Solved

Cisco ASA - Cant logon SSH

Posted on 2015-01-27
12
122 Views
Last Modified: 2015-02-01
On a Cisco ASA using ssh, I can logon with my AD account, but I cannot log on using a username I created locally on the ASA, why not?
0
Comment
Question by:tolinrome
  • 6
  • 6
12 Comments
 
LVL 20

Expert Comment

by:netcmh
ID: 40573634
Do you have the

aaa authentication ssh console <AD> LOCAL

set?
0
 
LVL 7

Author Comment

by:tolinrome
ID: 40573640
Yes, but I am not trying to logon with an AD account. I created a local user on the ASA and just simply want to ssh into the ASA using that local account.
0
 
LVL 20

Expert Comment

by:netcmh
ID: 40573650
I understand, the authentication would try AD first and then the local database.
0
Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

 
LVL 7

Author Comment

by:tolinrome
ID: 40573651
Then how do I get it to login?
0
 
LVL 20

Expert Comment

by:netcmh
ID: 40573688
Can you share your AAA & LOCAL config?

Also, is your ssh command configured to allow ssh from the particular host?

ssh <Inside host IP> <inside host netmask> inside
0
 
LVL 20

Expert Comment

by:netcmh
ID: 40573692
Sometimes, I've found that deleting that userid and then recreating it, helps.
0
 
LVL 20

Expert Comment

by:netcmh
ID: 40573701
I think that since the AD is always available, you would have difficulty having the Local database step up to authenticate. It's supposed to be used for the times when AD is inaccessible and you need to get into your device.
0
 
LVL 7

Author Comment

by:tolinrome
ID: 40573736
ssh is allowed from the host, I have deleted and recreated the username as well. Thanks.
0
 
LVL 7

Accepted Solution

by:
tolinrome earned 0 total points
ID: 40573798
I decided on an alternative non Cisco related since I couldnt get it working this way.
0
 
LVL 20

Expert Comment

by:netcmh
ID: 40573816
Could you share what you mean? I'd like to know how you did it.
0
 
LVL 7

Author Comment

by:tolinrome
ID: 40573853
Sure, I sent you a private message.
0
 
LVL 7

Author Closing Comment

by:tolinrome
ID: 40582247
I decided on an alternative non Cisco related since I couldnt get it working this way.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

#Citrix #Citrix Netscaler #HTTP Compression #Load Balance
When you try to share a printer , you may receive one of the following error messages. Error message when you use the Add Printer Wizard to share a printer: Windows could not share your printer. Operation could not be completed (Error 0x000006…
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

685 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question