Cisco Firewall :: SSH Stops Working To ASA 5510?

Feb 5, 2013

I find are steps to turn on SSH access.  I have quite a few customers with ASA5510's installed.  SSH is set up and working fine on every one.  After a period of time, you are no longer able to SSH into the firewall.  Using Putty, it just sits there on a blank screen without giving a "denied access" message or a login prompt.  Rebooting the firewall will solve the issue and SSH access works again.  Today, I had a customer with and active/standby configuration where I had to reboot both of them to be able to log in.  Most of my customers are on 8.2.software as most don't want to reconfigure for the new NAT, etc. 
 
I'm sure others have seen this before since it appears to be occuring on almost every ASA that I have access to.  Is there any fix to eliminate this or is there something that can be run from the ASDM that will grant SSH access again without just doing a reboot?

View 4 Replies


ADVERTISEMENT

Cisco Firewall :: 5510 Exchange Active Sync Stops Working

May 8, 2012

I know that I've run into this before but I can't remember the fix.  I have a 5510.  The 3 interfaces involved are INSIDE, OUTSIDE, and GUEST. Corporate users are allowed to put their iPhones on the Guest network, but the problem is that their Exchange ActiveSync stops working.  It is tied to the external DNS name of the OWA server (we'll say webmail.abc.com).  So the users are funneled out one public IP on the OUTSIDE interface and are trying to communicate with the outside of the OWA server, which is NATed to another public IP on the same outside interface.  What do I need to do on the ASA to allow users on the guest network (behind the GUEST interface) to access the mail server using its public IP (behind the INSIDE interface)

View 1 Replies View Related

Cisco :: Asa 5510 Site Stops Working

Jul 19, 2012

I recently setup a site to site vpn between a asa 5510 and router 1921. It was working great all night and this morning. When traffic stopped rolling through for a few hours the tunnel shutdown. I checked the router using cisco configuration and tells me the tunnel is up. When I check the asa it does not show up in the active tunnels. Any know what would cuase it to drop? and if so what can I do to avoid it.

View 6 Replies View Related

Cisco VPN :: ASA 5510 Ipsec Stops Working

Jun 8, 2011

i've an Cisco ASA 5510 with Security Appliance Software Version 8.0(2), in this ASA i've many L2L tunnels to this ASA, anda sometims new tunnels can't connect, the older tunnels still ok and working, yesterday this situation occured again and i've tried to clear all ipsec tunnels and try to reconnect again no one cames up again. At the time of this situation memory usage was about 78% and CPU is was around 5%. I've made a reload without changes and the situation returns to the normality.
 
At the time of the fail i've collect the outpu from debug crypto isakmp 255, the outpu was in the annexed file.

View 1 Replies View Related

Cisco Firewall :: ASA 5510 - SIP Stops When Upgrading

Dec 9, 2011

I have to be missing something small in my config. If I upgrade my ASA 5510 which I am routing and Na Ting off of, from 8.4.1 to 8.4.2.8, SIP stops. All phones go dead.
 
If I roll back to 8.4.1, SIP comes up.,... Go back to 8.4(2)8 and SIP goes down..... 
 
This is without making any config changes. I have looked at it so long, I must be overlooking something simple.

View 9 Replies View Related

Cisco Firewall :: Frequently ASA 5510 Stops

Sep 1, 2010

I am having a cisco ASA and its frequently stops working . Check the logs given below.
 
Let me know this happens because of the commands given below.
 
threat-detection basic-threatthreat-detection statistics access-list
 
[code]....

View 7 Replies View Related

Cisco Firewall :: NAT Stops Working With VLAN On PIX 515e

Jan 3, 2012

I have a PIX 515e (8.0 (2)) and 1841 router (12.4(25)).I had the following setup working without issue:
 
[Internet] <-----> PIX  <-----> 1841  <-----> [LAN]
 
I then tried to introduce VLANs and now I can not reach the Internet from the LAN.  It seems that no nat translations are taking place.
 
-I can successfully ping the LAN from the PIX.
-I can successfully ping the Internet from the PIX.
-I can successfully ping the PIX inside_lan interface from the router
-I can not ping the outside interface from the router
-I can not ping the Internet from the router
 
I introduced the LAN side VLAN first and everything still worked.  However, once i introduced the VLAN between the router and PIX, things have broken down. [code]

View 2 Replies View Related

Cisco Firewall :: ASA 5510 Stops Forwarding Incoming Traffic To Internal Servers?

