MY-ASA-1a# debug crypto ipsec 255 MY-ASA-1a# MY-ASA-1a# MY-ASA-1a# ###################### MY-ASA-1a# MY-ASA-1a# MY-ASA-1a# IPSEC: Received a PFKey message from IKE IPSEC: Parsing PFKey GETSPI message IPSEC: Creating IPsec SA IPSEC: Getting the inbound SPI IPSEC DEBUG: Inbound SA (SPI 0x00000000) state change from inactive to embryonic IPSEC: New embryonic SA created @ 0xae6f5180, SCB: 0xAE6DCEF0, Direction: inbound SPI : 0x588B2C43 Session ID: 0x000CD000 VPIF num : 0x00000003 Tunnel type: l2l Protocol : esp Lifetime : 240 seconds IPSEC: Received a PFKey message from IKE IPSEC: Parsing PFKey ADD message IPSEC: Creating IPsec SA IPSEC: Adding the outbound SA, SPI: 0x0CBF30C8 IPSEC DEBUG: Outbound SA (SPI 0x0CBF30C8) state change from inactive to embryonic IPSEC: New embryonic SA created @ 0xadca92f8, SCB: 0xAE6DD3A0, Direction: outbound SPI : 0x0CBF30C8 Session ID: 0x000CD000 VPIF num : 0x00000003 Tunnel type: l2l Protocol : esp Lifetime : 240 seconds IPSEC: Completed host OBSA update, SPI 0x0CBF30C8 IPSEC: Creating outbound VPN context, SPI 0x0CBF30C8 Flags: 0x00000005 SA : 0xadca92f8 SPI : 0x0CBF30C8 MTU : 1500 bytes VCID : 0x00000000 Peer : 0x00000000 SCB : 0x333E1199 Channel: 0xa970a0c0 IPSEC: Increment SA NP ref counter for outbound SPI 0x0CBF30C8, old value: 0, new value: 1, (ctm_ipsec_create_vpn_context:7349) IPSEC: Completed outbound VPN context, SPI 0x0CBF30C8 VPN handle: 0x0000ad6c IPSEC: New outbound encrypt rule, SPI 0x0CBF30C8 Src addr: 10.100.1.0 Src mask: 255.255.255.0 Dst addr: 172.29.1.0 Dst mask: 255.255.255.0 Src ports Upper: 0 Lower: 0 Op : ignore Dst ports Upper: 0 Lower: 0 Op : ignore Protocol: 0 Use protocol: false SPI: 0x00000000 Use SPI: false IPSEC: Increment SA NP ref counter for outbound SPI 0x0CBF30C8, old value: 1, new value: 2, (ctm_ipsec_create_acl_entry:6358) IPSEC: Completed outbound encrypt rule, SPI 0x0CBF30C8 Rule ID: 0xae6dd690 IPSEC: Decrement SA NP ref counter for outbound SPI 0x0CBF30C8, old value: 2, new value: 1, (ctm_ipsec_create_acl_cb:5452) IPSEC: New outbound permit rule, SPI 0x0CBF30C8 Src addr: ### ASA-WAN-IP ### Src mask: 255.255.255.255 Dst addr: ### TP-LINK-WAN-IP ### Dst mask: 255.255.255.255 Src ports Upper: 0 Lower: 0 Op : ignore Dst ports Upper: 0 Lower: 0 Op : ignore Protocol: 50 Use protocol: true SPI: 0x0CBF30C8 Use SPI: true IPSEC: Increment SA NP ref counter for outbound SPI 0x0CBF30C8, old value: 1, new value: 2, (ctm_ipsec_create_acl_entry:6500) IPSEC: Completed outbound permit rule, SPI 0x0CBF30C8 Rule ID: 0xae6dd738 IPSEC: Decrement SA NP ref counter for outbound SPI 0x0CBF30C8, old value: 2, new value: 1, (ctm_ipsec_create_acl_cb:5452) IPSEC: Decrement SA NP ref counter for outbound SPI 0x0CBF30C8, old value: 