Unable to SSH in to ASA with new created user

Hello. I have an ASA 5510 firewall running an older verison of code. I"m trying to create a new user account to log in but I can't seem to SSH with this account. ASDM works fine but SSH fails. I thought the command would have been: 
username newuser password usertest123 privilege 15
But I can't SSH with this. What am I missing?
Cisco Adaptive Security Appliance Software Version 7.2(4)
Device Manager Version 5.2(4)

I think this may be what's missing. Here's the error I received though when trying to add this to the configuration. I'm assuming I need to create this group?
FIrewall-ASA(config)# aaa authentication ssh console local
ERROR: aaa-server group local does not exist
Usage: [no] aaa mac-exempt match <mac-list-id>
        [no] aaa authentication secure-http-client
        [no] aaa authentication listener http|https <if_name> [port <port>] [redirect]
        [no] aaa authentication|authorization|accounting include|exclude <svc>
                <if_name> <l_ip> <l_mask> [<f_ip> <f_mask>] <server_tag>
        [no] aaa authentication serial|telnet|ssh|http|enable console
                <server_tag> [LOCAL]
        [no] aaa accounting telnet|ssh|serial|enable console <server_tag>
        [no] aaa authentication|authorization|accounting match
                <access_list_name> <if_name> <server_tag>
        [no] aaa authorization command {LOCAL | <tacacs_server_tag> [LOCAL]}
        [no] aaa accounting command {privilege <level>} <tacacs_server_tag>
        [no] aaa proxy-limit <proxy limit> | disable
        [no] aaa local authentication attempts max-fail <fail-attempts>
        clear configure aaa
        clear aaa local user {fail-attempts|lockout} {all | username <uname>}}
        show running-config [all] aaa [authentication|authorization|accounting
                |max-exempt|proxy-limit]
        show aaa local user [lockout]

Similar Messages

  • New created user does appear in the outlook address book

    My exchange server is 2007. I create a new new user in the exchange server. However, with outlook address book I did not see it. With OWA, I can see that user. Therefore, I am sure that Global address book works well. BTW, with those command
    Update-OfflineAddresssBook -Identity "Default Offline Address Book"
    Update-GlobalAddressList -Identity "Default Global Address List"
    I still did not see the new created user in outlook address book.
    I tried my outlook 2010 as well. I tried the action to download addressbook. Not working either. What shall I do?

    Hi,
    According to your description, the new mailbox doesn’t appear in Outlook while it’s visible in OWA.
    Before going further, I’d like to recommend you check if it’s visible in Outlook with online mode.
    If it is, the issue is most likely related to OAB. And we can try to download a new OAB and restart related services.
    For more detail steps, you can refer to the answer in the following thread:
    http://social.technet.microsoft.com/Forums/en-US/626dd301-12a5-4196-9bc8-9f3ec7ef3259/new-user-not-show-up-in-gal-on-outlook
    If it doesn’t show up in online mode, we can try to check if the new mailbox is visible in GAL on another computer. For more information about OAB downloading and updating, please refer to:
    http://support.microsoft.com/kb/841273/en-us
    Thanks,
    Winnie Liang
    TechNet Community Support

  • Treo 700P with contacts - need advice on synchronizing with new outlook user profile

    Hello Treo Experts.
    I have a Treo 700P.
    It is full of contacts.
    I have a new Outlook user profile and am unable to synchronize between the Treo and Outlook.
    I deinstalled Palm SW and reinstalled it
    I am about to 'syhncronize the Treo with my computer
    my question is: Is this safe to do? I don't want to lose all my contacts on my Treo. 
    Any suggestions - greatly appreciated!
    Post relates to: Treo 700p (Verizon)
    Post relates to: Treo 700p (Verizon)

    Hi..  Welcome to the Palm forums.  You should be fine, the contacts on the device should write to outlook and combine with what ever is in outlook.
    Post relates to: Centro (Sprint)

  • Not able to login with new LDAP user in portal..

    All,
    We have created a new user in our LDAP environment in Portal. ( not UME ). I am able to view the user id in Identity management and assigned the necessary roles. but, i am unable to login using the new user id. Can anybody please tell me what is missing here ? Thanks in advance.

