<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SXP session issue between Swith and ASA in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/4085977#M560428</link>
    <description>&lt;P&gt;I remember that's the first thing which I had tested. Both peers were pingable to each other bidirectionally. Thanks!&lt;/P&gt;</description>
    <pubDate>Thu, 14 May 2020 16:46:05 GMT</pubDate>
    <dc:creator>Saurabh Dhakate</dc:creator>
    <dc:date>2020-05-14T16:46:05Z</dc:date>
    <item>
      <title>SXP session issue between Switch and ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/3804368#M485044</link>
      <description>&lt;P&gt;Hi Everyone,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am trying to form a SXP sesstion between ASA and&amp;nbsp;WS-C3850-12S-S switch .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Commands on switch :&lt;/P&gt;
&lt;P&gt;cts sxp enable&lt;BR /&gt;cts sxp default source-ip 10.100.8.22&lt;BR /&gt;cts sxp default password testing&lt;BR /&gt;cts sxp connection peer 10.10.8.1 source 10.100.8.22 password default mode local speaker hold-time 0&lt;/P&gt;
&lt;P&gt;----------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;Commands on ASA:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;cts sxp enable&lt;BR /&gt;cts sxp default password testing&lt;BR /&gt;cts sxp default source-ip 10.100.8.1&lt;BR /&gt;cts sxp connection peer 10.100.8.22 source 10.100.8.1 password default mode local listener&lt;/P&gt;
&lt;P&gt;------------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;But the connection status is still off as shown below&lt;/P&gt;
&lt;P&gt;Sw(config)#do sh cts sxp conn&lt;BR /&gt;SXP : Enabled&lt;BR /&gt;Highest Version Supported: 4&lt;BR /&gt;Default Password : Set&lt;BR /&gt;Default Source IP: 10.100.8.22&lt;BR /&gt;Connection retry open period: 120 secs&lt;BR /&gt;Reconcile period: 120 secs&lt;BR /&gt;Retry open timer is running&lt;BR /&gt;Peer-Sequence traverse limit for export: Not Set&lt;BR /&gt;Peer-Sequence traverse limit for import: Not Set&lt;BR /&gt;----------------------------------------------&lt;BR /&gt;Peer IP : 10.10.8.1&lt;BR /&gt;Source IP : 10.100.8.22&lt;BR /&gt;Conn status : Off&lt;BR /&gt;Conn version : 4&lt;BR /&gt;Local mode : SXP Speaker&lt;BR /&gt;Connection inst# : 1&lt;BR /&gt;TCP conn fd : -1&lt;BR /&gt;TCP conn password: default SXP password&lt;BR /&gt;Duration since last state change: 0:00:01:02 (dd:hr:mm:sec)&lt;/P&gt;
&lt;P&gt;---------------------------------------------------------------------------------&lt;/P&gt;
&lt;P&gt;Below are the log messages which it shows .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*Feb 18 19:56:07.347: CTS-SXP-CONN:sxp_process_message_event = CTS_SXPMSG_REQUES T&lt;BR /&gt;*Feb 18 19:56:07.348: CTS-SXP-CONN:sxp_process_request CTS_SXPMSG_REQ_SHOWCONN&lt;BR /&gt;*Feb 18 19:56:07.348: CTS-SXP-INTNL:sxp_conn_wavl_cmp_tableid tableid1 0x0, tabl eid2 0x0, ip1 10.10.8.1, ip2 0.0.0.0 conn_mode1 1 conn_mode2 1&lt;/P&gt;
&lt;P&gt;*Feb 18 19:56:07.348: CTS-SXP-INTNL:sxp_get_next_conn_by_tableid conn:0x3DCB197C , peer ip:10.10.8.1, tableid:0x0&lt;/P&gt;
&lt;P&gt;*Feb 18 19:56:07.348: CTS-SXP-INTNL:sxp_conn_wavl_cmp_tableid tableid1 0x0, tabl eid2 0x0, ip1 10.10.8.1, ip2 10.10.8.1 conn_mode1 1 conn_mode2 1&lt;/P&gt;
&lt;P&gt;*Feb 18 19:56:07.348: CTS-SXP-INTNL:sxp_get_next_conn_by_tableid conn:0x0, peer ip:0.0.0.0, tableid:0x0&lt;/P&gt;
&lt;P&gt;*Feb 18 19:56:07.348: CTS-SXP-INTNL:cdb_get_next_entry&lt;BR /&gt;*Feb 18 19:56:07.348: CTS-SXP-INTNL:cdb_get_next_entry&lt;BR /&gt;*Feb 18 19:56:07.348: CTS-SXP-INTNL:sxp_process_request boolean set&lt;/P&gt;
&lt;P&gt;*Feb 18 19:56:07.348: CTS-SXP-INTNL:sxp_send_request set boolean after&lt;/P&gt;
&lt;P&gt;*Feb 18 19:56:16.998: CTS-SXP-CONN:is_cts_sxp_rf_active&lt;BR /&gt;*Feb 18 19:56:16.999: CTS-SXP-CONN:ph_retry_open_timer&lt;BR /&gt;*Feb 18 19:56:16.999: CTS-SXP-CONN:ph_retry_open_timer retry timer stopped&lt;BR /&gt;*Feb 18 19:56:16.999: CTS-SXP-INTNL:cdb_get_next_entry&lt;BR /&gt;*Feb 18 19:56:16.999: CTS-SXP-CONN:retry conn setup; conn index = 1&lt;BR /&gt;*Feb 18 19:56:16.999: CTS-SXP-CONN:sh_re_setup_conn conn_index = 1&lt;BR /&gt;*Feb 18 19:56:16.999: CTS-SXP-CONN:conn_cleanup &amp;lt;-1&amp;gt;&lt;BR /&gt;*Feb 18 19:56:16.999: sxp_calc_src_ip cfg src: 10.100.8.22, def src: 10.100.8.22 calc src: 10.100.8.22 vrf:, tableid:0x0&lt;BR /&gt;*Feb 18 19:56:16.999: CTS-SXP-CONN:sxp_socket_open vrf:, tablied:0x0 src_ip = 10.100.8.22&lt;BR /&gt;*Feb 18 19:56:16.999: CTS-SXP-CONN:SXP SCM: socket open fd = 1, src_ip = 10.100.8.22&lt;BR /&gt;*Feb 18 19:56:17.002: CTS-SXP-CONN:ph_send_open &amp;lt;1&amp;gt; fd: 1, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 19:56:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 19:56:17.002: CTS-SXP-CONN:get_conn_passwd_info &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 19:56:17.002: CTS-SXP-CONN:sxp_socket_upd_md5_option &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 19:56:17.002: CTS-SXP-CONN:SXP SCM: socket_connect result:-1, fd:1;errno = 265, No route to host, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 19:56:17.002: CTS-SXP-ERR:SXP SCM: socket_connect failed&lt;BR /&gt;*Feb 18 19:56:17.002: CTS-SXP-CONN:conn_cleanup &amp;lt;1&amp;gt;&lt;BR /&gt;*Feb 18 19:56:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 19:56:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 19:56:17.002: CTS-SXP-CONN:free_conn_buffers, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 19:56:17.003: CTS-SXP-CONN:conn_cleanup retry timer started&lt;BR /&gt;*Feb 18 19:56:17.003: CTS-SXP-INTNL:cdb_get_next_entry&lt;BR /&gt;*Feb 18 19:56:17.003: CTS-SXP-CONN:ph_retry_open_timer retry timer started&lt;BR /&gt;*Feb 18 19:57:11.925: CTS-SXP-CONN:Received invalid DIRECT_EVENT&lt;BR /&gt;*Feb 18 19:57:11.927: CTS-SXP-CONN:Received invalid DIRECT_EVENT&lt;BR /&gt;*Feb 18 19:57:11.928: CTS-SXP-CONN:is_cts_sxp_rf_active&lt;BR /&gt;*Feb 18 19:57:11.928: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 0, &amp;lt;0.0.0.0, 0.0.0.0&amp;gt;&lt;BR /&gt;*Feb 18 19:57:11.928: CTS-SXP-ERR:conn index out of range, ci=-1&lt;BR /&gt;*Feb 18 19:57:11.928: CTS-SXP-CONN:Received Socket event; sock_ev = 1 fd: 0, &amp;lt;0.0.0.0, 0.0.0.0&amp;gt;&lt;BR /&gt;*Feb 18 19:57:11.928: CTS-SXP-CONN:scm_handle_accept_sock &amp;lt;0&amp;gt;&lt;BR /&gt;*Feb 18 19:57:11.928: CTS-SXP-CONN:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.10.8.1, ip2 10.100.8.1 conn mode1 1, conn_mode2 1&lt;/P&gt;
&lt;P&gt;*Feb 18 19:57:11.928: CTS-SXP-INTNL:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.10.8.1, ip2 10.100.8.1 conn mode1 1,conn_mode2 1&lt;/P&gt;
&lt;P&gt;*Feb 18 19:57:11.928: CTS-SXP-CONN:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.10.8.1, ip2 10.100.8.1 conn mode1 1, conn_mode2 2&lt;/P&gt;
&lt;P&gt;*Feb 18 19:57:11.928: CTS-SXP-INTNL:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.10.8.1, ip2 10.100.8.1 conn mode1 1,conn_mode2 2&lt;/P&gt;
&lt;P&gt;*Feb 18 19:57:11.928: CTS-SXP-ERR:SXP SCM: configuration error: &amp;lt;10.100.8.1, 10.100.8.22&amp;gt; fd = 1 cfg:0x0, conndb:0x0&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can anyone figure out anything from this?&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 15:57:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/3804368#M485044</guid>
      <dc:creator>saurabhdhakate007</dc:creator>
      <dc:date>2020-05-14T15:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: SXP session issue between Swith and ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/3804371#M485046</link>
      <description>&lt;P&gt;*Feb 18 20:11:49.637: CTS-SXP-CONN:sxp_process_message_event = CTS_SXPMSG_REQUEST&lt;BR /&gt;*Feb 18 20:11:49.637: CTS-SXP-CONN:sxp_process_request CTS_SXPMSG_REQ_SHOWCONN&lt;BR /&gt;*Feb 18 20:11:49.637: CTS-SXP-INTNL:sxp_conn_wavl_cmp_tableid tableid1 0x0, tableid2 0x0, ip1 10.10.8.1, ip2 0.0.0.0 conn_mode1 1 conn_mode2 1&lt;/P&gt;&lt;P&gt;*Feb 18 20:11:49.637: CTS-SXP-INTNL:sxp_get_next_conn_by_tableid conn:0x3DCB197C, peer ip:10.10.8.1, tableid:0x0&lt;/P&gt;&lt;P&gt;*Feb 18 20:11:49.637: CTS-SXP-INTNL:sxp_conn_wavl_cmp_tableid tableid1 0x0, tableid2 0x0, ip1 10.10.8.1, ip2 10.10.8.1 conn_mode1 1 conn_mode2 1&lt;/P&gt;&lt;P&gt;*Feb 18 20:11:49.637: CTS-SXP-INTNL:sxp_get_next_conn_by_tableid conn:0x0, peer ip:0.0.0.0, tableid:0x0&lt;/P&gt;&lt;P&gt;*Feb 18 20:11:49.637: CTS-SXP-INTNL:cdb_get_next_entry&lt;BR /&gt;*Feb 18 20:11:49.637: CTS-SXP-INTNL:cdb_get_next_entry&lt;BR /&gt;*Feb 18 20:11:49.637: CTS-SXP-INTNL:sxp_process_request boolean set&lt;/P&gt;&lt;P&gt;*Feb 18 20:11:49.638: CTS-SXP-INTNL:sxp_send_request set boolean after&lt;/P&gt;&lt;P&gt;*Feb 18 20:12:16.998: CTS-SXP-CONN:is_cts_sxp_rf_active&lt;BR /&gt;*Feb 18 20:12:16.998: CTS-SXP-CONN:ph_retry_open_timer&lt;BR /&gt;*Feb 18 20:12:16.998: CTS-SXP-CONN:ph_retry_open_timer retry timer stopped&lt;BR /&gt;*Feb 18 20:12:16.998: CTS-SXP-INTNL:cdb_get_next_entry&lt;BR /&gt;*Feb 18 20:12:16.998: CTS-SXP-CONN:retry conn setup; conn index = 1&lt;BR /&gt;*Feb 18 20:12:16.998: CTS-SXP-CONN:sh_re_setup_conn conn_index = 1&lt;BR /&gt;*Feb 18 20:12:16.998: CTS-SXP-CONN:conn_cleanup &amp;lt;-1&amp;gt;&lt;BR /&gt;*Feb 18 20:12:16.998: sxp_calc_src_ip cfg src: 10.100.8.22, def src: 10.100.8.22 calc src: 10.100.8.22 vrf:, tableid:0x0&lt;BR /&gt;*Feb 18 20:12:16.998: CTS-SXP-CONN:sxp_socket_open vrf:, tablied:0x0 src_ip = 10.100.8.22&lt;BR /&gt;*Feb 18 20:12:16.999: CTS-SXP-CONN:SXP SCM: socket open fd = 1, src_ip = 10.100.8.22&lt;BR /&gt;*Feb 18 20:12:17.001: CTS-SXP-CONN:ph_send_open &amp;lt;1&amp;gt; fd: 1, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 20:12:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 20:12:17.002: CTS-SXP-CONN:get_conn_passwd_info &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 20:12:17.002: CTS-SXP-CONN:sxp_socket_upd_md5_option &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 20:12:17.002: CTS-SXP-CONN:SXP SCM: socket_connect result:-1, fd:1;errno = 265, No route to host, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 20:12:17.002: CTS-SXP-ERR:SXP SCM: socket_connect failed&lt;BR /&gt;*Feb 18 20:12:17.002: CTS-SXP-CONN:conn_cleanup &amp;lt;1&amp;gt;&lt;BR /&gt;*Feb 18 20:12:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 20:12:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 20:12:17.002: CTS-SXP-CONN:free_conn_buffers, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 20:12:17.002: CTS-SXP-CONN:conn_cleanup retry timer started&lt;BR /&gt;*Feb 18 20:12:17.002: CTS-SXP-INTNL:cdb_get_next_entry&lt;BR /&gt;*Feb 18 20:12:17.002: CTS-SXP-CONN:ph_retry_open_timer retry timer started&lt;BR /&gt;*Feb 18 20:13:11.986: CTS-SXP-CONN:Received invalid DIRECT_EVENT&lt;BR /&gt;*Feb 18 20:13:11.988: CTS-SXP-CONN:Received invalid DIRECT_EVENT&lt;BR /&gt;*Feb 18 20:13:11.988: CTS-SXP-CONN:is_cts_sxp_rf_active&lt;BR /&gt;*Feb 18 20:13:11.989: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 0, &amp;lt;0.0.0.0, 0.0.0.0&amp;gt;&lt;BR /&gt;*Feb 18 20:13:11.989: CTS-SXP-ERR:conn index out of range, ci=-1&lt;BR /&gt;*Feb 18 20:13:11.989: CTS-SXP-CONN:Received Socket event; sock_ev = 1 fd: 0, &amp;lt;0.0.0.0, 0.0.0.0&amp;gt;&lt;BR /&gt;*Feb 18 20:13:11.989: CTS-SXP-CONN:scm_handle_accept_sock &amp;lt;0&amp;gt;&lt;BR /&gt;*Feb 18 20:13:11.989: CTS-SXP-CONN:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.10.8.1, ip2 10.100.8.1 conn mode1 1, conn_mode2 1&lt;/P&gt;&lt;P&gt;*Feb 18 20:13:11.989: CTS-SXP-INTNL:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.10.8.1, ip2 10.100.8.1 conn mode1 1,conn_mode2 1&lt;/P&gt;&lt;P&gt;*Feb 18 20:13:11.989: CTS-SXP-CONN:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.10.8.1, ip2 10.100.8.1 conn mode1 1, conn_mode2 2&lt;/P&gt;&lt;P&gt;*Feb 18 20:13:11.989: CTS-SXP-INTNL:sxp_cfg_wavl_cmp_vrfname vrf name1 , vrf name2 , ip1 10.10.8.1, ip2 10.100.8.1 conn mode1 1,conn_mode2 2&lt;/P&gt;&lt;P&gt;*Feb 18 20:13:11.989: CTS-SXP-ERR:SXP SCM: configuration error: &amp;lt;10.100.8.1, 10.100.8.22&amp;gt; fd = 1 cfg:0x0, conndb:0x0&lt;BR /&gt;*Feb 18 20:13:11.989: CTS-SXP-CONN:Received invalid DIRECT_EVENT&lt;BR /&gt;*Feb 18 20:14:16.998: CTS-SXP-CONN:is_cts_sxp_rf_active&lt;BR /&gt;*Feb 18 20:14:16.998: CTS-SXP-CONN:ph_retry_open_timer&lt;BR /&gt;*Feb 18 20:14:16.998: CTS-SXP-CONN:ph_retry_open_timer retry timer stopped&lt;BR /&gt;*Feb 18 20:14:16.998: CTS-SXP-INTNL:cdb_get_next_entry&lt;BR /&gt;*Feb 18 20:14:16.998: CTS-SXP-CONN:retry conn setup; conn index = 1&lt;BR /&gt;*Feb 18 20:14:16.998: CTS-SXP-CONN:sh_re_setup_conn conn_index = 1&lt;BR /&gt;*Feb 18 20:14:16.998: CTS-SXP-CONN:conn_cleanup &amp;lt;-1&amp;gt;&lt;BR /&gt;*Feb 18 20:14:16.998: sxp_calc_src_ip cfg src: 10.100.8.22, def src: 10.100.8.22 calc src: 10.100.8.22 vrf:, tableid:0x0&lt;BR /&gt;*Feb 18 20:14:16.998: CTS-SXP-CONN:sxp_socket_open vrf:, tablied:0x0 src_ip = 10.100.8.22&lt;BR /&gt;*Feb 18 20:14:16.999: CTS-SXP-CONN:SXP SCM: socket open fd = 1, src_ip = 10.100.8.22&lt;BR /&gt;*Feb 18 20:14:17.002: CTS-SXP-CONN:ph_send_open &amp;lt;1&amp;gt; fd: 1, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 20:14:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 20:14:17.002: CTS-SXP-CONN:get_conn_passwd_info &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 20:14:17.002: CTS-SXP-CONN:sxp_socket_upd_md5_option &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 20:14:17.002: CTS-SXP-CONN:SXP SCM: socket_connect result:-1, fd:1;errno = 265, No route to host, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 20:14:17.002: CTS-SXP-ERR:SXP SCM: socket_connect failed&lt;BR /&gt;*Feb 18 20:14:17.002: CTS-SXP-CONN:conn_cleanup &amp;lt;1&amp;gt;&lt;BR /&gt;*Feb 18 20:14:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 20:14:17.002: CTS-SXP-INTNL:sxp_fd_hash_table_entry_find cdbp 1, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 20:14:17.002: CTS-SXP-CONN:free_conn_buffers, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 20:14:17.002: CTS-SXP-CONN:conn_cleanup retry timer started&lt;BR /&gt;*Feb 18 20:14:17.002: CTS-SXP-INTNL:cdb_get_next_entry&lt;BR /&gt;*Feb 18 20:14:17.002: CTS-SXP-CONN:ph_retry_open_timer retry timer started&lt;/P&gt;</description>
      <pubDate>Mon, 18 Feb 2019 20:06:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/3804371#M485046</guid>
      <dc:creator>saurabhdhakate007</dc:creator>
      <dc:date>2019-02-18T20:06:48Z</dc:date>
    </item>
    <item>
      <title>Re: SXP session issue between Swith and ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/3804377#M485050</link>
      <description>Try removing the cts sxp default source-ip command from both sides, the connection statement will handle that.  From the outputs, the switch is using the default source IP, but your connection is configured for 10.100.8.128 source.  There is also this log which I would follow up on to confirm you have reachability, check your 10.100.8.128 interface is up and active, remove the default IP if it continues trying to use 10.100.8.22.  &lt;BR /&gt;"*Feb 18 19:56:17.002: CTS-SXP-CONN:SXP SCM: socket_connect result:-1, fd:1;errno = 265, No route to host, &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;"&lt;BR /&gt;&lt;BR /&gt;In my lab I use a very simple two lines for SXP between my ASA to do exactly what you are trying, no default IP required.  You can keep the password, I just didn't bother. &lt;BR /&gt;switchx#sh run | inc cts&lt;BR /&gt;cts sxp enable&lt;BR /&gt;cts sxp connection peer 10.0.1.2 source 10.0.0.1 password none mode local speaker hold-time 0&lt;BR /&gt;&lt;BR /&gt;ASA&lt;BR /&gt;ASA# sh run | inc cts&lt;BR /&gt;cts sxp enable&lt;BR /&gt;cts sxp connection peer 10.0.0.1 source 10.0.1.2 password none mode local listener&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Mon, 18 Feb 2019 20:14:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/3804377#M485050</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-02-18T20:14:10Z</dc:date>
    </item>
    <item>
      <title>Re: SXP session issue between Swith and ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/3804651#M485052</link>
      <description>&lt;P&gt;Hey Damien,&lt;/P&gt;&lt;P&gt;Apologies&amp;nbsp;, it was my typo . I tried to change the IP's for confidentiality .&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is 10.100.8.1 as it should be.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do this all the time and it does not give me any issue at all . Its just this time I enabled it on ASA first , rather than Switch . Does it really make any difference?&lt;/P&gt;&lt;P&gt;I have tried disabling and reenabling it , shut and no shut SVI of the switch , clearing cts sxp config from both ends and reconfiguring them, finally reloading the Swith as well as ASA&amp;nbsp; and it did not come out.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please share me any documents which guides about best practise in SXP , if you have any?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Your help is hightly appreciated .&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks ,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Saurabh Dhakate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Feb 2019 07:04:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/3804651#M485052</guid>
      <dc:creator>saurabhdhakate007</dc:creator>
      <dc:date>2019-02-19T07:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: SXP session issue between Swith and ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/3804957#M485057</link>
      <description>&lt;P&gt;Perhaps the SXP connections not permitted. See&amp;nbsp;&lt;A href="https://community.cisco.com/docs/DOC-69479" target="_blank"&gt;TrustSec Troubleshooting Guide&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Other TrustSec resources at&amp;nbsp;&lt;A href="https://community.cisco.com/t5/security-documents/segmentation-amp-group-based-policy-resources/ta-p/3656481" target="_blank"&gt;Segmentation &amp;amp; Group-Based Policy Resou... - Cisco Community&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Feb 2019 14:36:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/3804957#M485057</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2019-02-19T14:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: SXP session issue between Swith and ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/3805221#M485059</link>
