SSH stops in double ISP configuration

ASA 7.2 (4)

I (unfortunately!) properly configured a site with double TIS, several site to site VPN (which do not failover), going forwards, etc... The only question that remains is SSH. Before adding a 2nd ISP, ssh on the inside and outside has worked well as expected. When the two interfaces of PSI are active and traffic moves on the primary, SSH is 'scales' on all 3 interfaces. Watch monitoring tool that goes up and down and is confirmed when I actually try to connect to it. Puzzled. Attached sanitized config, but for me, the party concerned is...

SSH 0.0.0.0 0.0.0.0 inside

SSH 67.xxx.xxx.0 255.255.255.0 outside

SSH 67.xxx.xxx.0 255.255.255.0 cable

SSH timeout 15

I could maybe understand if the interface not in use has expired due to lack of a return path, but all 3 interfaces are defective. As soon as one of the 2 wan interfaces is disconnected, ssh is well on the other 2.

Thank you

Ed

Yes, the way back could be a problem. I appreciate that you try to SSH on the internet and not on the VPN tunnel.

Can you check if it contains the same way when you try to access ASDM?

Can console yourself in the SAA and to collect and capture of ASA internet facing interfaces while you try to SSH.

Tags: Cisco Security

Similar Questions

  • How can I make Firefox stop me having to configure my search engines?

    From time to time - maybe every 15 searches, perhaps 20, perhaps it is not always the same number of searches - when I try to search via the search box, Firefox will open the Options-> search page instead.

    Repro:

    1. press Ctrl + K to activate the search box.

    2. Enter the search keywords.

    3. press ENTER.

    Expected result:

    Firefox opens the URL in the search engine, I configured to be my default.

    Actual result:

    Firefox opens the Options-> search page instead.

    If you do not see the result of 'Real' try these steps of reproduction, then return to the #1 step and repeat until you do. I don't know how trying this requires. 15-20 I suggested before is maybe too low. Maybe it's 50?

    How to make this stop? I want to just search - I don't want to have Firefox ask me to reconsider my search parameters.

    A possible cause is that you have the mouse pointer in a position that is in the drop-down menu that opens if you type a query.
    If the mouse pointer is in the wrong place, then you can call the element under the pointer of the mouse instead of the query.

  • 32 x 1 double switch configuration PXI-2527 and TB-2627

    Looking for configuration of the PXI-2527 at double 32 x 1 using a TB-2627 terminal block.  Under the OR rocking support for topology multiplexer NI PXI/SMU-2527 1 double wire 32 × 1 -.

    (link - http://zone.ni.com/reference/en-XX/help/375472C-01/switch/2527_dual_1-wire_32x1_mux/) it displays the names of software for different PIN numbers.  I don't care actually on this subject because I use the Terminal Board, but what worries me is that the diagrams represent Ch0-Ch31 connection com0 + and Ch32-Ch64 to com1 + and there is NO mention of com0 - or com1.  However, the NI TB-2627 installation instructions, table 4 shows the mapping Terminal double 32 x 1 1 - Wire topology.  In this map, IT lists a software name and the name of Terminal for com0 - and com1-.

    My question is, if com0 and com1 - are not listed in the manual switch why are the listed in the TB-2627 manul and what is it in this configuration?

    Thanks for your time.

    In the Setup instructions for the double configuration 32 x 1 TB-2627, she mentions Com0 - and Com1 - as a reference to inform the user what pin connects to since this same module can be used with other topologies. It is unnecessary for the topology of 32 x 1 information double since the switch card does not use these channels for this particular topology. Information is available for your reference, but does not neet to be connected to anything.

    Please let me know if any of this is unclear.

    Kyle K.

  • HDR-CX405 how to stop recording double, only the required mp4 files.

    Hello Sony,

    Yesterday I bought HDR-CX405. My question is, how to stop double registration? Only the required mp4 files.

    The two file created on the card then than shooing video scene - AVCHD and mp4.

    I don't want AVCHD (file too big), I want to just file mp4 only.

    Dual video REC

  • Cisco ASA: Redundancy of double ISP VPN...

    Hello, if it anyway to configure vpn site to site redundancy using a cisco asa. I know that I can configure the redundancy using two ISP on my cisco ASA, pointing to the same peer, but what if I need to point to different peers but to protect the same networks...

    I know it's possible in routers using tunnels gre + ipsec or VTI, but if there of still something similar using cisco ASA?