    Hi Addy,
    As Raghu said, this seems to be a password problem.
    Log into the Portal as an User administrator.
    Find the user and Click on Modify.
    In User Information, Add a new password.
    Then try to login with the given user id again with the new password.
    Good Luck!!!
    Biroj Patro

  • New created users don't work

    I have a very strange problem here.
    When i create a new user with the workgroup-manager, he doesn't work.
    I can't connect the server by AFP from a client computer with the username and password of the user and i can't connect the web services (wiki-server) with the login data of the user.
    The existing user work fine, only the new generated users doesn't work.
    Maybe a problem with the Open Directory service?
    Has someone an idea what the problem could be?
    Thank you for your help!
    Greetings
    Alex
    Message was edited by: FiveEcco

    ok, my fault, found the mistake.

  • Unable to extend existing wireless network with new TC

    I have an original 500GB Time Capsule that I've been using successfully for a long time. It is plugged into my modem/router (which acts as a DHCP server) in bridge mode.
    As the TC is getting full (and the number of Macs in our house is increasing!), I decided to buy another TC - this time the latest 2TB model. I have set it up so it extends my existing network. However, as soon as I plug it into my network my Internet connection breaks (or goes very slow) and the modem/router activity light flashes like crazy. As soon as I unplug the new TC from my wired network, I get my fast Internet connection back and the modem/router goes back to normal.
    I've tried using the LAN and WAN ports on the new TC to connect to my wired network but the result is the same.
    Has anyone any ideas what the problem is? Is there a problem using the latest TC to extend the wireless network of an older model TC?

    Welcome to the discussion area!
    If you are connecting your Time Capsules using an ethernet cable, you would connect from one of the LAN ports on the "main" device to the WAN port on your new 2TB device.
    The 2 TB device must be configured as a "bridge".
    You would configure the 2 TB device to "create a wireless network" using the same network name (SSID), security setting and password as your "main" device. (The "extend" setting is only used if you are connecting your devices using wireless only...and you are using ethernet).
    When you "create" the wireless network on your 2 TB device, you are configuring what is known as a "roaming" network. Your laptop will automatically connect the device with the strongest wireless signal depending on where it "roams".
    To configure your 2 TB device as a bridge:
    AirPort Utility > Manual Setup > Internet icon > Connection Sharing setting = Off (Bridge Mode).
    Please post back on your results.

  • Unable to correctly authorize a computer with new Apple ID

    I had to ditch my old Apple ID as it was shared with a person that I no longer live with. I registered a new Apple ID and using a new computer with my previous phone. I can sync the phone fine, but can't transfer purchased apps to iTunes. I authorize the computer and all seems well. I then attempt to transfer apps from my phone to iTunes and get an error message stating the computer isn't authorized. Any ideas? I've authorized/deauthorized many times and it seems to work until I attempt to transfer apps over.

    If the book was bought with your account then it will be tied to your account so you will need to authorise your account on it via the Store > Authorise This Computer menu option.

  • Unable to see tables in forms with new username

    I have created a new user test1 assigned to the role that provides privilege for objects. Originally I created my database objects using username ktb (public synonyms and grants have been provided). Logging into SQL*Plus as test1 I can see and access the ktb tables/objects. However, I cannot see these tables from Forms Builder when logging in as test1, whereas I can as ktb. Is there something I am missing?

    Error 201 ...
    identifier .... must be declared
    Also, I am running Forms 10g against Oracle Expess 10g database.
    Message was edited by:
    devint

  • Can't log in with newly created user on new install of Arch [solved]

    Hi all,
    Yesterday I installed Arch anew (because I had a hardware failure that took out my hard drive), but now I'm encountering an issue with logging in.
    After following the installation guide, and creating a new user, I find that I'm unable to log in as said user.
    It complains about wrong password, but it's the exact same password that I entered mere moments before that, when creating the new user.
    I can "log in" as said user by first logging in as root (which does work) and doing "su - <username>" (though then it doesn't ask for a password).
    Can someone point me in the right direction to fix this problem?
    Last edited by madjo (2013-07-03 20:19:43)

    I think cfr meant to say you shouldn't "fix" bash path - as some users did. Unfortunately there's a bit confusion wrt which paths should be used - see this ML thread.
    Some say we should keep /bin/foo for compatibility, others say that we should boldly move to /usr/bin/foo.

