Re: [rancid] New Cisco ASA Login Failure

2018-03-06 Thread Linwood Ferguson
>> I just got hit by this also on a 5506-x. I turned off the login history for >> now, but I saw back in January a proposed patch, did that work out? (I >> guess I could try it, but it's always nice to know if it worked, and if it >> might be destined for incorporation?) > >I've already repli

Re: [rancid] New Cisco ASA Login Failure

2018-03-06 Thread o...@leferguson.com
(Sorry, I replied to this initially with a different account, if that's sitting in a moderation queue it can be deleted) >> I just got hit by this also on a 5506-x. I turned off the login history for >> now, but I saw back in January a proposed patch, did that work out? (I >> guess I could

Re: [rancid] New Cisco ASA Login Failure

2018-03-06 Thread heasley
Tue, Mar 06, 2018 at 02:36:37PM +, o...@leferguson.com: > I just got hit by this also on a 5506-x. I turned off the login history for > now, but I saw back in January a proposed patch, did that work out? (I > guess I could try it, but it's always nice to know if it worked, and if it > mig

Re: [rancid] New Cisco ASA Login Failure

2018-03-06 Thread o...@leferguson.com
scuss [mailto:rancid-discuss-boun...@shrubbery.net] On Behalf Of Piegorsch, Weylin William Sent: Tuesday, March 6, 2018 7:59 AM To: james machado Cc: rancid-discuss@shrubbery.net Subject: Re: [rancid] New Cisco ASA Login Failure Aw snap! I even replied to that thread :-( http://www.shrubber

Re: [rancid] New Cisco ASA Login Failure

2018-03-06 Thread Piegorsch, Weylin William
in Piegorsch mailto:wey...@bu.edu>> Cc: "rancid-discuss@shrubbery.net<mailto:rancid-discuss@shrubbery.net>" mailto:rancid-discuss@shrubbery.net>> Subject: Re: [rancid] New Cisco ASA Login Failure This is due to changes in the supported encryption methods in the updated IOS

Re: [rancid] New Cisco ASA Login Failure

2018-03-05 Thread james machado
mes machado > *Date: *Monday, March 5, 2018 at 12:18 PM > *To: *Weylin Piegorsch > *Cc: *"rancid-discuss@shrubbery.net" > *Subject: *Re: [rancid] New Cisco ASA Login Failure > > > > This is due to changes in the supported encryption methods in the updated > IOS&#

Re: [rancid] New Cisco ASA Login Failure

2018-03-05 Thread doug . hughes
I use add cyphertype aes256-cbc for all of our ASA-5*-X models, and it works. Sent from my android device. -Original Message- From: james machado To: "Piegorsch, Weylin William" Cc: "rancid-discuss@shrubbery.net" Sent: Mon, 05 Mar 2018 18:31 Subject: Re: [r

Re: [rancid] New Cisco ASA Login Failure

2018-03-05 Thread james machado
This is due to changes in the supported encryption methods in the updated IOS's and ASA softwares. in your .cloginrc you will want to add a line: add cyphertype {encryption method} you can find an encryption method your systems are happy with by doing the following: ssh -vv [...] debug2: mac_

Re: [rancid] New Cisco ASA Login Failure

2018-03-05 Thread Piegorsch, Weylin William
: Monday, March 5, 2018 at 3:21 PM To: Weylin Piegorsch , james machado Cc: "rancid-discuss@shrubbery.net" Subject: Re: [rancid] New Cisco ASA Login Failure William, Your easiest solution might be to turn on auto-enable on your new ASA with this: aaa authorization exec authentication-s

Re: [rancid] New Cisco ASA Login Failure

2018-03-05 Thread Bob Brunette
your .cloginrc file lines for this device? The problem may be there. Bob Brunette From: Rancid-discuss on behalf of "Piegorsch, Weylin William" Date: Monday, March 5, 2018 at 2:09 PM To: james machado Cc: "rancid-discuss@shrubbery.net" Subject: Re: [rancid] New Cisco ASA L

Re: [rancid] New Cisco ASA Login Failure

2018-03-05 Thread Piegorsch, Weylin William
Got it; thanks Heasley. I'll poke around on it. weylin On 3/5/18, 12:41 PM, "heasley" wrote: Mon, Mar 05, 2018 at 02:48:56PM +, Piegorsch, Weylin William: > Hello, > > I have a Cisco ASA 5506X device I just deployed (running 9.8(2)20 version), that rancid’s not logging in

Re: [rancid] New Cisco ASA Login Failure

2018-03-05 Thread Piegorsch, Weylin William
cyphertype * {aes128-ctr,aes192-ctr,aes256-ctr,aes128-cbc,3des-cbc,aes192-cbc,aes256-cbc} [rancid@rancid-server ~] From: james machado Date: Monday, March 5, 2018 at 12:18 PM To: Weylin Piegorsch Cc: "rancid-discuss@shrubbery.net" Subject: Re: [rancid] New Cisco ASA Login Fai

Re: [rancid] New Cisco ASA Login Failure

2018-03-05 Thread heasley
Mon, Mar 05, 2018 at 02:48:56PM +, Piegorsch, Weylin William: > Hello, > > I have a Cisco ASA 5506X device I just deployed (running 9.8(2)20 version), > that rancid’s not logging into properly. Clogincrc is set to method {telnet > ssh} because there’s a plethora of really really old devices