Hi,
We are receiving messages in ASA firewalls saying first:
6 Oct 21 2021 12:19:47 605005 ssh Login permitted from x.x.x.x/xxxxx to interface:x.x.x.x/ssh for user x
followed by:
6 Oct 21 2021 12:19:52 315011 SSH session from x.x.x.x on interface for user "*****" disconnected by SSH server, reason: "Internal error" (0x00)
This is Orion NCM logging in to ASA with SSH and then disconnecting.
I see these two messages generated about once every minute whether I request a download config in NCM or not.
I tested logging in with SSH manually and if I do exit I get message in log saying "terminated normally" and if I just close the windows I get the message saying "internal error".
Is there any way to get NCM to exit the "right way" and does anybody know why this is happening so often?
I should add that the node is using the device template called "Cisco Adaptive Security Appliance".