Cant SSH into Cisco ASA

LIBBB
LIBBB used Ask the Experts™
on
SSH used to work fine, no changes were made when it stopped working.

I can ADSM in.

When I attempt to SSH in, its not like I get instantly rejected network wise, but the putty prompt just sits there.

This is production so a reboot will be challenging .
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Network Consultant
Commented:
I have run across a bug where telnet and ssh stop working on certain levels of the os.

If its not a bug issue you are dealing with you need to check the following items in the config:

Do you have a statement like this:

ssh 192.168.1.0 255.255.255.0 inside

or something similar...  this defines that the network 192.168.1.0 can ssh from the inside of the firewall to the asa.

in addition do you have aaa authentication ssh command configured pointing at your authentication method - maybe LOCAL  if the usernames are defined on the ASA?

Then lastly you can try to re generate your crypto key.

crypto key generate rsa modulus 1024

Author

Commented:
Yep I have those 2 commands confirmed.

SSH 0.0.0.0 0.0.0.0 outside
aaa authentication ssh console local

Yes I was thinking about re generate crypto key.

What affects will this have on the production server? I know it would break any current SSH sessions if they were there, but what about anything else?
Ken BooneNetwork Consultant

Commented:
I don't think you would have an issue doing this.  I have had to do this on a number of occassions.
Exploring SQL Server 2016: Fundamentals

Learn the fundamentals of Microsoft SQL Server, a relational database management system that stores and retrieves data when requested by other software applications.

Ken BooneNetwork Consultant

Commented:
Although if it is a bug it won't fix the problem.  Would have to reboot for that.

Author

Commented:
FYI,

I just issued

No ssh 0.0.0.0 0.0.0.0 outside

ssh 0.0.0.0 0.0.0.0 outside

and SSH worked again.
Ken BooneNetwork Consultant

Commented:
image that ;)

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial