<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic crypto errors CTM ERROR: Failed to allocate x bytes of memory in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/crypto-errors-ctm-error-failed-to-allocate-x-bytes-of-memory/m-p/2067007#M397746</link>
    <description>&lt;P&gt;Hi There.&lt;/P&gt;&lt;P&gt;I am currently getting a strange error when trying to use and crypto services on our ASA 5520 (8.0.3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Initially I observed that a connected VPN had dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then when I attempted to use ASDM or SSH I was blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the end I opened telnet as a test and this was successful. Syslog also shows that traffic is passing as normal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only obvious error I can see when observing various debug traces is this;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FW02# CTM: rsa session with no priority allocated @ 0xCF1FBBA0&lt;/P&gt;&lt;P&gt;CTM: Session 0xCF1FBBA0 uses a nlite (Nitrox Lite) as its hardware engine&lt;/P&gt;&lt;P&gt;CTM: rsa context allocated for session 0xCF1FBBA0&lt;/P&gt;&lt;P&gt;CTM: rsa session with no priority allocated @ 0xCE7A5EA8&lt;/P&gt;&lt;P&gt;CTM: Session 0xCE7A5EA8 uses a nlite (Nitrox Lite) as its hardware engine&lt;/P&gt;&lt;P&gt;CTM: rsa context allocated for session 0xCE7A5EA8&lt;/P&gt;&lt;P&gt;CTM: rsa session with no priority allocated @ 0xCEF249D0&lt;/P&gt;&lt;P&gt;CTM: Session 0xCEF249D0 uses a nlite (Nitrox Lite) as its hardware engine&lt;/P&gt;&lt;P&gt;CTM: rsa context allocated for session 0xCEF249D0&lt;/P&gt;&lt;P&gt;CTM: dh session with no priority allocated @ 0xCEF249D0&lt;/P&gt;&lt;P&gt;CTM: Session 0xCEF249D0 uses a nlite (Nitrox Lite) as its hardware engine&lt;/P&gt;&lt;P&gt;CTM: dh context allocated for session 0xCEF249D0&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;CTM ERROR: Failed to allocate 279 bytes of memory, ctm_nlite_generate_dh_key_pair:183&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone seen anything like this before as I am lost?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 00:07:15 GMT</pubDate>
    <dc:creator>mikedelafield</dc:creator>
    <dc:date>2019-03-12T00:07:15Z</dc:date>
    <item>
      <title>crypto errors CTM ERROR: Failed to allocate x bytes of memory</title>
      <link>https://community.cisco.com/t5/network-security/crypto-errors-ctm-error-failed-to-allocate-x-bytes-of-memory/m-p/2067007#M397746</link>
      <description>&lt;P&gt;Hi There.&lt;/P&gt;&lt;P&gt;I am currently getting a strange error when trying to use and crypto services on our ASA 5520 (8.0.3)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Initially I observed that a connected VPN had dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then when I attempted to use ASDM or SSH I was blocked.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the end I opened telnet as a test and this was successful. Syslog also shows that traffic is passing as normal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only obvious error I can see when observing various debug traces is this;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FW02# CTM: rsa session with no priority allocated @ 0xCF1FBBA0&lt;/P&gt;&lt;P&gt;CTM: Session 0xCF1FBBA0 uses a nlite (Nitrox Lite) as its hardware engine&lt;/P&gt;&lt;P&gt;CTM: rsa context allocated for session 0xCF1FBBA0&lt;/P&gt;&lt;P&gt;CTM: rsa session with no priority allocated @ 0xCE7A5EA8&lt;/P&gt;&lt;P&gt;CTM: Session 0xCE7A5EA8 uses a nlite (Nitrox Lite) as its hardware engine&lt;/P&gt;&lt;P&gt;CTM: rsa context allocated for session 0xCE7A5EA8&lt;/P&gt;&lt;P&gt;CTM: rsa session with no priority allocated @ 0xCEF249D0&lt;/P&gt;&lt;P&gt;CTM: Session 0xCEF249D0 uses a nlite (Nitrox Lite) as its hardware engine&lt;/P&gt;&lt;P&gt;CTM: rsa context allocated for session 0xCEF249D0&lt;/P&gt;&lt;P&gt;CTM: dh session with no priority allocated @ 0xCEF249D0&lt;/P&gt;&lt;P&gt;CTM: Session 0xCEF249D0 uses a nlite (Nitrox Lite) as its hardware engine&lt;/P&gt;&lt;P&gt;CTM: dh context allocated for session 0xCEF249D0&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;CTM ERROR: Failed to allocate 279 bytes of memory, ctm_nlite_generate_dh_key_pair:183&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone seen anything like this before as I am lost?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 00:07:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-errors-ctm-error-failed-to-allocate-x-bytes-of-memory/m-p/2067007#M397746</guid>
      <dc:creator>mikedelafield</dc:creator>
      <dc:date>2019-03-12T00:07:15Z</dc:date>
    </item>
    <item>
      <title>crypto errors CTM ERROR: Failed to allocate x bytes of memory</title>
      <link>https://community.cisco.com/t5/network-security/crypto-errors-ctm-error-failed-to-allocate-x-bytes-of-memory/m-p/2067008#M397747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Sounds like the ASA is out of DMA memory (show memory detail - should indicate this).&amp;nbsp; There could be a number of reasons why... Your logging config, snmp config, etc.... or a bug.&amp;nbsp; However it may take some troubelshooting to determine what is causing it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For now, capture a 'show tech' and "show memory detail".&amp;nbsp; At this point, you will most likely need to reload the ASA in order to gain back the DMA memory in order to initiate new tunnels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;David.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2012 13:48:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-errors-ctm-error-failed-to-allocate-x-bytes-of-memory/m-p/2067008#M397747</guid>
