[Webinar] Streamline your web hosting managementRegister Today

x
?
Solved

Unable to manage ASA device

Posted on 2007-10-15
3
Medium Priority
?
2,011 Views
Last Modified: 2010-08-05
I have a asa 5505 at a remote location, in which does not allow me to access using: http, telnet, or ASDM.
When I attempt to access via ASDM I receive the following error: unable to launch ASDM from (IP ADDRESS)  unexpected end of file from server


CONFIG:

ASA Version 8.0(2)
!
hostname ASA123
enable password C9DpliqVB7t8EEvU encrypted
names
!
interface Vlan1
 nameif inside
 security-level 100
 ip address 10.50.8.253 255.255.255.0
!
interface Vlan2
 nameif outside
 security-level 0
 ip address (PUBLIC Address) 255.255.255.0
!
interface Ethernet0/0
 switchport access vlan 2
!
interface Ethernet0/1
!
interface Ethernet0/2
!
interface Ethernet0/3
!
interface Ethernet0/4
!
interface Ethernet0/5
!
interface Ethernet0/6
!
interface Ethernet0/7
!
passwd 2KFQnbNIdI.2KYOU encrypted
boot system disk0:/asa802-k8.bin
ftp mode passive
access-list (ACCESS-GROUP) extended permit ip 10.50.22.0 255.255.255.0 10.1.0.0 255.255.0.0
access-list (ACCESS-GROUP) extended permit ip 10.50.22.0 255.255.255.0 10.2.0.0 255.255.0.0
access-list outside_acl extended permit icmp any any
pager lines 24
logging asdm informational
mtu inside 1500
mtu outside 1500
icmp unreachable rate-limit 1 burst-size 1
no asdm history enable
arp timeout 14400
global (outside) 1 interface
!

nat (inside) 1 10.50.8.0 255.255.255.0
nat (inside) 1 0.0.0.0 0.0.0.0
access-group outside_acl in interface outside
route outside 0.0.0.0 0.0.0.0 (GATEWAY) 1
timeout xlate 3:00:00
timeout conn 1:00:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
timeout sunrpc 0:10:00 h323 0:05:00 h225 1:00:00 mgcp 0:05:00 mgcp-pat 0:05:00
timeout sip 0:30:00 sip_media 0:02:00 sip-invite 0:03:00 sip-disconnect 0:02:00
timeout uauth 0:05:00 absolute
dynamic-access-policy-record DfltAccessPolicy
http server enable
http 12.xx.xx.0 255.255.255.0 outside
http 10.1.254.0 255.255.255.0 inside
http 10.1.254.8 255.255.255.0 inside

no snmp-server location
no snmp-server contact
snmp-server enable traps snmp authentication linkup linkdown coldstart
telnet 10.50.8.0 255.255.255.0 inside
telnet 10.1.254.0 255.255.255.0 inside
telnet 10.1.231.0 255.255.255.0 inside
telnet 65.xxx.143.0 255.255.255.0 outside
telnet timeout 5
ssh timeout 5
<--- More --->
             
console timeout 0
dhcpd dns 204.130.255.3 209.63.0.6
dhcpd wins 10.1.253.20 10.1.252.20
dhcpd ping_timeout 750
dhcpd domain corp.xxx.com
dhcpd auto_config outside
!
dhcpd address 10.50.8.50-10.50.8.60 inside
dhcpd enable inside
!
vpnclient server 12.xx.xx.xxx
vpnclient mode network-extension-mode
vpnclient nem-st-autoconnect
vpnclient vpngroup WarehouseVPN password ********
vpnclient username ASA123 password ********
vpnclient enable
threat-detection basic-threat
threat-detection statistics access-list
!
class-map inspection_default
 match default-inspection-traffic
!
!
policy-map type inspect dns preset_dns_map
<--- More --->
             
 parameters
  message-length maximum 512
policy-map global_policy
 class inspection_default
  inspect dns preset_dns_map
  inspect ftp
  inspect h323 h225
  inspect h323 ras
  inspect rsh
  inspect rtsp
  inspect esmtp
  inspect sqlnet
  inspect skinny  
  inspect sunrpc
  inspect xdmcp
  inspect sip  
  inspect netbios
  inspect tftp
!
service-policy global_policy global
prompt hostname context
Cryptochecksum:2b24b57f79975b3e9000ce2f4055c3dc
: end
0
Comment
Question by:jalexan798
2 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 252 total points
ID: 20081758
I don't see this in your config:
 asdm image disk0:/asdm-602.bin

0
 

Assisted Solution

by:bdurocher
bdurocher earned 252 total points
ID: 20510341
make sure you are trying to run ASDM on a computer that is on the same network as those you specified for management:

http 10.1.254.0 255.255.255.0 inside
http 10.1.254.8 255.255.255.0 inside
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
In this article, the configuration steps in Zabbix to monitor devices via SNMP will be discussed with some real examples on Cisco Router/Switch, Catalyst Switch, NAS Synology device.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …

612 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question