<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Firewall VPN Client Error in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-firewall-vpn-client-error/m-p/2492907#M45685</link>
    <description>&lt;P&gt;Dear Techies,&lt;/P&gt;&lt;P&gt;Following messages are generating on ASA and when it starts generating our VPN client (remote users) failed to pass thourgh IKE phase and VPN client get a message "VPN CLIENT ERROR".&lt;BR /&gt;&lt;BR /&gt;We clear all vpn session and also reapply cryto map for remote vpns and also shutdown the outside interface but all in vain as nothing change and same error was generating. After rebooting the ASA problems get resolved which is not the permanent solution. Your help is required to find a solution to this issue. Attached are the logs which were generating on ASA related to this issue.&lt;BR /&gt;&lt;BR /&gt;2014-03-10 11:56:07 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:43 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = khiap, IP = 119.160.51.248, Can't create conn entry!&lt;BR /&gt;&lt;BR /&gt;2014-03-10 11:56:07 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:44 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = shwcrm, IP = 182.185.169.162, Can't create conn entry!&lt;BR /&gt;&lt;BR /&gt;2014-03-10 11:56:07 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:44 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = lhrap, IP = 182.185.239.172, Can't create conn entry!&lt;BR /&gt;2014-03-10 11:56:07 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:44 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = pshdmr, IP = 175.107.56.173, Can't create conn entry!&lt;BR /&gt;2014-03-10 11:56:07 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:44 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = islrm, IP = 115.186.137.197, Can't create conn entry!&lt;BR /&gt;&lt;BR /&gt;2014-03-10 11:56:08 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:44 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = inkot, IP = 182.186.112.233, Can't create conn entry!&lt;BR /&gt;2014-03-10 11:56:08 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:45 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = khiap, IP = 119.73.92.220, Can't create conn entry!&lt;BR /&gt;&lt;BR /&gt;2014-03-10 11:56:09 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:45 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = muldmr, IP = 182.185.169.162, Can't create conn entry!&lt;BR /&gt;2014-03-10 11:56:09 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:45 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = khiap, IP = 119.73.92.220, Can't create conn entry!&lt;BR /&gt;2014-03-10 11:56:09 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:46 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = dikdmr, IP = 182.181.238.131, Can't create conn entry!&lt;BR /&gt;&lt;BR /&gt;2014-03-10 11:56:09 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Error &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:46 172.16.208.1 : %ASA-3-713203: IKE Receiver: Error reading from socket.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;2014-03-10 12:05:57 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Error &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 12:03:34 172.16.208.1 : %ASA-3-713232: IP = 182.181.238.131, SA lock refCnt = 1, bitmask = 00000002, p1_decrypt_cb = 0, qm_decrypt_cb = 0, qm_hash_cb = 0, qm_spi_ok_cb = 0, qm_dh_cb = 0, qm_secret_key_cb = 0, qm_encrypt_cb = 0&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;2014-03-10 12:06:03 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Debug &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 12:03:39 172.16.208.1 : %ASA-7-713052: Group = test_tunnel, Username = lhrcrm1, IP = 182.185.151.238, User (lhrcrm1) authenticated.&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;2014-03-10 12:06:03 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Debug &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 12:03:39 172.16.208.1 : %ASA-7-713052: Group = test_tunnel, Username = sukdmr, IP = 39.51.65.61, User (sukdmr) authenticated.&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;2014-03-10 12:06:03 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 12:03:40 172.16.208.1 : %ASA-4-713903: Group = test_tunnel, Username = lhrcrm1, IP = 182.185.151.238, ERROR: IKE failed trying to create a session manager entry&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;2014-03-10 12:06:03 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 12:03:40 172.16.208.1 : %ASA-4-713903: Group = test_tunnel, Username = sukdmr, IP = 39.51.65.61, ERROR: IKE failed trying to create a session manager entry&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;2014-03-10 14:18:47 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Error &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 14:16:24 172.16.208.1 : %ASA-3-713232: IP = 182.181.238.131, SA lock refCnt = 1, bitmask = 00000002, p1_decrypt_cb = 0, qm_decrypt_cb = 0, qm_hash_cb = 