      <dc:creator>David White</dc:creator>
      <dc:date>2012-10-10T13:48:37Z</dc:date>
    </item>
    <item>
      <title>crypto errors CTM ERROR: Failed to allocate x bytes of memory</title>
      <link>https://community.cisco.com/t5/network-security/crypto-errors-ctm-error-failed-to-allocate-x-bytes-of-memory/m-p/2067009#M397748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is possibly a software/hardware issue as this cisco doc&amp;nbsp; ( Search for CTM).. though they are providing a resolution.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/asa/asa81/command/ref/s2.html"&gt;http://www.cisco.com/en/US/docs/security/asa/asa81/command/ref/s2.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;may be time to a take a reload and try for a luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Harish.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2012 13:49:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-errors-ctm-error-failed-to-allocate-x-bytes-of-memory/m-p/2067009#M397748</guid>
      <dc:creator>Harish Balakrishnan</dc:creator>
      <dc:date>2012-10-10T13:49:25Z</dc:date>
    </item>
    <item>
      <title>crypto errors CTM ERROR: Failed to allocate x bytes of memory</title>
      <link>https://community.cisco.com/t5/network-security/crypto-errors-ctm-error-failed-to-allocate-x-bytes-of-memory/m-p/2067010#M397749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for that. It does look like its out of crypto memory...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DMA memory:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Unused memory:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 23849516 bytes (30%)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Crypto reserved memory:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20537556 bytes (26%)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Crypto free:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 bytes ( 0%)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Crypto used:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 20537556 bytes (26%)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Block reserved memory:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 34669024 bytes (44%)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Block free:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 30734752 bytes (39%)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Block used:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3934272 bytes ( 5%)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; Used memory:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 185120 bytes ( 0%)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unless there is a way to specifically restart only the crypto engine or clear crypto memory then I guess I am looking at a reload?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mike&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2012 13:52:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-errors-ctm-error-failed-to-allocate-x-bytes-of-memory/m-p/2067010#M397749</guid>
      <dc:creator>mikedelafield</dc:creator>
      <dc:date>2012-10-10T13:52:53Z</dc:date>
    </item>
    <item>
      <title>crypto errors CTM ERROR: Failed to allocate x bytes of memory</title>
      <link>https://community.cisco.com/t5/network-security/crypto-errors-ctm-error-failed-to-allocate-x-bytes-of-memory/m-p/2067011#M397750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I may also have found a bug ID which could be relevant&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSCsm93115 &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2012 13:54:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-errors-ctm-error-failed-to-allocate-x-bytes-of-memory/m-p/2067011#M397750</guid>
      <dc:creator>mikedelafield</dc:creator>
      <dc:date>2012-10-10T13:54:53Z</dc:date>
    </item>
    <item>
      <title>crypto errors CTM ERROR: Failed to allocate x bytes of memory</title>
      <link>https://community.cisco.com/t5/network-security/crypto-errors-ctm-error-failed-to-allocate-x-bytes-of-memory/m-p/2067012#M397751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Mike,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you are out of crypto memory.&amp;nbsp; There could be a few reasons &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&amp;nbsp; The bug you cite is one of them.&lt;/P&gt;&lt;P&gt;Unfortunately, at this point you have to reload to get the memory back.&amp;nbsp; You can't reload just the crypto sub-system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sincerely,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;David.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Oct 2012 13:58:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/crypto-errors-ctm-error-failed-to-allocate-x-bytes-of-memory/m-p/2067012#M397751</guid>
      <dc:creator>David White</dc:creator>
      <dc:date>2012-10-10T13:58:59Z</dc:date>
    </item>
  </channel>
</rss>