Dec 5, 2012

Since the power failure two days ago, my -ASA stops forwarding traffic to internal servers, for no apparent reason. Packet trace shows all OK, packet capture buffer stays empty when I try to http into the mail server. The only way to get it working is to change the Outside Ip to the one used for mail, then to change it back. It will work OK for a few hours, then stop, with nothing obvious in the logs.

View 2 Replies View Related

Cisco Routers :: RV042 Port Forwarding Stops Working When Firewall Is Enabled

Jun 4, 2013

I have a RV042 router on a single WAN and an internal LAN. I have configured port forwarding as follows: HTTP[TCP/80~80]->10.0.0.6HTTPS[TCP/443~443]->10.0.0.6IMAP[TCP/143~143]->10.0.0.5IMAP SSL[TCP/993~993]->10.0.0.5SMTP SSL[TCP/587~587]->10.0.0.5
 
Everything works just fine when I have the firewall DISABLED. However, when I enable it the behaviour is erratic. 1 out of 10 attempts to connect to ANY port forwarded works. Almost all attempts time out. Notice that this happens even if using only the default firewall rules (which should be bypassed by the port forwarding as I read in other posts).
 
My second try was to create firewall rules manually, overriding the default ones. I tried adding rules from source WAN1 (where my connection is) to ANY and to SINGLE IP's on every port. Nothing seems to work.
 
I don't know what I'm doing wrong, this is really bugging me. I had to turn the firewall off so we can access our servers from outside the office. This shouldn't have to be done.
 
Just found out that my firewall is getting LOTS and LOTS of Blocked - SYN Flood entries. I think this is why we are having trouble with the firewall. Could this be the problem? I have no idea where all these SYN packets are coming from since they appear with spoofed IPs or come from different bots all over.

View 1 Replies View Related

Cisco Firewall :: 5510 Vpn Client Groups Configured / DHCP Server Stops Giving Network Service

Feb 20, 2013

I have a asa 5510 vpn client groups configured and connected to the internal network DHCP server stops giving network service dhcp and the network goes down.

View 6 Replies View Related

Cisco Firewall :: ASA 5510 - SSH Is Not Working

Jul 1, 2011

I configured ASA 5510 with IOS 8.4.2 version. I configured SSH to outside and backup interface with any any permission.
 
ssh 0.0.0.0 0.0.0.0 outside
ssh 0.0.0.0 0.0.0.0 backup
 
configured password with command
 
passwd < Password>
  
While connecting from outside through Putty i am not able to authenticate the password.
 
Aftter entering user name as pix its asking password. After entering its not authenticating.
 
I taken output by telnetting to inside after connecting to the firewall from outside and entering username as pix
 
PM-ASA-5510# sh ssh sessions
SID Client IP       Version Mode Encryption Hmac     State            Username1   122.169.252.112 2.0     IN   aes256-cbc sha1     KeysExchanged    pix                            OUT  aes256-cbc sha1     KeysExchanged    pixSPM-ASA-5510#

View 5 Replies View Related

Cisco Firewall :: Twice NAT Not Working With 5510

Aug 22, 2012

Our NOC is trying to configure a site to site tunnel to one of our customers. The tunnel is up and operational, however we can't get our NAT rules to match what we want.
 
We are running ASA version 8.4(3)
 
The traffic is sourced from 172.16.1.50 (inside1) and destined to192.168.2.9 (outside), the nat configuration is posted below:
 
NOC-ASA5510-01# show run nat
nat (inside1,inside2) source static ng-noc-networks ng-noc-networks destination static ng-inside2-networks ng-inside2-networks
nat (inside1,outside) source static test test-EXT destination static otherside otherside
object network obj_any
nat (inside1,outside) dynamic interface dns
object network servers-noc
nat (inside1,outside) static 192.168.1.68
 
Here is the output from the show nat detailed:
 
NOC-ASA5510-01# show nat detail
Manual NAT Policies (Section 1)
I left off entry 1 but it doesnt have any translated hits either

2 (inside1) to (outside) source static test test-EXT   destination static otherside otherside
    translate_hits = 0, untranslate_hits = 624
    Source - Origin: 172.16.1.50/32, Translated: 192.168.1.67/32
    Destination - Origin:192.168.2.9/32, Translated:192.168.2.9/32
 
Auto NAT Policies (Section 2)
1 (inside1) to (outside) source static servers-noc 192.168.1.68 
    translate_hits = 0, untranslate_hits = 187
    Source - Origin: 172.16.1.101/32, Translated: 192.168.1.68/32
2 (inside1) to (outside) source dynamic obj_any interface   dns
    translate_hits = 58417, untranslate_hits = 1511
    Source - Origin: 0.0.0.0/0, Translated: 192.168.1.66/29
 
Here are the network objects:
 
object network test
host 172.16.1.50
object network test-EXT
host 192.168.1.67
[Code]...