0, qm_spi_ok_cb = 0, qm_dh_cb = 0, qm_secret_key_cb = 0, qm_encrypt_cb = 0&lt;BR /&gt;2014-03-10 14:18:47 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Error &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 14:16:24 172.16.208.1 : %ASA-3-713232: IP = 182.186.27.230, SA lock refCnt = 1, bitmask = 00000002, p1_decrypt_cb = 0, qm_decrypt_cb = 0, qm_hash_cb = 0, qm_spi_ok_cb = 0, qm_dh_cb = 0, qm_secret_key_cb = 0, qm_encrypt_cb = 0&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;2014-03-10 18:53:07 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:50:44 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0xA81E0AFF, sequence number= 0x57D) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 172.16.192.116/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:53:16 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:50:54 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0xA81E0AFF, sequence number= 0x57E) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 172.16.192.116/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:53:18 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:50:56 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0x637D43E2, sequence number= 0x22C) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 10.10.9.2/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:53:26 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:04 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0xA81E0AFF, sequence number= 0x57F) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 172.16.192.116/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:53:28 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:06 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0x637D43E2, sequence number= 0x22D) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 10.10.9.2/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:53:36 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:14 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0xA81E0AFF, sequence number= 0x580) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 172.16.192.116/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:53:38 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:16 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0x637D43E2, sequence number= 0x22E) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 10.10.9.2/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:53:46 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:24 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0xA81E0AFF, sequence number= 0x581) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 172.16.192.116/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:53:56 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:34 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0xA81E0AFF, sequence number= 0x582) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 172.16.192.116/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:54:06 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:44 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0xA81E0AFF, sequence number= 0x583) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 172.16.192.116/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:54:08 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:46 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0x637D43E2, sequence number= 0x232) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 10.10.9.2/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:54:16 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:54 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0xA81E0AFF, sequence number= 0x584) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 172.16.192.116/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;ASA# sh vpn-sessiondb remote&lt;BR /&gt;&lt;BR /&gt;Session Type: IPsec&lt;BR /&gt;&lt;BR /&gt;Username &amp;nbsp; &amp;nbsp; : bwpdmr &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Index &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: 29424&lt;BR /&gt;Assigned IP &amp;nbsp;: 192.168.x.x &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; Public IP &amp;nbsp; &amp;nbsp;: x.x.x.x&lt;BR /&gt;Protocol &amp;nbsp; &amp;nbsp; : IKE IPsecOverNatT&lt;BR /&gt;License &amp;nbsp; &amp;nbsp; &amp;nbsp;: IPsec&lt;BR /&gt;Encryption &amp;nbsp; : 3DES &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Hashing &amp;nbsp; &amp;nbsp; &amp;nbsp;: MD5 SHA1&lt;BR /&gt;Bytes Tx &amp;nbsp; &amp;nbsp; : 0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Bytes Rx &amp;nbsp; &amp;nbsp; : 0&lt;BR /&gt;Group Policy : DfltGrpPolicy &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Tunnel Group : test_tunnel&lt;BR /&gt;Login Time &amp;nbsp; : 14:18:59 UTC Mon Mar 10 2014&lt;BR /&gt;Duration &amp;nbsp; &amp;nbsp; : 0h:00m:22s&lt;BR /&gt;Inactivity &amp;nbsp; : 0h:00m:00s&lt;BR /&gt;NAC Result &amp;nbsp; : Unknown&lt;BR /&gt;VLAN Mapping : N/A &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;VLAN &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : none&lt;BR /&gt;&lt;BR /&gt;Username &amp;nbsp; &amp;nbsp; : muldmr &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Index &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: 29425&lt;BR /&gt;Assigned IP &amp;nbsp;: 192.168.172.207 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Public IP &amp;nbsp; &amp;nbsp;: 182.185.169.162&lt;BR /&gt;Protocol &amp;nbsp; &amp;nbsp; : IKE IPsecOverNatT&lt;BR /&gt;License &amp;nbsp; &amp;nbsp; &amp;nbsp;: IPsec&lt;BR /&gt;Encryption &amp;nbsp; : 3DES &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Hashing &amp;nbsp; &amp;nbsp; &amp;nbsp;: MD5 SHA1&lt;BR /&gt;Bytes Tx &amp;nbsp; &amp;nbsp; : 0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Bytes Rx &amp;nbsp; &amp;nbsp; : 641&lt;BR /&gt;Group Policy : DfltGrpPolicy &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Tunnel Group : test_tunnel&lt;BR /&gt;Login Time &amp;nbsp; : 14:19:00 UTC Mon Mar 10 2014&lt;BR /&gt;Duration &amp;nbsp; &amp;nbsp; : 0h:00m:21s&lt;BR /&gt;Inactivity &amp;nbsp; : 0h:00m:00s&lt;BR /&gt;NAC Result &amp;nbsp; : Unknown&lt;BR /&gt;VLAN Mapping : N/A &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;VLAN &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : none&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;ASA# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; show memory&lt;BR /&gt;Free memory: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;94703144 bytes (18%)&lt;BR /&gt;Used memory: &amp;nbsp; &amp;nbsp; &amp;nbsp; 442167768 bytes (82%)&lt;BR /&gt;------------- &amp;nbsp; &amp;nbsp; ----------------&lt;BR /&gt;Total memory: &amp;nbsp; &amp;nbsp; &amp;nbsp;536870912 bytes (100%)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me in this issue.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Farhan.&lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 13:09:47 GMT</pubDate>
    <dc:creator>Syed Farhan Ali</dc:creator>
    <dc:date>2019-03-10T13:09:47Z</dc:date>
    <item>
      <title>ASA Firewall VPN Client Error</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-vpn-client-error/m-p/2492907#M45685</link>
      <description>&lt;P&gt;Dear Techies,&lt;/P&gt;&lt;P&gt;Following messages are generating on ASA and when it starts generating our VPN client (remote users) failed to pass thourgh IKE phase and VPN client get a message "VPN CLIENT ERROR".&lt;BR /&gt;&lt;BR /&gt;We clear all vpn session and also reapply cryto map for remote vpns and also shutdown the outside interface but all in vain as nothing change and same error was generating. After rebooting the ASA problems get resolved which is not the permanent solution. Your help is required to find a solution to this issue. Attached are the logs which were generating on ASA related to this issue.&lt;BR /&gt;&lt;BR /&gt;2014-03-10 11:56:07 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:43 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = khiap, IP = 119.160.51.248, Can't create conn entry!&lt;BR /&gt;&lt;BR /&gt;2014-03-10 11:56:07 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:44 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = shwcrm, IP = 182.185.169.162, Can't create conn entry!&lt;BR /&gt;&lt;BR /&gt;2014-03-10 11:56:07 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:44 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = lhrap, IP = 182.185.239.172, Can't create conn entry!&lt;BR /&gt;2014-03-10 11:56:07 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:44 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = pshdmr, IP = 175.107.56.173, Can't create conn entry!&lt;BR /&gt;2014-03-10 11:56:07 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:44 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = islrm, IP = 115.186.137.197, Can't create conn entry!&lt;BR /&gt;&lt;BR /&gt;2014-03-10 11:56:08 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:44 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = inkot, IP = 182.186.112.233, Can't create conn entry!&lt;BR /&gt;2014-03-10 11:56:08 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:45 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = khiap, IP = 119.73.92.220, Can't create conn entry!&lt;BR /&gt;&lt;BR /&gt;2014-03-10 11:56:09 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:45 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = muldmr, IP = 182.185.169.162, Can't create conn entry!&lt;BR /&gt;2014-03-10 11:56:09 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:45 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = khiap, IP = 119.73.92.220, Can't create conn entry!&lt;BR /&gt;2014-03-10 11:56:09 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Critical &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:46 172.16.208.1 : %ASA-2-713901: Group = test_tunnel, Username = dikdmr, IP = 182.181.238.131, Can't create conn entry!&lt;BR /&gt;&lt;BR /&gt;2014-03-10 11:56:09 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Error &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 11:53:46 172.16.208.1 : %ASA-3-713203: IKE Receiver: Error reading from socket.