1, new value: 0, (ctm_np_vpn_context_cb:11505) IPSEC: Increment SA HW ref counter for outbound SPI 0x0CBF30C8, old value: 0, new value: 1, (ctm_nlite_ipsec_create_hw_obsa:1175) IPSEC: Decrement SA HW ref counter for outbound SPI 0x0CBF30C8, old value: 1, new value: 0, (ctm_nlite_outbound_callback:4507) IPSEC: Received a PFKey message from IKE IPSEC: Parsing PFKey UPDATE message IPSEC: Creating IPsec SA IPSEC: Updating the inbound SA, SPI: 0x588B2C43 IPSEC: New embryonic SA created @ 0xae6f5180, SCB: 0xAE6DCEF0, Direction: inbound SPI : 0x588B2C43 Session ID: 0x000CD000 VPIF num : 0x00000003 Tunnel type: l2l Protocol : esp Lifetime : 240 seconds IPSEC: Completed host IBSA update, SPI 0x588B2C43 IPSEC: Creating inbound VPN context, SPI 0x588B2C43 Flags: 0x00000006 SA : 0xae6f5180 SPI : 0x588B2C43 MTU : 0 bytes VCID : 0x00000000 Peer : 0x0000AD6C SCB : 0x3336F281 Channel: 0xa970a0c0 IPSEC: Increment SA NP ref counter for inbound SPI 0x588B2C43, old value: 0, new value: 1, (ctm_ipsec_create_vpn_context:7282) IPSEC: Completed inbound VPN context, SPI 0x588B2C43 VPN handle: 0x0000dfe4 IPSEC: Updating outbound VPN context 0x0000AD6C, SPI 0x0CBF30C8 Flags: 0x00000005 SA : 0xadca92f8 SPI : 0x0CBF30C8 MTU : 1500 bytes VCID : 0x00000000 Peer : 0x0000DFE4 SCB : 0x333E1199 Channel: 0xa970a0c0 IPSEC: Increment SA NP ref counter for outbound SPI 0x0CBF30C8, old value: 0, new value: 1, (ctm_ipsec_update_vpn_context:7478) IPSEC: Completed outbound VPN context, SPI 0x0CBF30C8 VPN handle: 0x0000ad6c IPSEC: Completed outbound inner rule, SPI 0x0CBF30C8 Rule ID: 0xae6dd690 IPSEC: Completed outbound outer SPD rule, SPI 0x0CBF30C8 Rule ID: 0xae6dd738 IPSEC: Decrement SA NP ref counter for outbound SPI 0x0CBF30C8, old value: 1, new value: 0, (ctm_np_vpn_context_cb:11505) IPSEC: New inbound tunnel flow rule, SPI 0x588B2C43 Src addr: 172.29.1.0 Src mask: 255.255.255.0 Dst addr: 10.100.1.0 Dst mask: 255.255.255.0 Src ports Upper: 0 Lower: 0 Op : ignore Dst ports Upper: 0 Lower: 0 Op : ignore Protocol: 0 Use protocol: false SPI: 0x00000000 Use SPI: false IPSEC: Increment SA NP ref counter for inbound SPI 0x588B2C43, old value: 1, new value: 2, (ctm_ipsec_create_acl_entry:6036) IPSEC: Completed inbound tunnel flow rule, SPI 0x588B2C43 Rule ID: 0xae6ddb18 IPSEC: Decrement SA NP ref counter for inbound SPI 0x588B2C43, old value: 2, new value: 1, (ctm_ipsec_create_acl_cb:5452) IPSEC: New inbound decrypt rule, SPI 0x588B2C43 Src addr: ### TP-LINK-WAN-IP ### Src mask: 255.255.255.255 Dst addr: ### ASA-WAN-IP ### Dst mask: 255.255.255.255 Src ports Upper: 0 Lower: 0 Op : ignore Dst ports Upper: 0 Lower: 0 Op : ignore Protocol: 50 Use protocol: true SPI: 0x588B2C43 Use SPI: true IPSEC: Increment SA NP