Solved

Cat Tools backup firewall module of Cisco 6506

Posted on 2011-03-17
11
949 Views
Last Modified: 2012-05-11
I want to backup config file of fire wall module of 6506 and it keeps failling.

Put ssh username and password and Enable password. To me look like all the entry is fine, but when it authenticated username and password then it dropps.

In CatTools I get faild login here is the firewall logs. 10.9.2.18 is the IP of the server & 10.12.0.1 is IP of firewall.

%FWSM-6-611101: User authentication succeeded: Uname: testusername
%FWSM-6-605005: Login permitted from 10.9.2.18/51554 to INTERNAL-FW:10.12.0.1/ss h for user "testusername"
%FWSM-6-302014: Teardown TCP connection 0 for INTERNAL-FW:10.12.0.1/1118 to INTE RNAL-FW:10.9.8.24/49 duration 0:00:00 bytes 754 TCP FINs
%FWSM-6-106015: Deny TCP (no connection) from 10.9.2.18/51553 to 10.12.0.1/22 fl ags ACK  on interface INTERNAL-FW
%FWSM-6-106015: Deny TCP (no connection) from 10.9.2.18/51553 to 10.12.0.1/22 fl ags RST  on interface INTERNAL-FW

I can login to firewall normally with CatTools telent/ssh and with putty as well.
0
Comment
Question by:piji
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 3
  • 3
11 Comments
 
LVL 5

Accepted Solution

by:
shubhanshu_jaiswal earned 300 total points
ID: 35164986
are you able to ping or telnet the module from your backup server...
0
 
LVL 5

Author Comment

by:piji
ID: 35165379
Yes, as I mentioned, even I can do telnet or ssh from CatTools with click on the button. Just the auto config backup couldn’t login to firewall.
0
 
LVL 5

Assisted Solution

by:shubhanshu_jaiswal
shubhanshu_jaiswal earned 300 total points
ID: 35166035
There must be some info logs in the Cattools...what does they say...
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 5

Author Comment

by:piji
ID: 35166643
If I put the wrong username and password, then comes up with username and password is incorect. But if the ussername and password is fine comes with "login failed".
0
 
LVL 5

Assisted Solution

by:shubhanshu_jaiswal
shubhanshu_jaiswal earned 300 total points
ID: 35170493
can you put the snapshot of the password settings for that device...
0
 
LVL 19

Assisted Solution

by:nodisco
nodisco earned 200 total points
ID: 35176318
Hey
What ssh are you using from Cattools?

There are options for ssh1, ssh2 and Cisco ssh
Its in the device configuration - I use Cisco SSH for firewalls but have not tried it on a firewall module.

Try the options here incuding telnet if you can't get ssh to happen.

hth
0
 
LVL 5

Author Comment

by:piji
ID: 35229791
I have tried all of those ssh but didn't work where can I find the option for ssh give me more details, can't find it.
0
 
LVL 19

Assisted Solution

by:nodisco
nodisco earned 200 total points
ID: 35229824
Click on the devices tab then click on the device and click edit.
The information you are looking for is Connect Via - and Method *
Method lists the versions of ssh

I would try a couple of these out
0
 
LVL 5

Assisted Solution

by:piji
piji earned 0 total points
ID: 35229919
Thanks guys for your comment, when I change the device type to Firewall.ASA it works.
0
 
LVL 19

Expert Comment

by:nodisco
ID: 35229936
Good stuff!
0
 
LVL 5

Author Closing Comment

by:piji
ID: 35292658
My last comment was the solution
0

Featured Post

Surfing Is Meant To Be Done Outdoors

Featuring its rugged IP67 compliant exterior and delivering broad, fast, and reliable Wi-Fi coverage, the AP322 is the ideal solution for the outdoors. Manage this AP with either a Firebox as a gateway controller, or with the Wi-Fi Cloud for an expanded set of management features

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

I found an issue or “bug” in the SonicOS platform (the firmware controlling SonicWALL security appliances) that has to do with renaming Default Service Objects, which then causes a portion of the system to become uncontrollable and unstable. BACK…
For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

756 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question