    Any help will be appreciated! Thank you!

    Hello

    Yes, Nagiswaren is right. For example, you have this:

    Based on the image above and your answers, you need to configure something like this:

    Subnet mask IP address name interface method
    Ethernet0/0 outsideVPN 10.198.16.143 255.255.255.224 manual
    Ethernet0/1 inside 172.31.255.1 255.255.255.0 Manual
    Ethernet0/2 outside-VPN2 10.198.29.21 255.255.255.224 manual

    Ethernet0/3 INTERNET 12.12.12.12 255.255.255.224 manual

    155 extended access-list allow ip 10.0.20.0 255.255.255.0 10.0.10.0 255.255.255.0
    IP 10.0.20.0 allow Access-list extended sheep 255.255.255.0 10.0.10.0 255.255.255.0

    NAT (inside) 0 access-list sheep

    Crypto ipsec transform-set esp-3des esp-md5-hmac 3DES-MD5

    correspondence address card crypto mymap 10 155
    map mymap 10 set peer 1.1.1.1 crypto 2.2.2.2
    mymap 10 transform-set 3DES-MD5 crypto card
    card crypto mymap interface outsideVPN
    crypto interface outside-VPN2 mymap map
    ISAKMP crypto enable outsideVPN
    ISAKMP crypto enable outside-VPN2

    crypto ISAKMP policy 10
    preshared authentication
    3des encryption
    md5 hash
    Group 2
    life 86400

    tunnel-group 1.1.1.1 type ipsec-l2l
    tunnel-group 1.1.1.1 ipsec-attributes
    pre-shared-key cisco123

    tunnel-group 2.2.2.2 type ipsec-l2l
    2.2.2.2 tunnel-group ipsec-attributes
    pre-shared-key cisco123

    =============================================================================================

    FOLLOW-UP OF THE OBJECT

    Track 100 rtr 10 accessibility
    ALS 10 monitor
    type echo protocol ipIcmpEcho 4.2.2.2 interface outsideVPN
    NUM-package of 3
    frequency 10
    Annex monitor SLA 10 life never start-time now

    course INTERNET 0.0.0.0 0.0.0.0 12.12.12.1 1

    Route outsideVPN 1.1.1.1 255.255.255.255 10.198.16.129 1 followed by 100

    Route outsideVPN 2.2.2.2 255.255.255.255 10.198.16.129 1 followed by 100

    Route outsideVPN 10.0.10.0 255.255.255.0 10.198.16.129 1 followed by 100
    Route outsideVPN 4.2.2.2 255.255.255.255 10.198.16.129 1

    Route outside-VPN2 1.1.1.1 255.255.255.255 10.198.29.1 254
    Route outside-VPN2 2.2.2.2 255.255.255.255 10.198.29.1 254

    Route outside-VPN2 10.0.10.0 255.255.255.0 10.198.29.1 254

    I used 4.2.2.2 but you can use the isps1 IP address.

    ==========================ROUTER===================================================================
    crypto ISAKMP policy 1
    BA 3des
    preshared authentication
    Group 2

    access-list 133 allow ip 10.0.10.0 0.0.0.255 10.0.20.0 0.0.0.255

    ISAKMP crypto key cisco123 address 10.198.16.143 No.-xauth

    ISAKMP crypto key cisco123 address 10.198.29.21 No.-xauth

    Crypto ipsec transform-set esp-SHA-ESP-3DES-3des esp-sha-hmac

    primary-card 10 map ipsec-isakmp crypto
    defined by peer 10.198.16.143

    defined by peer 10.198.29.21
    game of transformation-ESP-3DES-SHA
    match address 133

    secondary-card 10 map ipsec-isakmp crypto
    defined by peer 10.198.16.143

    defined by peer 10.198.29.21
    game of transformation-ESP-3DES-SHA
    match address 133

    interface FastEthernet0
    IP 1.1.1.1 255.255.255.0
    crypto primer-card card

    interface FastEthernet1
    IP address 2.2.2.2 255.255.255.0
    card crypto high school-map

    Interface Vlan1 * inside the interface *.
    IP 10.0.10.1 255.255.255.0

    1 IP sla monitor
    Protocol type echo 4.2.2.2 ipIcmpEcho
    timeout of 1000
    frequency 3
    threshold 2

    IP sla monitor Appendix 1 point of life to always start-time now
    accessibility of rtr 1 track 123

