Sunday, September 6, 2020

Why can't I connect to my ASA out of the box?

Cipher issues, etc.

I've tried all sorts of additional ciphers, etc., and I still can't connect via SSH or ASDM.

ciscoasa#

ciscoasa# sho ssl

Accept connections using SSLv3 or greater and negotiate to TLSv1.1 or greater

Start connections using TLSv1.1 and negotiate to TLSv1.1 or greater

SSL DH Group: group14 (2048-bit modulus, 224-bit prime order subgroup, FIPS)

SSL ECDH Group: group21 (521-bit EC)

SSL trust-points:

Self-signed (RSA 2048 bits RSA-SHA256) certificate available

Self-signed (EC 256 bits ecdsa-with-SHA256) certificate available

Certificate authentication is not enabled

ciscoasa# sho ssh

Idle Timeout: 30 minutes

Version allowed: 2

Cipher encryption algorithms enabled: 3des-cbc aes128-cbc aes192-cbc aes256-cbc aes128-ctr aes192-ctr aes256-ctr

Cipher integrity algorithms enabled: hmac-sha1 hmac-md5 hmac-sha1-96 hmac-md5-96

Hosts allowed to ssh into the system:

0.0.0.0 0.0.0.0 inside

ciscoasa# sho run http

http server enable

http 0.0.0.0 0.0.0.0 inside

ciscoasa#



No comments:

Post a Comment