CLI access to PA

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

CLI access to PA

L4 Transporter

@reaper@BPry @Mick_Ball

 

What could cause a superuser to not be able to ssh to the CLI of the PA?

1 accepted solution

Accepted Solutions

@reaper @BPry @RobinClayton @Mick_Ball

 

The deletion and re-add of the user fixed the issue

View solution in original post

31 REPLIES 31

Cyber Elite
Cyber Elite

@jdprovine,

Do you get some sort of error message or does the device simply never respond? 

L4 Transporter

Do you get the loign prompt?

@BPry

Its simply never responds

@RobinClayton

Nope no login prompt

@jdprovine,

Look in the threat logs for ( id eq 31914 ) and see if the traffic is getting identified as a threat and droped. Ensure that your management profile wasn't altered to disable SSH access, or that it wasn't disabled on the management port itself. Ensure that if this traffic flows through the firewall it is actually allowed and isn't hitting the default interzone-default deny policy. 

 

Does this only happen to one user, or is it anyone who attempts to access the device?

So not limited to super user,

 

 

Using the same IP as the HTTPS interface?

 

 

Device > Setup > Interface > management ( SSH enabled? )

@BPry

I checked and nope not being dropped as a threat. Management interface is set to allow ssh access. I am not the one who cannot ssh, it is a  user that was just elevated to superuser in the last week. I and others can ssh fine to both PA's. I don't see the user being blocked in the traffic monitor, in fact he is in the same zone as the PA.

 

@RobinClayton

Only one user is having this issue and he is a superuser. Yes same IP as the HTTPS interface .

Device > Setup > Interface > management ( SSH enabled? ) - yes

Cyber Elite
Cyber Elite

Has the user been able to log into the web interface ?

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

If there is no login prompt, is this not affecting all users from the same workstation?

 

 

"I don't see the user being blocked in the traffic monitor, in fact he is in the same zone as the PA."

 

Are they using the Dedicated managemetn interface? ( can they ping it? )

 

Is there any IP restrictions on the management interface?

 

 

@reaper

Yes he is able to login to the web interface

L7 Applicator

Hi @jdprovine'

 

perhaps go back a step, is ping enabled on management interface.

 

if it is and you can ping the interface, then see if the troubled user can also ping it. 

@RobinClayton

Everything is the same for him as it is for me, he is able to use the local superuser admin account and login fine

@Mick_Ball

Yes ping is enabled, I will check if he can ping it

  • 1 accepted solution
  • 6800 Views
  • 31 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!