Jump to content

Recommended Posts

Posted

We had a planned power outage and our cisco ASA 5508 now seems to have stopped working - or letting us login anyway. Prior to the power cut all that happened was that the domain servers were shutdown and then restarted

 

Now, when I try to connect via ASDM I get the error 'Unable to launch device manager from <ip of asa>' and the java console shows the error 'java.net.ConnectException: Connection refused: connect'

 

If I try to ssh in to the device I get the error 'Unable to negotiate with <ip> port 22: no matching key exchange method found. Their offer: diffie-hellman-group14-sha1'

 

I can ssh using this method I found online: ssh -oKexAlgorithms=+diffie-hellman-group14-sha1 -oHostkeyAlgorithms=+ssh-rsa user@<ip> and I can see the running config looks the same as before the reboot!

 

So I'm baffled and a bit stressed as it seems to be blocking our vpn access as well now, even though the radius server shows granted access the users see the message 'User not authorised for AnyConnect Client access' after entering their details and adding their MS MFA code

 

So what could have caused this just from a reboot? The config was saved before the reboot so its not like we're missing a change (its been working for years with pretty much the same config)

 

I can't access the https://ip/admin page either now, the 'http server enable' command also doesn't seem to work anymore either

Posted

Assuming you enabled and it's all still the same password. 

Only got one boot image on there?

 

The change to SSH key requirements makes it feel like it's gone to an older software, I got the same from my 5510 when I forgot to remove the old bin file. 

 

Without seeing it, you never know what's gone on so I am just guessing :)

Posted

I’m still testing this but after two more reboots it seems to be working again! Which is a relief but also worrying as I’ve no idea what went wrong….

Posted

Probably not useful sorry - with that ASA being eol and nearly eosl, is it not worth replacing? I see you previously talk about smoothwall, any reason your not using that as a firewall?

 

Posted
3 minutes ago, CrootUK said:

Probably not useful sorry - with that ASA being eol and nearly eosl, is it not worth replacing? I see you previously talk about smoothwall, any reason your not using that as a firewall?

 

For me, personally, there has never been a good firewall that also was a good filter.

 

I think Smoothwall is probably closest to the best you could get, but I feel a firewall should be its own entity, it should do the job of yes/no, not have an alternative role to play. 

 

Obviously it's my preference though, everyone's different. 

  • Like 1
Posted (edited)

Yep agreed, with budgets in schools though, if you’re already invested in a product that can do both, certainly makes sense to do so, if said product is capable of doing so well that is.

 

If you were using say netsweeper then yeah separate firewall is your only option lol. 

 

Edited by CrootUK
Posted

You could use Netsweeper as the firewall, but you'd be on iptables or similar and it's not exactly user friendly. But yes 100% budgets and also supporting of said item often becomes the pinch point!

Posted
11 hours ago, PaddyNewman said:

For me, personally, there has never been a good firewall that also was a good filter.

 

I think Smoothwall is probably closest to the best you could get, but I feel a firewall should be its own entity, it should do the job of yes/no, not have an alternative role to play. 

 

Obviously it's my preference though, everyone's different. 

Some of the Fortinet stuff is pretty good too for fw/filter 

Posted (edited)

I’m planning to ditch the asa as part of our new build and mainly use the smootwall as the firewall, but we still need the vpn for remote sims access for now

 

It’s too soon for sims cloud so we either stick with the asa or setup remote apps (which I’ve used successfully in the past)

 

To be fair the Asa has been pretty reliable apart from this odd wobble!

Edited by Sheridan
Posted
16 minutes ago, dmj said:

Some of the Fortinet stuff is pretty good too for fw/filter 

I dealt with FortiGates when they started to introduce their web filter. My support case from 2017 closed with 'no fix' and I think it's still the case to this day. Their protocol detection leaves a lot to be desired. 

 

Their filter itself has got better over the years, I still don't personally believe it's fit for education but they have come on leaps and bounds since 2017, it used to be almost unusable!

Posted
1 hour ago, Sheridan said:

I’m planning to ditch the asa as part of our new build and mainly use the smootwall as the firewall, but we still need the vpn for remote sims access for now

 

It’s too soon for sims cloud so we either stick with the asa or setup remote apps (which I’ve used successfully in the past)

 

To be fair the Asa has been pretty reliable apart from this odd wobble!

Fair enough. Lots of options if you have issues again though without breaking the bank.. Entra App Proxy for RDWebclient or your smoothwall can do VPN. 

 

Touch wood it doesn't happen again, do you have any support for the ASA? worth logging a ticket.. 

Posted
On 18/04/2025 at 09:53, Sheridan said:

I’m planning to ditch the asa as part of our new build and mainly use the smootwall as the firewall, but we still need the vpn for remote sims access for now

 

It’s too soon for sims cloud so we either stick with the asa or setup remote apps (which I’ve used successfully in the past)

 

To be fair the Asa has been pretty reliable apart from this odd wobble!

 

In my (probably biased) view Sophos is a good option for both firewall and web-filter, but also as a separate firewall.  The Central combined management of CIXA, MDR, firewall etc are a good timesaver and give a lot of visibility/felxibility across your estate - cost effective too...  I think a continuing/increasing focus on security standards for schools from DFE is inevitable, and an enterprise NG Firewall is a foundational step in that ecosystem.

Posted

Smoothwall remains your only UKSIC accredited option if you want firewall and filter in the same box :) we can support openvpn if you need to keep VPN knocking about for now?

Posted

I'd prefer to keep the smoothwall on and use it as the all in one solution - however we currently use MFA (Microsoft Azure) on the ASA and I don't think the smoothwall has any way of 2 factoring a connection?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...