Thursday 11 April 2013

Error code: ssl_error_no_cypher_overlap ASDM cannot connect or will not start on Cisco ASA using Windows 7

This is to help anyone having problems with the initial ASDM download that according to Cisco should happen straight out the box, well as with a lot of Cisco's equipment it isn't always as friendly as the documentation says.

My particular problem occurred with version was ASA Version 8.6(1)2 and ASDM 6.6(1)

I tried with three machines Windows 7 32 bit, Windows 7 64 bit and Windows XP only the windows XP machine worked, atleast I knew at that point there is hope.

 I noticed that when connecting via the windows 7 box I would sometimes get the error message:
 Cannot communicate securely with peer: no common encryption algorithm(s).
(Error code: ssl_error_no_cypher_overlap)












At this point I had a good search around the internet and managed to find the following line of code in a forum:
ssl encryption rc4-md5 rc4-sha1 aes128-sha1 aes256-sha1 3des-sha1

After this was entered at the conf t prompt everything worked as it should.

I can only put this down to later browsers usings more advanced versions of encryption that were n't configured when ASA Version 8.6(1)2 was built.

I've since found another blog with a better explanation but I will leave this in place as I didn't find anything when trawling google originally and the more help out their the better as this gave me a bit of a headache and wasted a good few hours!