CLI access to PA

Reply
Highlighted
L4 Transporter

CLI access to PA

@reaper@BPry @MickBall

 

What could cause a superuser to not be able to ssh to the CLI of the PA?


Accepted Solutions
Highlighted
L4 Transporter

@reaper @BPry @RobinClayton @MickBall

 

The deletion and re-add of the user fixed the issue

View solution in original post


All Replies
Highlighted
Cyber Elite

@jdprovine,

Do you get some sort of error message or does the device simply never respond? 

Highlighted
L4 Transporter

Do you get the loign prompt?

Highlighted
L4 Transporter

@BPry

Its simply never responds

Highlighted
L4 Transporter

@RobinClayton

Nope no login prompt

Highlighted
Cyber Elite

@jdprovine,

Look in the threat logs for ( id eq 31914 ) and see if the traffic is getting identified as a threat and droped. Ensure that your management profile wasn't altered to disable SSH access, or that it wasn't disabled on the management port itself. Ensure that if this traffic flows through the firewall it is actually allowed and isn't hitting the default interzone-default deny policy. 

 

Does this only happen to one user, or is it anyone who attempts to access the device?

Highlighted
L4 Transporter

So not limited to super user,

 

 

Using the same IP as the HTTPS interface?

 

 

Device > Setup > Interface > management ( SSH enabled? )

Highlighted
L4 Transporter

@BPry

I checked and nope not being dropped as a threat. Management interface is set to allow ssh access. I am not the one who cannot ssh, it is a  user that was just elevated to superuser in the last week. I and others can ssh fine to both PA's. I don't see the user being blocked in the traffic monitor, in fact he is in the same zone as the PA.

 

Highlighted
L4 Transporter

@RobinClayton

Only one user is having this issue and he is a superuser. Yes same IP as the HTTPS interface .

Device > Setup > Interface > management ( SSH enabled? ) - yes

Highlighted
L7 Applicator

Has the user been able to log into the web interface ?

Tom Piens - PANgurus.com
Find my book at amazon.com/dp/1789956374
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!