ref counter for inbound SPI 0x588B2C43, old value: 1, new value: 2, (ctm_ipsec_create_acl_entry:6159) IPSEC: Completed inbound decrypt rule, SPI 0x588B2C43 Rule ID: 0xae6ddbc0 IPSEC: Decrement SA NP ref counter for inbound SPI 0x588B2C43, old value: 2, new value: 1, (ctm_ipsec_create_acl_cb:5452) IPSEC: New inbound permit rule, SPI 0x588B2C43 Src addr: ### TP-LINK-WAN-IP ### Src mask: 255.255.255.255 Dst addr: ### ASA-WAN-IP ### Dst mask: 255.255.255.255 Src ports Upper: 0 Lower: 0 Op : ignore Dst ports Upper: 0 Lower: 0 Op : ignore Protocol: 50 Use protocol: true SPI: 0x588B2C43 Use SPI: true IPSEC: Increment SA NP ref counter for inbound SPI 0x588B2C43, old value: 1, new value: 2, (ctm_ipsec_create_acl_entry:6159) IPSEC: Completed inbound permit rule, SPI 0x588B2C43 Rule ID: 0xae6ddc68 IPSEC: Decrement SA NP ref counter for inbound SPI 0x588B2C43, old value: 2, new value: 1, (ctm_ipsec_create_acl_cb:5452) IPSEC: Decrement SA NP ref counter for inbound SPI 0x588B2C43, old value: 1, new value: 0, (ctm_np_vpn_context_cb:11505) IPSEC: Increment SA HW ref counter for inbound SPI 0x588B2C43, old value: 0, new value: 1, (ctm_nlite_ipsec_create_hw_ibsa:748) IPSEC: Decrement SA HW ref counter for inbound SPI 0x588B2C43, old value: 1, new value: 0, (ctm_nlite_inbound_callback:3225) IPSEC: Added SA to last received DB, SPI: 0x588B2C43, user: DefaultL2LGroup, peer: ### TP-LINK-WAN-IP ###, SessionID: 0x000CD000 IPSEC DEBUG: Inbound SA (SPI 0x588B2C43) state change from embryonic to active IPSEC DEBUG: Outbound SA (SPI 0x0CBF30C8) state change from embryonic to active IPSEC: Received a PFKey message from IKE IPSEC DEBUG: Received a DELETE PFKey message from IKE for an inbound SA (SPI 0x588B2C43) IPSEC DEBUG: Outbound SA (SPI 0x0CBF30C8) destroy started, state active IPSEC: Destroy current outbound SPI: 0x0CBF30C8 IPSEC DEBUG: Outbound SA (SPI 0x0CBF30C8) free started, state active IPSEC DEBUG: Outbound SA (SPI 0x0CBF30C8) state change from active to dead IPSEC DEBUG: Deleting the outbound encrypt rule for SPI 0x0CBF30C8 IPSEC: Increment SA NP ref counter for outbound SPI 0x0CBF30C8, old value: 0, new value: 1, (ctm_ipsec_delete_acl_entry:6931) IPSEC: Deleted outbound encrypt rule, SPI 0x0CBF30C8 Rule ID: 0xae6dd690 IPSEC: Decrement SA NP ref counter for outbound SPI 0x0CBF30C8, old value: 1, new value: 0, (ctm_ipsec_delete_acl_cb:5556) IPSEC ERROR: No active outbound encrypt rule to be deleted, SPI 0x0CBF30C8 IPSEC DEBUG: Deleting the outbound permit rule for SPI 0x0CBF30C8 IPSEC: Increment SA NP ref counter for outbound SPI 0x0CBF30C8, old value: 0, new value: 1, (ctm_ipsec_delete_acl_entry:6931) IPSEC: Deleted outbound permit rule, SPI 0x0CBF30C8 Rule ID: 0xae6dd738 IPSEC: Decrement