I've got an ASA 5510 running 8.4(2) with ASDM 6.4(5)205 and an AIP SSM-10 running 7.0(6).
About 2 weeks ago we had an unscheduled reboot on the ASA and since then I have been unable to connect to the SSM using ASDM.
Direct SSH access to the SSM works fine so I am happy the username/password combination is ok and there are no ACL issues. I can also session across from the ASA with no problem.
I have tried "hw-module module 1 reload" which didn't work which i then followed with a scheduled reboot of the ASA overnight. No dice.
I'm hoping someone here might be able to point me in the right direction......
When you try to login to the IPS via ASDM the ASDM open a new connection to the IPS to be able to access it.
Can you check if the IP address of the ASA is still added to the permitted hosts on the IPS.
Else if you have an old config backup from the ASA you can compare it with the present config, can do the same for IPS as well
I've not got an old config to hand for it unfortunately.
The SSM is pingable and I can SSH in ok from the same workstation. I had a look at the config and I've got an "access-list" entry for the internal IP of the ASA (/32) as well as the workstation I'm trying to access it via ASDM from.
If I connect to the ASA then go to "Conffiguration" -> "IPS" I get "Error connecting to sensor. Error Loading Sensor".
I can connect directly to the SSM via SSH with the same credentials ok though.
If I try to connect directly to the SSM with ASDM I get "Unable to launch device manager from 10.x.x.x".
What lines should I be looking for on the ASA and SSM module with regard to being able to connect?
Can you try this
this will give you IDM access
IDM is a better tool to manage IPS so is IME
Related to the error on ASDM I would suggest you check the syslogs on the ASA, what do they say?
I have some issue like this before..
i resolve with shutdown the ASA then open the module then install it again..
and everything normal agai,..
i hope this help you..
Hi Ho Sy Tan,
Try Cisco IME (Cisco IPS Manager Express), this is powerfull management for cisco IPS.