Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

PIX-515E end problem with ssh conenction through VPN to inside interface

Hi

I have PIX-515E with:

Cisco PIX Security Appliance Software Version 8.0(2)

Device Manager Version 6.0(2)

I can't connect from host 192.168.2.6 using ssh through VPN to inside interface.

Here you are my running config:

ssh 192.168.2.0 255.255.255.0 inside

management-access inside

In the log I can find this:

Nov 24 2008 13:28:08: %PIX-6-302013: Built inbound TCP connection 527654 for outside:192.168.2.6/1499 (192.168.2.6/1499) to NP Identity Ifc:172.22.1.1/22 (172.22.1.1/22)

Nov 24 2008 13:28:08: %PIX-6-302014: Teardown TCP connection 527654 for outside:192.168.2.6/1499 to NP Identity Ifc:172.22.1.1/22 duration 0:00:00 bytes 0 Flow terminated by TCP Intercept

An ssh debug:

Device ssh opened successfully.

SSH1: SSH client: IP = '192.168.2.6' interface # = 6

SSH: host key initialised

SSH1: starting SSH control process

SSH1: Exchanging versions - SSH-1.99-Cisco-1.25

SSH1: send SSH message: outdata is NULL

server version string:SSH-1.99-Cisco-1.25

SSH1: Session disconnected by SSH server - error 0x3c "Time-out activated"

SSH1: receive SSH message: [no message ID: variable *data is NULL]

SSH1: receive unsuccessful - status 0x3c

The same situation is with ASDM.

Other communicaton works well (snmp from this server to PIX works fine).

Could you help me ?

Thanks in advance for help

Tomek

1 ACCEPTED SOLUTION

Accepted Solutions
Cisco Employee

Re: PIX-515E end problem with ssh conenction through VPN to insi

Hi,

If you have already checked your configuration and logs and do not see anything wrong with it, then you are most likely running into Bug ID CSCsi79159.

CSCsi79159

Yes

admin connections to PIX with crypto card via management-access fail

The above bug is fixed in 8.0(4)

http://www.cisco.com/en/US/docs/security/pix/pix80/release/notes/pixrn804.html

Regards,

Arul

*Pls rate if it helps*

7 REPLIES

Re: PIX-515E end problem with ssh conenction through VPN to insi

Is this issue coming with only one client?

Have you tried clearing the connections on the firewall?

Regards

Farrukh

New Member

Re: PIX-515E end problem with ssh conenction through VPN to insi

This issue is comming only from this network (192.168.2.0/24) - this is only one network I have to connect from through VPN.

(The same configuration on ASA 5505 in other location works fine.)

I have restarted PIX and nothing ...

regards

Tomek

Re: PIX-515E end problem with ssh conenction through VPN to insi

It could be related to TCP normalization (MSS etc.) or MTU issues as well. Have you checked the 'show asp drop' output? Because both ASDM/SSH are TCP based and SNMP is UDP based (which is working fine)>

Regards

Farrukh

New Member

Re: PIX-515E end problem with ssh conenction through VPN to insi

Hi

I have created capture (capture ssh type asp-drop all) and I didn't find anything about trafic between asa and source host :(

Any other suggestions ?

thx in advance

Tomek

Re: PIX-515E end problem with ssh conenction through VPN to insi

Have you tried re-generating your crypto keys??

And then perhaps the Microsoft solution (Reboot) :)

Regards

Farrukh

New Member

Re: PIX-515E end problem with ssh conenction through VPN to insi

Yes, but new keys did't help and restart neither :(

Any other idea ??

Thanks in advance

Tomek

Cisco Employee

Re: PIX-515E end problem with ssh conenction through VPN to insi

Hi,

If you have already checked your configuration and logs and do not see anything wrong with it, then you are most likely running into Bug ID CSCsi79159.

CSCsi79159

Yes

admin connections to PIX with crypto card via management-access fail

The above bug is fixed in 8.0(4)

http://www.cisco.com/en/US/docs/security/pix/pix80/release/notes/pixrn804.html

Regards,

Arul

*Pls rate if it helps*

308
Views
0
Helpful
7
Replies
CreatePlease to create content