    IP route 4.2.2.2 255.255.255.255 1.1.1.254 permanent
    IP route 10.198.16.143 255.255.255.255 1.1.1.254 1 follow 123

    IP route 10.198.29.21 255.255.255.255 1.1.1.254 1 follow 123

    IP route 10.0.20.0 255.255.255.0 1.1.1.254 1 follow 123

    IP route 10.198.16.143 255.255.255.255 2.2.2.254 200

    IP route 10.198.29.21 255.255.255.255 2.2.2.254 200

    IP route 10.0.20.0 255.255.255.0 2.2.2.254 200

    -josemed

  • A Site with double ISPS to problems of branch

    The topology is fixed so I'll try to be brief.  Basically what is happening is when the IP SLA on the main switch of the branch fails it injects a route of default backup to the secondary ISP for the local network (5.5.5.0/24).  When this happens, 'interesting' traffic updates one site-to-site of this FW FW HQ even primary uses (3.3.3.2).  The problem is when the IP SLA covers, switches, the default route back to the ISP and the same traffic 'interesting' evokes this tunnel - there are now two tunnels at the same line VPN branch head unit.  Peer IP address are of course different for the end of the branch, but the peer at HQ is just an IP address and does not change the protected traffic which is defined for each.  When the primary comes back upward, it causes problems to be able to access the resources of the branch (and vice versa) until manually clear us the SA for the secondary VPN on the side HQ or simply, its expiry date.

    I would really like to than this to automate obviously, but I can't figure out how do it in style (SLA for the tunnels would be nice on the ASA).  It is worth noting that the two ASAs at the branch are not in any kind of configuration HA - they are firewalls separate, not dependent on each other, and they share not all state information. It is important that we keep redundancy it if for more than just losing the INET connection b/c of the ISP, we need hardware redundancy for firewalls. In the immediate future, I changed the delays on the track for the IP SLA on switch central branch so they are not as sensitive, but it is not optimal in the long term I think. I'm open to any suggestion, even a new conception of topology at the end of the branch if it is not expensive.

    Hi Chris,

    I hope you do well.

    Indeed, there is a problem when the two VPN tunnels to stay up.

    I suggest you check this link, especially the part about the VPN Backup tunnels and the response only feature.

    http://www.Cisco.com/en/us/products/HW/vpndevc/ps2030/products_configuration_example09186a00805a87f7.shtml#backup

    I hope it helps.

    Thank you.

  • Cannot SSH in ASA after EZVPN configuration and do not specify "split-tunnel-political tunnelspecified.

    Even after the "split-tunnel-policy tunnelspecified" specification with "split-tunnel-network-list value TUNNEL of SPLITTING" and denying all traffic to the public IP address of the ASA, I'm still not able to SSH in the firewall. Everything else seems to work OK, but I have to be able to handle the ASA from the public interface. In fact, I expect little given the mean one sa is the installer for the tunnel, and it would seem that a deny statement would be ignored, but perhaps there is a way around this. Thank you.

    If you want to connect to your home IP through the tunnel, you must specify 'inside access management:

    http://www.Cisco.com/en/us/docs/security/ASA/asa82/configuration/guide/a...

    Best regards, Karsten

    Sent by Cisco Support technique iPad App

  • Photosmart all-in-one 7280 stop spacing double

    I have an all in one photosmart 7280 printer I hooked just back again computer now I print all text spell double spaced how stop this

    Hi jiummy,

    What program you use to create text documents?

  • The mouse would no path, stops at 'double arrow' - 6 Captivate

    Having a strange problem on some 6 Captivate Slides.

    In design mode, the mouse has an indicator of 'double arrow '.  During playback, the mouse does not complete the path but stops where are the double arrows.

    I tried everything I can think of, including the cache and re-display of the mouse, move its location on the previous slide, move the point of departure, etc..

    Someone at - he seen elsewhere or have any ideas?  Thank you

    CaptivateMouseDoubleArrows.png

    Thanks for your reply, Rick.

    It turns out that I had put the mouse to display for the 'rest of slide' instead of 'point in time '.  I noticed the same problem in another project. When I put the mouse "specific time" the problem disappeared.

    Moral: Never set the mouse to display up to 'end of the slide.

    Corbin

  • setupccrt.exe has stopped working in Oracle Configuration Manager

    I installed Oracle 11 GR 2, that everything was fine, but at the end when he was cofiguring Oracle Configuration Manager. I got error folloing

    setupccr.exe has stopped working.