  • Unable to access server files shares with Active Directory Users

    Quick breakdown of my issue.
    I have setup a Yosemite file server running the latest version of Yosemite and Server.
    File sharing in Server.app is enabled and shares have been created
    The server is bound to my company's Active Directory and you can directly login to the computer via AD credentials.
    The big issue is this, unless the user has directly walked up to my server and logged into it at least once, they cannot authenticate to the file shares via their AD credentials.
    For example: Administrator (me) I can login and access all file shares without issue.
    Jane Smith (SMITH) who has actually walked up to my server and logged in via her AD credentials, can also access all file shares. (That she has access to)
    John Doe (JDOE) who has not logged into the server in anyway, cannot authenticate to the server file shares  at all (even though I have granted him permission) He just gets an "Access Denied" message.
    I have gone into Directory Utility and changed the search order to give AD priority and this still doesn't resolve the problem.
    We have unbound the server from AD and added in back again and still not able to resolve.
    If you open Server.app and go to add someone from AD to a file share, it finds the AD user quickly and everything looks right. but still unable to authenticate to the server if they haven't directly logged into it before?
    All of the documentation and google articles I have found say my server is setup correctly, any help would be greatly appreciate it!
    Thanks in advance!

    I figured this out. In Mountain Lion Server, it doesn't matter if you give the user rights to a shared file or folder, if the user doesn't have access the File Sharing service, they can't get it. I had to find the specific users in the Server app under the AD in the Users tab, and give them rights to the File Sharing service. I think you can do this for a whole AD group as well, but I haven't tried.

  • New created user cannot access OWA

    I have a sporadic issue with some new users.  As we migrate folks to Exchange, some new accounts created are unable to access their mailbox via OWA (or their personal device).  It just keeps responding "The username or passowrd you entered
    isn't correct.  Try entering it again.".
    They never successfully log on (although some have after a few days).  I've verified that they have the correct security.  
    Any ideas?

    Try checking the OWA and ActiveSync policies, and comparing to a user that is known to work:
    Get-CASMailbox "<mailbox name>" | Select-Object Name,ActiveSyncEnabled,ActiveSyncMailboxPolicy,OWAEnabled,OWAMailboxPolicy

  • Mb5b time_out with newly created user

    Dear expert,
    I have created new sap id and provided requested authorization however if we run mb5b it gets time_out even for one day but if we run it using any old SAP id it works fine.

    take a performance trace in ST05 to see where the transaction spends all the time.
    take an authorization trace in ST01 to see if the authorization affects the transaction.
    make sure you execute with the very same selection parameters (except for the display variant, which may be user specific), the old user might have some defaults from user parameters which might not be available for the new user, compare the user parameters.
    MB5B is in general slow and must not be used for mass data (see 1005901 - MB5B: Performance problems)