      <description>This doc is also quite relevant. &lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://www.cisco.com/c/dam/en/us/solutions/collateral/borderless-networks/trustsec/C07-730151-00_overview_of_trustSec_og.pdf" target="_blank"&gt;https://www.cisco.com/c/dam/en/us/solutions/collateral/borderless-networks/trustsec/C07-730151-00_overview_of_trustSec_og.pdf&lt;/A&gt;</description>
      <pubDate>Tue, 19 Feb 2019 19:26:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/3805221#M485059</guid>
      <dc:creator>Damien Miller</dc:creator>
      <dc:date>2019-02-19T19:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: SXP session issue between Swith and ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/4085013#M560381</link>
      <description>&lt;P&gt;Have you solved this ? We have a problem SXP problem with ASA and IOS-XE too&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 14:49:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/4085013#M560381</guid>
      <dc:creator>kerstin-534</dc:creator>
      <dc:date>2020-05-13T14:49:36Z</dc:date>
    </item>
    <item>
      <title>Re: SXP session issue between Swith and ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/4085056#M560384</link>
      <description>&lt;P&gt;As per the logs, it looks like the routing issue on switch:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;*Feb 18 19:56:17.002: CTS-SXP-CONN:sxp_socket_upd_md5_option &amp;lt;10.10.8.1, 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 19:56:17.002: CTS-SXP-CONN:SXP SCM: socket_connect result:-1, fd:1;errno = 265&lt;STRONG&gt;, No route to host, &amp;lt;10.10.8.1,&lt;/STRONG&gt; 10.100.8.22&amp;gt;&lt;BR /&gt;*Feb 18 19:56:17.002: CTS-SXP-ERR:SXP SCM: socket_connect failed&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 15:32:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/4085056#M560384</guid>
      <dc:creator>poongarg</dc:creator>
      <dc:date>2020-05-13T15:32:32Z</dc:date>
    </item>
    <item>
      <title>Re: SXP session issue between Swith and ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/4085977#M560428</link>
      <description>&lt;P&gt;I remember that's the first thing which I had tested. Both peers were pingable to each other bidirectionally. Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 16:46:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/4085977#M560428</guid>
      <dc:creator>Saurabh Dhakate</dc:creator>
      <dc:date>2020-05-14T16:46:05Z</dc:date>
    </item>
    <item>
      <title>Re: SXP session issue between Swith and ASA</title>
      <link>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/4087226#M560463</link>
      <description>&lt;P&gt;The authoritative guide for switch to ASA would be the &lt;A title="http://www.cisco.com/c/dam/en/us/td/docs/solutions/CVD/Apr2016/User-to-DC_Access_Control_Using_TrustSec_Deployment_April2016.pdf" href="http://www.cisco.com/c/dam/en/us/td/docs/solutions/CVD/Apr2016/User-to-DC_Access_Control_Using_TrustSec_Deployment_April2016.pdf" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;TrustSec User to Data Center Access Control Design Guide.&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Find others at &lt;A href="http://cs.co/ise-guides#TrustSec" target="_blank"&gt;http://cs.co/ise-guides#TrustSec&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 17 May 2020 00:29:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/sxp-session-issue-between-switch-and-asa/m-p/4087226#M560463</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2020-05-17T00:29:48Z</dc:date>
    </item>
  </channel>
</rss>