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;2014-03-10 12:05:57 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Error &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 12:03:34 172.16.208.1 : %ASA-3-713232: IP = 182.181.238.131, SA lock refCnt = 1, bitmask = 00000002, p1_decrypt_cb = 0, qm_decrypt_cb = 0, qm_hash_cb = 0, qm_spi_ok_cb = 0, qm_dh_cb = 0, qm_secret_key_cb = 0, qm_encrypt_cb = 0&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;2014-03-10 12:06:03 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Debug &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 12:03:39 172.16.208.1 : %ASA-7-713052: Group = test_tunnel, Username = lhrcrm1, IP = 182.185.151.238, User (lhrcrm1) authenticated.&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;2014-03-10 12:06:03 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Debug &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 12:03:39 172.16.208.1 : %ASA-7-713052: Group = test_tunnel, Username = sukdmr, IP = 39.51.65.61, User (sukdmr) authenticated.&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;2014-03-10 12:06:03 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 12:03:40 172.16.208.1 : %ASA-4-713903: Group = test_tunnel, Username = lhrcrm1, IP = 182.185.151.238, ERROR: IKE failed trying to create a session manager entry&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;2014-03-10 12:06:03 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 12:03:40 172.16.208.1 : %ASA-4-713903: Group = test_tunnel, Username = sukdmr, IP = 39.51.65.61, ERROR: IKE failed trying to create a session manager entry&lt;/STRONG&gt;&lt;BR /&gt;&lt;BR /&gt;2014-03-10 14:18:47 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Error &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 14:16:24 172.16.208.1 : %ASA-3-713232: IP = 182.181.238.131, SA lock refCnt = 1, bitmask = 00000002, p1_decrypt_cb = 0, qm_decrypt_cb = 0, qm_hash_cb = 0, qm_spi_ok_cb = 0, qm_dh_cb = 0, qm_secret_key_cb = 0, qm_encrypt_cb = 0&lt;BR /&gt;2014-03-10 14:18:47 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Error &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 14:16:24 172.16.208.1 : %ASA-3-713232: IP = 182.186.27.230, SA lock refCnt = 1, bitmask = 00000002, p1_decrypt_cb = 0, qm_decrypt_cb = 0, qm_hash_cb = 0, qm_spi_ok_cb = 0, qm_dh_cb = 0, qm_secret_key_cb = 0, qm_encrypt_cb = 0&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;2014-03-10 18:53:07 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:50:44 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0xA81E0AFF, sequence number= 0x57D) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 172.16.192.116/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:53:16 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:50:54 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0xA81E0AFF, sequence number= 0x57E) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 172.16.192.116/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:53:18 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:50:56 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0x637D43E2, sequence number= 0x22C) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 10.10.9.2/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:53:26 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:04 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0xA81E0AFF, sequence number= 0x57F) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 172.16.192.116/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:53:28 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:06 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0x637D43E2, sequence number= 0x22D) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 10.10.9.2/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:53:36 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:14 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0xA81E0AFF, sequence number= 0x580) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 172.16.192.116/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:53:38 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:16 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0x637D43E2, sequence number= 0x22E) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 10.10.9.2/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:53:46 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:24 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0xA81E0AFF, sequence number= 0x581) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 172.16.192.116/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:53:56 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:34 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0xA81E0AFF, sequence number= 0x582) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 172.16.192.116/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:54:06 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:44 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0xA81E0AFF, sequence