  • Java exception with commadmin create user command

    Hi,
    I should very much like to get Messaging Server running in conjunction with Identity Server.
    Ideally I would like Identity Server to be accessible via an Application Server instance.
    So far I have succeeded in installing Directory Server, Administration Server, Application Server and Identity Server.
    I have two problems:
    When I executed commadmin to create a mail user I used this command:
    /opt/SUNWcomm/bin/commadmin user create -v -D amAdmin -n acc.graddelt.com
    -w <pw> -F test -l test -L test -W <pw> -S mail -H trabant.acc.graddelt.com
    I then get a Java error:
    [17/Feb/2004:15:16:35] SEVERE (14419): StandardWrapperValve[commLDAPAuth]: Servlet.service() for se
    rvlet commLDAPAuth threw exception
    java.security.AccessControlException: access denied (java.util.PropertyPermission user.language wri
    te)
    on the Application Server
    Second problem:
    I've setup the HTTP server component of Messenger Server to listen on port 81, but I only get
    the Application Server default page instead of the Messenger Server Web Interface.
    I think both problems may be caused by the way I installed these JES components, so
    I enclose the procedure here:
    I chose a Base DN of dc=acc.graddelt.com without a sub organisation.
    I chose the Custom Install option for each application
    ) Installed Application Server, Directory Server and Admin Server. Did not install sample data.
    ) Started Application Admin Server
    /var/opt/SUNWappserver7/domains/domain1/admin-server/bin/startserv
    ) Then created a new instance called `server1'
    ) Installed Identity Server in the newly created Application Server instance server1
    ) I verified Identity server was accessible and working correctly
    ) Installed Messaging Server & Calendar Server
    ) Executed 'perl comm_dssetup.pl'
    Server Root : /var/opt/mps/serverroot
    Server Instance : slapd-trabant
    Users/Groups Directory : Yes
    Update Schema : yes
    Schema Type : 2
    DC Root : dc=acc.graddelt.com
    User/Group Root : dc=acc.graddelt.com
    Add New Indexes : yes
    Directory Manager DN : cn=Directory Manager
    ) Setup additional Indexes (http://docs.sun.com/source/816-6874/std-comp-inst.html#wp28563)
    & added Self Ref. Plug-in to LDAP server then restarted LDAP server and Application server.
    ) Executed /opt/SUNWcomm/sbin/config-iscli
    Chose to put users in Base DN as this is simple test system
    ) Updated App server as per http://docs.sun.com/source/817-4216-10/config.html
    ./asadmin deploy user admin password <pw> --instance server1 \
    host trabant port 4848 name commcli contextroot commcli \
    /opt/SUNWcomm/lib/jars/commcli-server.war
    ) Restarted Application Server
    ) Executed /opt/SUNWmsgvr/sbin/configure
    ) Added Mail service from /opt/SUNWam/samples/integration
    /opt/SUNWam/bin/amadmin \
    --runasdn uid=admin,ou=People,dc=acc.graddelt.com \
    password <pw> schema sampleMailServerService.xml
    ) Created a User with uid test and Registered the simple Mail service in Identity Manager.
    ) Setup a user account in Messaging Server
    /opt/SUNWcomm/bin/commadmin user create -v -D admin -F test -n acc.graddelt.com -l test -w <pw>
    -W <pw> -L test -S mail -H trabant.acc.graddelt.com
    I'm running JES 03Q4 on a Solaris 8 420R. The system is fully patched and up to date
    Many thanks
    Shaun

    Two questions:
    [17/Feb/2004:15:16:35] SEVERE (14419): StandardWrapperValve[commLDAPAuth]: Servlet.service() for se
    rvlet commLDAPAuth threw exception
    java.security.AccessControlException: access denied (java.util.PropertyPermission user.language wri
    te)
    on the Application Server
    This looks like an acl problem. A default installation should not have this, so, we're looking at what might have gone wrong with your installation, or what was changed. Let's start with looking at file permissions and such. I believe JES installer defaults to installing the container for Identity and Identity as root. Did you change this? If so, you need to check file ownership and permissions.
    Second problem:
    I've setup the HTTP server component of Messenger Server to listen on port 81, but I only get
    the Application Server default page instead of the Messenger Server Web Interface.
    This means that you installed App Server to also respond on port 81. You cannot have two different products listening to ther same port. You will need to change one or the other.

  • Problem when logged in using a new created user

    Hi,
    I'm implementing Single-Sign-On feature, i followed steps given in weblog
    Integrating your Web Front-ends into the SAP Enterprise Portal using the Application Integrator
    I created one portal user with the same name and password as my application requires and specified the same in User Mapping. Also I assigned this user content_admin_role.
    When i logged in with this user and tried to open my iView, its shows this error:
    Portal Runtime Error
    An exception occurred while processing a request for :
    iView : N/A
    Component Name : N/A
    Access denied (Object: portal_content/com.sap.pct/admin.templates/iviews/editors/com.sap.portal.templateSelection).
    Exception id: 10:43_31/05/06_0011_3850950
    See the details for the exception ID in the log file
    Is there anythig I'm missing.
    I require urgent help on this.
    Thanks & Regards,
    bhawna

