,

thanks for your answer. Yes, i get a reply, if I analyzed it right, it stops somewhere after the SSL handshake, i can see the certificate in the packets and many, many retransmissions, after a while the connection is resetted. SSH connection ist no problem, i am also recieving snmp and syslog data, so it seems to be only http/https related problem.

I configured "ip tcp mss 1250" on one of the controllers to test (by ssh), but no luck. Do i have to reboot the EWC to activate this setting? If yes, i will have to wait for the night, as EWC is in production.

The Sophos UTM doesnt seem to support this option, at least not on the IPSec Tunnel, only on real ethernet interfaces. I have remote session with them tomorrow, maybe the will find something.

best regards
M. Baltruschat

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card