View 2 Replies View Related

Cisco Firewall :: ASA 5510 NAT Doesn't Appear To Be Working

Mar 8, 2012

I've got an ASA 5510 running 8.4.I have a host on an inside interface, with a static NAT configured on the ASA. The inbound/return half of the NAT doesn't appear to be working. [code] I run a ping from the host (192.168.100.98) to something on the outside (1.2.3.4)Running captures, I can see the outbound ping leaving, having been NATed OK. I can see the reply coming back in to the outside interface with the correct IP address, but I never get the final NATed packet appear on the inside interface. The packet just disappears inside the ASA.

View 2 Replies View Related

Cisco Firewall :: ASA 5510 8.4 - Internet Is Not Working?

Nov 14, 2011

I implemented a ASA5510 with latest software version. I configured outside interface, default route, PAT to the outside interface. I am able to ping and telnet to the inside interface of the ASA.But internet is not working.Did i miss any configuration?i enabled icmp to outside,. i did a ping to the next hop from ASA. but it is not working.

View 6 Replies View Related

Cisco Firewall :: ASA 5510 EIGRP Not Working

Sep 24, 2012

We have 2 ASA5510 and 2 ASA5525. Got a very weird error; up to release 8.4 eigrp works fine, after upgrading to 8.6 eigrp stops working.Can't see any neighbors; but same command from another asa on same network but with release 8.4: [code] I want to put the 5525 on production but would like to do it with latest release; could this be a bug on 8.6?

View 12 Replies View Related

Cisco Firewall :: ASA 5510 - HA No More Working After Upgrade To 8.4.1(11)

Jun 2, 2011

we recently upgraded our ASA 5510 active/standby cluster from ASA Version 8.3.2 to 8.4.1(11). Unfortunately the standby ASA is now crashing a few seconds after the configuration was synchronized from the active ASA.
 
Also completely disabling HA, bringing the default config to standby ASA again and activating HA afterwards did not work. Also tried through the Wizard provided by ASDM to be sure to have no errors with requirements.
 
How to solve this without doing a downgrade back to 8.3.2. ?

View 4 Replies View Related

Cisco Firewall :: ASA 5510 - Vpn Tunnel Not Working From One End

May 9, 2013

I have an ASA 5510 and I am building a site-to-site vpn tunnel, peer on the other end is a sonicwall. I can initiate the tunnel from my end, but when he tries from his end it fails on phase 2 with this error in the logs:
 
"Rejecting IPSec tunnel: no matching crypto map entry for remote proxy"
 
Obviously our crypto map's don't match, i have it restricted to specific ports on my end and he had it wide open on his end, but said he is not sure how to restrict it down to specific ports. My question is why would I be able to bring the tunnel up on my end if the crypto map's don't match and he can't bring it up?

View 5 Replies View Related

Cisco Firewall :: VPN Tunnel Not Working From One End ASA 5510

Dec 5, 2012

I have an ASA 5510 and I am building a site-to-site vpn tunnel, peer on the other end is a sonicwall. I can initiate the tunnel from my end, but when he tries from his end it fails on phase 2 with this error in the logs:
 
"Rejecting IPSec tunnel: no matching crypto map entry for remote proxy"
 
Obviously our crypto map's don't match, i have it restricted to specific ports on my end and he had it wide open on his end, but said he is not sure how to restrict it down to specific ports. My question is why would I be able to bring the tunnel up on my end if the crypto map's don't match and he can't bring it up?

View 1 Replies View Related

Cisco Firewall :: ASA-5510 - SIP ACL Traffic Not Working

Jun 11, 2013

I have an ASA with an outside ACL that is configured to allow 208.84.248.95 SIP/5060 to 1x.x.x.46.  I show no hits.  I added an ACL to do a packet capture, it sees the packet coming into the ASA but not going to the Serv Prov interface.  I see hits on the vuong ACL but not the production acl_out ACL..  What is up?
 
NOTE:ACL_out is the ACL we use to allow outside traffic to enter our network. 
FW1(config)# sh access-list | i 1.x.x.46
access-list acl_out line 1 extended permit ip host 63.x.x.140 host 1x.x.x.46 (hitcnt=0) 0xc09a9387  (*NO HITS)
access-list acl_out line 658 extended permit udp host 208.84.248.95 host 1x.x.x.46 eq sip (hitcnt=0) 0x0f327179  (NO HITS)
[code]...