    I am unable to sort it out, but my database works very well and I started to work on 4 APEX with oracle. but I am still concerned about this error.

    If someone can tell me what I shuold do so that this problem can be solved.

    Thank you

    Concerning

    Mazahir Abbas

    Hello
    You want to use the configuration manager? If so, see according to document otherwise ignores the error.

    http://download.Oracle.com/docs/CD/E18041_01/index.htm

    Salman

  • 6500 a more don't stop printing double sided

    Good afternoon

    I have a HP Officejet 6500 has more and I can print the mac computer. All of sudden my printer ONLY print double-sided, but only one of my macs. I checked all the settings and even if it is not set to print double-sided, it continues to do so.

    I need help ASAP!

    Thank you

    MMD

    Welcome to the MMD31 forums,

    I understand that you are only able to print double-sided to your JO 6500 has more. I will do my best to help you with this.

    Please try:

    I hope that helps!

    Happy Monday

  • using word 2008, how can I stop print double-sided?

    Using osx 10.9.4 Mavericks on a mini mac MS Office 2008 for mac HP Envy 4500 printer. Whenever I print a document larger than one page, the printer automatically prints on both sides. The only way to stop this is to print a page at a time which is a pain in the rear. I click the colate box to disable this feature, but it makes no difference. I went into system preferences (this site seems to suggest I go to printers and faxes, but there is no such thing, it's printers and scanners), but there is no way to disable this option. If I print documents from a music notation software, there is a box to put the two sides feel, but not in word. I print guitar and drum tablature for students and two sided useless when the students, both hands are busy playing an instrument and cannot turn pages! Any help would be appreciated! BTW, wireless printing does not work also and I got an error message when you try to install the latest driver. I don't care actually on good wireless printing. I only mention this in case my problem is a driver problem.

    Hello
    Please follow the steps below to disable two-sided printing:

    The application used to print, click the file menu, click on print. The print window is displayed.
    NOTE: The print window might be minimized. Click Show details to see all the available parameters.

    Click on the area of selection below, listed as the name of the program (e.g. TextEdit)
    Will appear as Copies & Pages within Microsoft Office applications.

    Select layout from the drop-down.

    Set the duplex as Off.

    You can save the settings for later use by clicking preset > save current settings as preset. By default, a used preset will remain until another preset will be used.

    Kind regards
    Shlomi

  • How to stop emails double in my Inbox in? I get duplicates of all emails.

    I use OUTLOOK EXPRESS for my e-mail. For months I get duplicates of 90% of the e-mails received. I can't figure out how to stop the duplicates. Can anyone help?

    First of all, check tools | Accounts and make sure that the account is not listed twice.
     
    Second, make sure that your security program is not set to scan e-mail.
     
     
    If the above does not help, create a new file Pop3uidl.dbx.
     
    Tools | Accounts | Mail | Properties | Advanced. Uncheck: Leave a copy of messages on the server. Then, remove the Pop3uidl.dbx file. You will get the messages once more, but it should be.
     
    Tools | Options | Maintenance | Store folder will reveal the location of your Outlook Express files. Note the location and navigate on it in Explorer Windows or, copy and paste in start | Run.
     
    In Windows XP, the files of user OE (DBX and WAB) are by default marked as hidden. To view these files in Windows Explorer, you must enable Show hidden files and folders under start | Control Panel | Folder Options icon | Opinion, or in Windows Explorer. Tools | Folder options | View.
     
    With OE closed, find the Pop3uidl.dbx file and delete it.  Another will be created automatically when you open OE.
     

     
  • Stop loading double pictures a SanDisk to

    When I try to download pictures from my SanDisk, the program recognizes no photos previously uploaded and double post all images.  It just became a problem 3 weeks ago.

    Hello
     
    1. When you try to download the pictures?
    2 are. what program you referring?
    3. What is the format of picture file?
     
    Try to manually move the image files.
    1. plug the flash drive.
    2. open computer in the start menu.
    3. double-click on the icon of the flash player to open it and copy the image files.
    4. Paste the files copied to the target location.
     
    After return the details, so that we can help you better.
     
    Kind regards
    Syed
    Answers from Microsoft supports the engineer.
  • NAT timeout for failover w / double ISPS

    I have failover configured, tested and verified using IP SLA, based on routing rules and failover NAT mentioned in this guide:

    http://docwiki.Cisco.com/wiki/NAT_failover_with_DUAL_ISP_on_a_router_Configuration_Example

    The problem is that it takes about 60 seconds for the active nat translation timeout.  Is there a recommended way to shorten this time other than changing the NAT time-out value in the world?