    Hi bhawna,
    Step 1:
    1.Go to System Administration - > Permissions
    2. Go to Portal Content -> Your Folder (iViews, Workset, Roles, Systems)
    3. Right click - > Open Permissions.
    4. Give Permissions for the user for the iViews.
    Note : Enable "End user " check box.
    Step 2:
    1. Go to System Admin -> System Config -> System Landscape
    2. Go to Portal Content - > Your system
    3. Right click - > Open Permissions.
    4. Give Permissions for the user for the iViews.
    Note : Enable "End user " check box.
    Regards,
    venkat.
    [Pls reward points if useful]

  • Serious problem with TSCAL per user Licensing (Event 4105 on Licenseserver)

    Hello,
    i've got a problem with Terminalservice-Licensing: We migrated our AD from W2003 to W2008. At the same time, we updated our Terminalservice-Licenseserver to W2008 (Memberserver, no DC). We are using per-user TSCAL licensing. The problem is, that for (nearly) every user that logs on to a W2008 Terminalserver, an event 4105 is generated in the eventlog of the Licenseserver, that  means that the licence server cannot update the ad user properties when he delivers the cals.
    We have discovered that the terminalserver-licenceserver group is under the security properties of the user listed but has no rights. For new created users the rights "terminalserver-licenceserver read/write" are correctly set and for those users no event 4105 is generated. The problem is, that License-reporting (usage) is only working for those newly created accounts and not for old ones. Why doesn't the terminalserver-licenceserver group have the rights to modify the Terminalserver-AD attributes for older accounts (these accounts were created when the domain-level was W2003)??? Is there a workaround or hotfix from Microsoft to correct the securitysettings ??
    Many thanks
    Ralf

    Hello Ralf,
    Thanks for your post in our forum.
    Based on my understanding on your post, you have met the following issue:
    You have migrated the Active Directory domain from Windows Server 2003 to Windows Server 2008; You have also upgraded the Terminal Server License Server from Windows Server 2003 to Windows Server 2008. After that, when the existing terminal users access the Terminal Server, an Event ID 4105 is logged to claim that the License Server fails to update the AD user’s properties.
    According to the analysis on the second paragraph of your post, I think it is a known issue caused by insufficient permissions of the migrated users created in Windows Server 2003 domain environment. As you’ve found, the permissions required are for the Terminal Services Licensing Servers
    group:
    ·          Read Terminal Server license server
    ·          Write Terminal Server license server
    To fix this issue, please give these two permissions to the existing users.
    After that, please confirm if the License Usage Report is working for the old users.
    For more information about Event ID 4105, please refer to:
    Event ID 4105 — Terminal Services Per User Client Access License Tracking and Reporting
    http://technet.microsoft.com/en-us/library/cc775179(WS.10).aspx
    Please feel free to let me know if I can provide any further assistance. Thank you for your cooperation.
    Lionel Chen
    TechNet Subscriber Support in forum
    If you have any feedback on our support, please contact [email protected]

Maybe you are looking for

  • How do I get rid of album art on iPad?

    I upgraded to iOS 7.0.4 today, and I hate it. But what I hate most of all is that all my purchases had album art automatically downloaded for them, even though I intentionally delete all album art from every song I buy. I have no idea how to get rid

  • Problem when connection with 2 accounts

    A friend of mine have problem to surf the web when he is connected to the internet. The ISP supply him with 2 accounts, and when he surf with the main account, he don't have problem to reach all the site he wish to go. But, when he use the second acc

  • Arch not compatible with Cairo Dock

    As you can see in this topic: http://www.glx-dock.org/bg_topic.php?t= - mess_65929 it turns out using menu system in Cairo Dock on Arch is not possible due to Arch sporting newest Python 3 rather than 2. Is there any workaround for it? I do need this

  • No guidance as to which version of desktop one should load for a particular handheld

    I know that different versions of the desktop software are geared for the latest and greatest new models.  I have a 7130 dinasour.   I want to know what is the most recent software that is good to safely load that will work well with my device, not t

  • How to find out when an agent was deleted from scom

    I can get an installed date easy enough, but I wonder if there is a log or record of when a particular agent/server was removed from monitoring in SCOM. If there is a way to get this information, please post a query. Thanks. B. Wright