Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
New Member

Unable to SSH from Outside to ASA 5520

I am unable to ssh to the cisco firewall from outside. Though when i telnet on port 22, i do get a reply Please see below.

Capture30.PNG

Below is my config

aaa authentication ssh console LOCAL

ssh 0.0.0.0 0.0.0.0 inside

ssh 0.0.0.0 0.0.0.0 outside

ssh timeout 5

console timeout 0

When i do a putty session i get a blank screen. Not sure why is it happening.

9 REPLIES

Unable to SSH from Outside to ASA 5520

Try adding the specific networks that are allowed to ssh to the inside and outside of your ASA.

Thanks,

Kimberly

Thanks and Cheers! Kimberly Please remember to rate helpful posts.
New Member

Unable to SSH from Outside to ASA 5520

Did you generate the RSA key?  I find myself forgetting that one stinking thing and get locked out since I only use SSH.

cry key gen rsa mod 2048

New Member

Unable to SSH from Outside to ASA 5520

I did generate RSA key but i used 1024.

Also ssh works from inside. Only outside is the problem.

I tried adding specific networks too but no luck.

New Member

Unable to SSH from Outside to ASA 5520

any ACL on outside interface?

Red

Unable to SSH from Outside to ASA 5520

Plz check if port 22 is used on the outside interface for any other service...

Chcek "show asp table socket".

Thanks,

Varun

Thanks, Varun Rao Security Team, Cisco TAC
New Member

Unable to SSH from Outside to ASA 5520

below is the output of 'show asp table socket'

Protocol  Socket    Local Address               Foreign Address         State

SSL       0000a73f  192.168.6.1:443             0.0.0.0:*               LISTEN

TCP       0ad7604f  192.168.7.1:22              0.0.0.0:*               LISTEN

TCP       0ad7a17f  204.138.112.2:22            0.0.0.0:*               LISTEN

TCP       0ad7d1ef  192.168.6.1:23              0.0.0.0:*               LISTEN

TCP       0ad85148  192.168.7.1:22              192.168.7.10:49964      ESTAB

New Member

Unable to SSH from Outside to ASA 5520

What version IOS is it running and how long has it been up?   There are a couple versions out that have an issue with SSH that I ran into that show this problem, a reboot normally clears it up.

Red

Unable to SSH from Outside to ASA 5520

Yes, a reboot might help or remove the outside interface ssh configuration, zeroise the crypto keys, the generate the rsa keys again and re-add the ssh outisde interface configuration.

Thanks,

Varun

Thanks, Varun Rao Security Team, Cisco TAC
New Member

Unable to SSH from Outside to ASA 5520

This is funny. We had a crypto map for some reason for that network thats why i wasnt able to do an ssh. but it works now. Thanks Guys.

910
Views
0
Helpful
9
Replies
CreatePlease to create content