number= 0x583) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 172.16.192.116/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:54:08 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:46 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0x637D43E2, sequence number= 0x232) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 10.10.9.2/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;2014-03-10 18:54:16 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Local4.Warning &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Firewall &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Mar 10 2014 18:51:54 172.16.208.1 : %ASA-4-402116: IPSEC: Received an ESP packet (SPI= 0xA81E0AFF, sequence number= 0x584) from 202.47.94.1 (user= 202.47.94.1) to 125.209.115.240. &amp;nbsp;The decapsulated inner packet doesn't match the negotiated policy in the SA. &amp;nbsp;The packet specifies its destination as 125.209.115.240, its source as 202.47.94.1, and its protocol as 1. &amp;nbsp;The SA specifies its local proxy as 172.16.192.116/255.255.255.255/0/0 and its remote_proxy as 192.168.232.51/255.255.255.255/0/0.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;ASA# sh vpn-sessiondb remote&lt;BR /&gt;&lt;BR /&gt;Session Type: IPsec&lt;BR /&gt;&lt;BR /&gt;Username &amp;nbsp; &amp;nbsp; : bwpdmr &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Index &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: 29424&lt;BR /&gt;Assigned IP &amp;nbsp;: 192.168.x.x &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; Public IP &amp;nbsp; &amp;nbsp;: x.x.x.x&lt;BR /&gt;Protocol &amp;nbsp; &amp;nbsp; : IKE IPsecOverNatT&lt;BR /&gt;License &amp;nbsp; &amp;nbsp; &amp;nbsp;: IPsec&lt;BR /&gt;Encryption &amp;nbsp; : 3DES &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Hashing &amp;nbsp; &amp;nbsp; &amp;nbsp;: MD5 SHA1&lt;BR /&gt;Bytes Tx &amp;nbsp; &amp;nbsp; : 0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Bytes Rx &amp;nbsp; &amp;nbsp; : 0&lt;BR /&gt;Group Policy : DfltGrpPolicy &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Tunnel Group : test_tunnel&lt;BR /&gt;Login Time &amp;nbsp; : 14:18:59 UTC Mon Mar 10 2014&lt;BR /&gt;Duration &amp;nbsp; &amp;nbsp; : 0h:00m:22s&lt;BR /&gt;Inactivity &amp;nbsp; : 0h:00m:00s&lt;BR /&gt;NAC Result &amp;nbsp; : Unknown&lt;BR /&gt;VLAN Mapping : N/A &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;VLAN &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : none&lt;BR /&gt;&lt;BR /&gt;Username &amp;nbsp; &amp;nbsp; : muldmr &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Index &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;: 29425&lt;BR /&gt;Assigned IP &amp;nbsp;: 192.168.172.207 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Public IP &amp;nbsp; &amp;nbsp;: 182.185.169.162&lt;BR /&gt;Protocol &amp;nbsp; &amp;nbsp; : IKE IPsecOverNatT&lt;BR /&gt;License &amp;nbsp; &amp;nbsp; &amp;nbsp;: IPsec&lt;BR /&gt;Encryption &amp;nbsp; : 3DES &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Hashing &amp;nbsp; &amp;nbsp; &amp;nbsp;: MD5 SHA1&lt;BR /&gt;Bytes Tx &amp;nbsp; &amp;nbsp; : 0 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Bytes Rx &amp;nbsp; &amp;nbsp; : 641&lt;BR /&gt;Group Policy : DfltGrpPolicy &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Tunnel Group : test_tunnel&lt;BR /&gt;Login Time &amp;nbsp; : 14:19:00 UTC Mon Mar 10 2014&lt;BR /&gt;Duration &amp;nbsp; &amp;nbsp; : 0h:00m:21s&lt;BR /&gt;Inactivity &amp;nbsp; : 0h:00m:00s&lt;BR /&gt;NAC Result &amp;nbsp; : Unknown&lt;BR /&gt;VLAN Mapping : N/A &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;VLAN &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; : none&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;ASA# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; show memory&lt;BR /&gt;Free memory: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;94703144 bytes (18%)&lt;BR /&gt;Used memory: &amp;nbsp; &amp;nbsp; &amp;nbsp; 442167768 bytes (82%)&lt;BR /&gt;------------- &amp;nbsp; &amp;nbsp; ----------------&lt;BR /&gt;Total memory: &amp;nbsp; &amp;nbsp; &amp;nbsp;536870912 bytes (100%)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please help me in this issue.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Farhan.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 13:09:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-vpn-client-error/m-p/2492907#M45685</guid>
      <dc:creator>Syed Farhan Ali</dc:creator>
      <dc:date>2019-03-10T13:09:47Z</dc:date>
    </item>
    <item>
      <title>Can you post your config?</title>
      <link>https://community.cisco.com/t5/network-security/asa-firewall-vpn-client-error/m-p/2492908#M45689</link>
      <description>Can you post your config?</description>
      <pubDate>Thu, 13 Mar 2014 14:37:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-firewall-vpn-client-error/m-p/2492908#M45689</guid>
      <dc:creator>nigel doe</dc:creator>
      <dc:date>2014-03-13T14:37:02Z</dc:date>
    </item>
  </channel>
</rss>

