<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA VPN Tunnel Phase 8 Subtype encrypt : DROP in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-vpn-tunnel-phase-8-subtype-encrypt-drop/m-p/3997079#M4970</link>
    <description>&lt;P&gt;yes, lovely&lt;/P&gt;</description>
    <pubDate>Wed, 11 Dec 2019 10:09:41 GMT</pubDate>
    <dc:creator>Chewbakka1</dc:creator>
    <dc:date>2019-12-11T10:09:41Z</dc:date>
    <item>
      <title>ASA VPN Tunnel Phase 8 Subtype encrypt : DROP</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-tunnel-phase-8-subtype-encrypt-drop/m-p/3995964#M4965</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have set up a new VPN tunnel to a remote site, but the tunnel will not come up.&lt;/P&gt;&lt;P&gt;Running packet-tracer shows that the tunnel is failing with:&lt;/P&gt;&lt;P&gt;Phase: 8&lt;BR /&gt;Type: VPN&lt;BR /&gt;Subtype: encrypt&lt;BR /&gt;Result: DROP&lt;BR /&gt;Config:&lt;BR /&gt;Additional Information:&lt;/P&gt;&lt;P&gt;Result:&lt;BR /&gt;input-interface: inside&lt;BR /&gt;input-status: up&lt;BR /&gt;input-line-status: up&lt;BR /&gt;output-interface: outside&lt;BR /&gt;output-status: up&lt;BR /&gt;output-line-status: up&lt;BR /&gt;Action: drop&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have checked that the access-lists(encryption domain) matches.&lt;/P&gt;&lt;P&gt;I have checked that the return traffic matches the same nat rule as for outgoing traffic.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas what could be the cause for this?&lt;/P&gt;&lt;P&gt;I suspect this could be that the firewall does not have the source network directly connected, and that is why packet tracer cannot source the traffic correctly.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:45:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-tunnel-phase-8-subtype-encrypt-drop/m-p/3995964#M4965</guid>
      <dc:creator>Chewbakka1</dc:creator>
      <dc:date>2020-02-21T17:45:16Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN Tunnel Phase 8 Subtype encrypt : DROP</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-tunnel-phase-8-subtype-encrypt-drop/m-p/3996102#M4966</link>
      <description>&lt;P&gt;When the source subnet,subject to encryption is not directly connected, is it necessary to include the directly connected subnet in the access-list as well?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2019 22:36:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-tunnel-phase-8-subtype-encrypt-drop/m-p/3996102#M4966</guid>
      <dc:creator>Chewbakka1</dc:creator>
      <dc:date>2019-12-09T22:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN Tunnel Phase 8 Subtype encrypt : DROP</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-tunnel-phase-8-subtype-encrypt-drop/m-p/3996107#M4967</link>
      <description>&lt;P&gt;show your configuration otherwise its really hard to say what causing the issue.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2019 22:42:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-tunnel-phase-8-subtype-encrypt-drop/m-p/3996107#M4967</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2019-12-09T22:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN Tunnel Phase 8 Subtype encrypt : DROP</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-tunnel-phase-8-subtype-encrypt-drop/m-p/3996604#M4968</link>
      <description>&lt;P&gt;Digging further into the logs i found this:&lt;/P&gt;&lt;P&gt;Local:0.0.0.0:0 Remote:0.0.0.0:0 Username:Unknown IKEv2 SA request rejected by CAC. Reason: IN-NEGOTIATION SA LIMIT REACHED&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Dec 2019 16:05:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-tunnel-phase-8-subtype-encrypt-drop/m-p/3996604#M4968</guid>
      <dc:creator>Chewbakka1</dc:creator>
      <dc:date>2019-12-10T16:05:29Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN Tunnel Phase 8 Subtype encrypt : DROP</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-tunnel-phase-8-subtype-encrypt-drop/m-p/3996676#M4969</link>
      <description>&lt;P&gt;You may have found this already, but it seems like you're hitting this bug:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class="bugTitle"&gt;ASA IKEv2:L2L tunnel failing with IN-NEGOTIATION SA LIMIT REACHED&lt;/DIV&gt;&lt;DIV class="bugId"&gt;CSCug95008&lt;/DIV&gt;&lt;DIV class="bugId"&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class="bugId"&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCug95008" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCug95008&lt;/A&gt;&lt;/DIV&gt;</description>
      <pubDate>Tue, 10 Dec 2019 17:25:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-tunnel-phase-8-subtype-encrypt-drop/m-p/3996676#M4969</guid>
      <dc:creator>gerald.scott</dc:creator>
      <dc:date>2019-12-10T17:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASA VPN Tunnel Phase 8 Subtype encrypt : DROP</title>
      <link>https://community.cisco.com/t5/network-security/asa-vpn-tunnel-phase-8-subtype-encrypt-drop/m-p/3997079#M4970</link>
      <description>&lt;P&gt;yes, lovely&lt;/P&gt;</description>
      <pubDate>Wed, 11 Dec 2019 10:09:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-vpn-tunnel-phase-8-subtype-encrypt-drop/m-p/3997079#M4970</guid>
      <dc:creator>Chewbakka1</dc:creator>
      <dc:date>2019-12-11T10:09:41Z</dc:date>
    </item>
  </channel>
</rss>