    Platform: 2921

    IOS: 15.2 (4) M4

    Topology:

    ------------- ISP1 -------------

    |                                |

    | int Gi0/1 |

    LAN - router WAN Internet

    | int Gi0/2 |

    |                                |

    ------------- ISP2 -------------

    Config:

    ALS IP 1

    1.1.1.1 - echo ICMP-source 1.1.1.2 ip address

    threshold 250

    Timeout 900

    frequency 3

    IP SLA annex 1 point of life to always start-time now

    !

    ALS IP 2

    2.2.2.1 - echo ICMP-source 2.2.2.2 ip address

    threshold 250

    Timeout 900

    frequency 3

    IP SLA annex 2 to always start-time life now

    !

    track 1 accessibility of als 1 ip

    !

    Track 2 accessibility of ALS 2 ip

    !

    IP access-list extended by default-traffic-ACB

    deny ip 192.168.0.0 0.0.255.255 192.168.0.0 0.0.255.255

    IP 192.168.0.0 allow 0.0.255.255 everything

    !

    Media-Lab-ACB extended IP access list

    deny ip 192.168.19.0 0.0.0.255 192.168.0.0 0.0.255.255

    IP 192.168.19.0 allow 0.0.0.255 any

    !

    by default-traffic-PBR permit 10 route map

    the IP by default-traffic-ACB-matches

    set ip 2.2.2.1 jump following 10 track 2

    set ip 1.1.1.1 jump following 20 track 1

    !

    Media-Lab-ACB route map permit 10

    the IP Media-Lab-ACB-matches

    set ip 1.1.1.1 jump following 10 Track1

    set ip 2.2.2.1 next 20 track 2 break

    !

    strategy local IP map route by default-traffic-ACB

    !

    interface GigabitEthernet0/0,16

    property policy intellectual map of route by default-traffic-ACB

    !

    interface GigabitEthernet0/0.19

    intellectual property policy map route Media-Lab-ACB

    !

    ! NAT CONFIGURATION

    !

    NAT_ACL extended IP access list

    deny ip 192.168.0.0 0.0.255.255 192.168.0.0 0.0.255.255

    IP 192.168.0.0 allow 0.0.255.255 everything

    !

    ISP1_NAT allowed 10 route map

    corresponds to the IP NAT_ACL

    is the interface GigabitEthernet0/1

    !

    ISP2_NAT allowed 10 route map

    corresponds to the IP NAT_ACL

    is the interface GigabitEthernet0/2

    !

    IP nat inside source map route ISP1_NAT interface GigabitEthernet0/1 overload

    !

    IP nat inside source map route ISP2_NAT interface GigabitEthernet0/2 overload

    !

    end

    Hello

    You can use the EEM script to help in your case.

    !

    NAT-TRACK event manager applet

    model event syslog 'FOLLOW-UP-5-STATE '.

    order cli action 0.1 'enable '.

    action 0.2 wait 3

    action 0.3 cli command "clear ip nat translations."

    action 0.4 syslog msg "Translation NAT cleared after state change of track"

    !

    I hope that helps...!

Maybe you are looking for

  • BSOD with Qosmio F60-033

    I updated my drivers in accordance with this url: http://www.mytoshiba.com.au/support/notebooks/qosmio/f60/pqf65a-033002/download?os=25 I ran windows update and it reports no new drivers. Yet these two got BSOD I did a debug of depressed windows done

  • Satellite Pro P100: Where to find recovery CD/DVDs

    We have a 2 year old child "Satellite PRO P100 (model No. PSPA4E-00N00KED) and it does not work very well and now I want to use the recovery CD, but miss me it. Is it possible for anyone to help them with this issue with a link to an approved place o

  • Firewalls in El Capitan

    Does anyone know how the Firewall works in El Capitan? I modified the apple script to add redirection rules and blocking and allowing services on a server that is also a gateway.  It is a script imported from a Maverick server that has a job for a co

  • Conversion of integer string String table

    I have two text files, numbers (signal1.txt and signal2.txt). I want to convert it to an array of integers and have a process on them. When I got diverted by control Fract/Exp to string number, it just shows 0 (you can see in the attached file). How

  • How to load its drive

    my audio player is not installed