It was tested and verified from the inside network to make sure the server is listening on that port. Below we created an ACL to allow all IP from another test PC to the Server IP 1x.x.x.46.  We did a telnet to port 5060 and it showed hits but not on the acl_out ACL.
 
ccess-list vuong line 1 extended permit ip host 63.x.x.140 host 1x.x.x.46 (hitcnt=0) 0x2759fa92
FW1(config)# q
FW1# capture capture1 access-list vuong interface outside
[code]...
 
Below we applied the same ACL to the ServProv interface to see if traffic was going where it was supposed to .  By trying to telnet to the 1x.x.x46 IP from 63.x.x.140 IP.  Looking below, no traffic appeared on the capture2.
 
FW1# capture capture2 access-list vuong interface ServProv
FW1# sh capture capture2
0 packet captured
0 packet shown
[code]...
 
Capture 1 above shows the last 3 incoming messages initiated from 63.x.x.140 to the 1x.x.x.46! Vuong ACL belows shows 3 more hits.....nothing on the acl_out ACL???
 
FW1# sh access-list vuong
access-list vuong; 1 elements; name hash: 0x29df3e90
access-list vuong line 1 extended permit ip host 63.x.x.140 host 1x.x.x.46 (hitcnt=6) 0x2759fa92
[code]...

View 1 Replies View Related

Cisco Firewall :: ASA 5510 - Static NAT For Outside Access Not Working?

Sep 19, 2011

I've got an ASA 5510 that has been working like a charm for some time now. Until now we've not had to nat any resources to the outside. I created network objects for an internal host and an external host. The internal host has to respond to requests on tcp/2001.
 
The internal host has no problem accessing the internet, but when I attempt to access the internal host from the outside, I get the following:
 
4    Sep 20 2011    16:20:33        fw_outside_ip    62678    outside_host    2001    Deny tcp src outside:outside_host_ip/62678 dst inside_host:inside_host_ip/2001 by access-group "outside_access_in" [0x0, 0x0]
 
When I try to use the packet tracer to simulate the outside traffic, I get the following
 
5    Sep 20 2011    16:17:41        inside_host    2001            Asymmetric NAT rules matched for forward and reverse flows; Connection for tcp src outside:outside_host/1065 dst inside_int:inside_host/2001 denied due to NAT reverse path failure
 
I've got over my NAT statement and access rule and can't find anything wrong with either.
 
Here are the pertinent NAT and access rule...
 
static (inside_int,outside) tcp interface 2001 inside_host 2001 netmask 255.255.255.255
 
access-list outside_access_in extended permit tcp host outside_host host inside_host eq 2001

View 5 Replies View Related

Cisco Firewall :: ASA 5510 With Inside Interface And DMZ Not Working

Feb 5, 2012

i have here a ASA 5510 sec k9.
 
I build a Config with a DMZ,INSIDE and OUTSIDE Interface. My Plan is to use the IP-Address of the OUTSIDE Interface with PORT to setup a HTTP Server In the DMZ
 
But my Config doesn't work. And I have no Plan why .....
 
The Inside Interface have to work normal. The Traffic to the Internet is TRiggert from Inside with Dynamic PAT
 
ciscoasa(config)# exit 
ciscoasa# show run
: Saved
:
ASA Version 8.4(1)

[Code].....

View 2 Replies View Related

Cisco Firewall :: ASA 5510 - LAN Based Failover Not Working

Jun 23, 2011

I have ASA 5510 connected as shown in attached diagram.Ideally when ASA 1 is active and if I boot Switch-1, ASA-2 shood take over. But that is not happening.When I boot SW1 , ASA-2 shows "Failover LAN Interface: failover Ethernet0/0 (Failed - No Switchover)" and remains standby.Fail over works properly If ASA-1 boots.

View 7 Replies View Related

Cisco Firewall :: ASA 5510 Object-Groups Not Working

May 9, 2012

I have an ASA 5510 and have just started using object-groups which are super handy in theory, but not working in reality. I have a service object-group with a mix of tcp, icmp, and udp ports. Let's call it Sample_Port_Group. I'm trying to apply it to my dmz_access_in ACL. Here's the line giving me problems:
 
access-list dmz_access_in extended permit object-group Sample_Port_Group 192.168.1.1 any
 
The asa throws up an error between 192.168.1.1 and any. When I put up a ? after Sample_Port_Group, it gives me the option of putting in an IP address, any, etc. When I put in a ? after 192.168.1.1, it only gives me the option of putting in an IP address.URL

Those posts gave me the impression my line was possible, especially the "access-list outsideacl extended permit object-group myaclog interface inside any" line, which is at the end of the 2nd article linked.

