Cisco ASA: Keep VPN Always Up
Nov22

Cisco ASA: Keep VPN Always Up

VPN Always UP KB ID 0001839 Problem This was information that was passed to me by a colleague (Thanks Ajay) this week. If you have a site to site VPN tunnel after a period of inactivity the tunnel will be torn down. In most cases when required it will simply be re-established, but what if you wanted it to be permanently up? I have had situations where only the ASA side of a tunnel can bring it up (usually because of misconfiguration...

Read More
macOS – SSH Error ‘No Matching Exchange Method Found’
Oct22

macOS – SSH Error ‘No Matching Exchange Method Found’

Mac SSH Error KB ID 0001245  Problem Certified working all the way up to macOS Ventura version 13.6 Certified working all the way up to macOS Sonoma version 14.1 I thought my RoyalTSX had broken today, I upgraded it a couple of weeks ago, and I upgraded to macOS Catalina 10.15 the other day. After this, all my SSH sessions refused to connect with this error;   Unable to negotiate with x.x.x.x port 22: no matching key exchange found....

Read More
ASDM on Windows 11?
Nov24

ASDM on Windows 11?

ASDM on Windows 11 KB ID 0001806 Problem Can you install ASDM on Windows 11? yes, but as usual there’s some pre requisites. Someone asked this question on EE today, so I thought I’d check. ASDM on Windows 11 Solution ASDM requires Java, theres an open Java version, but to be honest, most people (and certainly most older firewalls) are using the Oracle JRE so make sure you have that installed before you do anything. Note:...

Read More
Windows: Cisco ASDM ‘This app can’t run on your PC’
Nov24

Windows: Cisco ASDM ‘This app can’t run on your PC’

‘This app can’t run on your PC’ KB ID 0001574 Problem Whys isn’t Java dead yet? 🙁 Anyway, I tried to connect to a clients ASDM today, and from my Windows 10 machine, I got the following error; Windows 11 Windows 10 This app can’t run on your PC To find a version for your PC, check with the software publisher. ‘This app can’t run on your PC’ Solution Make sure you have installed Java...

Read More
FortiGate Certificate Import Errors
Jun27

FortiGate Certificate Import Errors

FortiGate Certificate KB ID 0001791 Problem A colleague messaged me last week because he could not import a certificate on a FortiGate (that had been exported from a Cisco ASA). He was seeing this error; Incorrect certificate file format for CA/LOCAL/CRL/REMOTE cert. FortiGate Certificate Problems A brief Google led me to ask “Is the FortGate licensed or on a Free/Trial license?” As that can produce this error...

Read More
Cisco to FortiGate Command Conversion
Apr06

Cisco to FortiGate Command Conversion

KB ID 0001776 Problem Bah what the hell is ‘show run’? If you’ve spent years on Cisco IOS and ASA/Firepower, then FortiGate can be a little confusing. Hopefully this Cisco to FortiGate list below will make it a little easier. Cisco to Fortigate Translation Cisco Command FortiGate Command Basic commands show run show full-config show version get system status show ip interface brief show system interface show run...

Read More