SA NP ref counter for outbound SPI 0x0CBF30C8, old value: 1, new value: 0, (ctm_ipsec_delete_acl_cb:5556) IPSEC DEBUG: Deleting the Outbound VPN context for SPI 0x0CBF30C8 IPSEC: Increment SA NP ref counter for outbound SPI 0x0CBF30C8, old value: 0, new value: 1, (ctm_ipsec_free_sa:9066) IPSEC: Deleted outbound VPN context, SPI 0x0CBF30C8 VPN handle: 0x0000ad6c IPSEC: Decrement SA NP ref counter for outbound SPI 0x0CBF30C8, old value: 1, new value: 0, (ctm_np_vpn_delete_cb:11565) IPSEC DEBUG: Outbound SA (SPI 0x0CBF30C8) free completed IPSEC DEBUG: Outbound SA (SPI 0x0CBF30C8) destroy completed IPSEC DEBUG: Inbound SA (SPI 0x588B2C43) destroy started, state active IPSEC: Destroy current inbound SPI: 0x588B2C43 IPSEC DEBUG: inbound SA (SPI 0x588B2C43) state change from active to dead IPSEC DEBUG: Inbound SA (SPI 0x588B2C43) free started, state dead IPSEC DEBUG: Inbound SA (SPI 0x588B2C43) state change from dead to dead IPSEC DEBUG: Deleting the inbound decrypt rule for SPI 0x588B2C43 IPSEC: Increment SA NP ref counter for inbound SPI 0x588B2C43, old value: 0, new value: 1, (ctm_ipsec_delete_acl_entry:6931) IPSEC: Deleted inbound decrypt rule, SPI 0x588B2C43 Rule ID: 0xae6ddbc0 IPSEC: Decrement SA NP ref counter for inbound SPI 0x588B2C43, old value: 1, new value: 0, (ctm_ipsec_delete_acl_cb:5556) IPSEC DEBUG: Deleting the inbound permit rule for SPI 0x588B2C43 IPSEC: Increment SA NP ref counter for inbound SPI 0x588B2C43, old value: 0, new value: 1, (ctm_ipsec_delete_acl_entry:6931) IPSEC: Deleted inbound permit rule, SPI 0x588B2C43 Rule ID: 0xae6ddc68 IPSEC: Decrement SA NP ref counter for inbound SPI 0x588B2C43, old value: 1, new value: 0, (ctm_ipsec_delete_acl_cb:5556) IPSEC DEBUG: Deleting the inbound tunnel flow rule for SPI 0x588B2C43 IPSEC: Increment SA NP ref counter for inbound SPI 0x588B2C43, old value: 0, new value: 1, (ctm_ipsec_delete_acl_entry:6931) IPSEC: Deleted inbound tunnel flow rule, SPI 0x588B2C43 Rule ID: 0xae6ddb18 IPSEC: Decrement SA NP ref counter for inbound SPI 0x588B2C43, old value: 1, new value: 0, (ctm_ipsec_delete_acl_cb:5556) IPSEC DEBUG: Deleting the Inbound VPN context for SPI 0x588B2C43 IPSEC: Increment SA NP ref counter for inbound SPI 0x588B2C43, old value: 0, new value: 1, (ctm_ipsec_free_sa:9066) IPSEC: Deleted inbound VPN context, SPI 0x588B2C43 VPN handle: 0x0000dfe4 IPSEC: Decrement SA NP ref counter for inbound SPI 0x588B2C43, old value: 1, new value: 0, (ctm_np_vpn_delete_cb:11565) IPSEC: Removed SA from last received DB, SPI: 0x588B2C43, user: DefaultL2LGroup, peer: ### TP-LINK-WAN-IP ###, SessionID: 0x000CD000 IPSEC DEBUG: Inbound SA (SPI 0x588B2C43) free completed IPSEC DEBUG: Inbound SA (SPI 0x588B2C43) destroy completed