View 2 Replies View Related

Cisco Firewall :: Inter Interface Communications Not Working On Asa 5510 V 8.2.2

Aug 20, 2012

I have an ASA 5510 attached to 2 internal networks.  Everything is working except communications between the 2 internal interfaces.I can ping the FW from either interface and I can ping hosts on both networks from the CLI but can't get any traffic to pass.I'd like to open the connection to all traffic. [code]

View 33 Replies View Related

Cisco Firewall :: ASA 5510 / Management Interface Stopped Working After Upgrade?

Jun 24, 2012

After I have upgraded our ASA 5510 to 8.4.2 I have problem with the management interface.Our former firmware 8.2.3 had no problem using the management interface as a DMZ zone, but after we upgraded to 8.4.2 we can't make it work.The interface and the protocol is up, when I type: show interface.But when I ping the interface from a computer connectet to the interface, nothing happens.
Even the logging shows nothing.

View 7 Replies View Related

Cisco WAN :: 876 - Nat Stops Working After 30 To 60 Sec?

Apr 24, 2013

i have a 876 Router, connected to the Internet and a VPN. From inside i would like to pass all traffic destinied to 192.168.0.0 255.255.255.0 to the VirtualPPP IF and al the other to the Internet (vlan2) I have created this rule, but after applying ist works only for about 30 to 60 seconds. after that only the Internet reachable. Everytime i do a clear ip nat trans * both Interfaces will work für 30 to 60 secs again...
 
This is the relevant part of the cfg
  
ip nat inside source route-map Di1 interface Virtual-PPP1 overload
ip nat inside source route-map VLAN1 interface Vlan2 overload
!
access-list 1 remark CCP_ACL Category=2

[Code].....

View 5 Replies View Related

Cisco WAN :: ASA 5510 - Outside Interface Stops Sending And Receiving Traffic

Aug 8, 2012

Cisco ASA 5510.  Between 5 to 10 minutes of reseting the asa traffic stop accessing outside ip addresses.  Ping from console fails to ISP router IP. Ping to google name server failes.  I have reset to factory default only setting up nic and natting and it still happens. 

View 2 Replies View Related

Cisco :: Asa5010 Interface Stops Working?

Mar 5, 2012

I have a cisco asa 5010 where, during the process of configuring, the outside ports become down/down. The /0 port won't even reactivate after cycling power on the unit.Port /1 is the inside interface and it is not affected by the problems.I switched the outside port to port /3 and it worked for awhile then it stopped working. I switched it to Port /2 and the same thing.Port /2 and Port /3 are on after a power recycle but shut down completely (down/down) during the reconfiguration. It seems like a hardware failure, but I'm wondering if it could be anything else.

View 4 Replies View Related

Cisco WAN :: 891 NAT Stops Working And Translations Don't Appear In Show IP

May 17, 2011

I have a problem with configuring brach router 891 (with IOS v15.0(1)M).I want to connect to HQ via EasyVPN connection (split-tunnel) and allow the local traffic to go directly to the Internet via NAT (PAT).When the VPN connection goes up, NAT stops working and NAT translations don't appear in show ip nat translations. When the VPN connection goes down, NAT begins to work again.

View 1 Replies View Related

Wireless For Laptop Sometimes Stops Working?

Mar 8, 2013

I have a Asus n55s. The wireless acts very funky. It sometimes disconnects and stops working. Sometimes, it will stop detecting any nearby wireless networks altogether. Then I have to enable and disable the wireless functionality until it starts seeing nearby wireless networks.

View 9 Replies View Related

Laptop's Wifi Stops Working

Feb 5, 2013

I've been having this problem with my laptop's wifi for a while now and it's been getting a little out of hand lately that I can't deal with it anymore. I asked some friends and they seem to have the same problem too but not nearly as often as I do. Every so often, my laptop's wifi just stops working so I turn it off and then turn it back on and it starts working again. My friend says it happens very rarely to him but for me just today it happened 2 times within 10 minutes

View 7 Replies View Related

After Few Hours The Tcp / Ip Protocol Stops Working

Oct 14, 2011

I'm having is that every few hours my TCP/IP protocol stops working. The modem lights remain normal but I can't connect to anything. The only thing that works on the internet is traceroutes at the command prompt which function normally. The solution is that I have to reboot and then everything returns to normal until a few hours later when it happens again. There are no error messages on any of my browsers. The page just goes white immediately. When I try to retrieve my email, I get a message about the TCP/IP isn't working.

View 9 Replies View Related

Wireless Stops Working After 30 Mins?

May 2, 2012

I've got the same problem on my wife's Acer One 532h. Did it get resolved for you, Adrian and if so, how?

View 5 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved