<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Missing crypto policy in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458319#M652008</link>
    <description>&lt;P&gt;Why would a crypto isakmp policy not be loaded from the startup-config into the running-config during a reload?&amp;nbsp; We had five policies, only four of which are in the running-config now.&amp;nbsp; No changes had been made after reload.&amp;nbsp; Thanx!&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 18:29:32 GMT</pubDate>
    <dc:creator>pootboy69</dc:creator>
    <dc:date>2019-03-11T18:29:32Z</dc:date>
    <item>
      <title>Missing crypto policy</title>
      <link>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458319#M652008</link>
      <description>&lt;P&gt;Why would a crypto isakmp policy not be loaded from the startup-config into the running-config during a reload?&amp;nbsp; We had five policies, only four of which are in the running-config now.&amp;nbsp; No changes had been made after reload.&amp;nbsp; Thanx!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 18:29:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458319#M652008</guid>
      <dc:creator>pootboy69</dc:creator>
      <dc:date>2019-03-11T18:29:32Z</dc:date>
    </item>
    <item>
      <title>Re: Missing crypto policy</title>
      <link>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458320#M652020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only reason why this would happen is if the startup-config has only 4 policies. Are you sure the configuration was saved to the startup-config prior to the reload?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Aug 2010 16:22:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458320#M652020</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-08-23T16:22:28Z</dc:date>
    </item>
    <item>
      <title>Re: Missing crypto policy</title>
      <link>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458321#M652032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did a backup, using the ASDM prior to making any changes.&amp;nbsp; The policy exists in the startup-config, but did not transfer to the running-config during the reload.&amp;nbsp; I do not understand how this could happen.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Aug 2010 16:24:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458321#M652032</guid>
      <dc:creator>pootboy69</dc:creator>
      <dc:date>2010-08-23T16:24:31Z</dc:date>
    </item>
    <item>
      <title>Re: Missing crypto policy</title>
      <link>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458322#M652036</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So when you do a "show start" you see the configured isakmp policy but not when you do a "show run"? If that's the case, can you do a "copy start run" and see if it copies now?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Aug 2010 16:53:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458322#M652036</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-08-23T16:53:05Z</dc:date>
    </item>
    <item>
      <title>Re: Missing crypto policy</title>
      <link>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458323#M652046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have to schedule this for off-hours.&amp;nbsp; I will simply manually enter the policy, after I've verified that's the only command that did not load.&amp;nbsp; I still don't see how the reload could have missed it.&amp;nbsp; Thanx so much for your assistance!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regerds,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wolf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Aug 2010 16:56:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458323#M652046</guid>
      <dc:creator>pootboy69</dc:creator>
      <dc:date>2010-08-23T16:56:33Z</dc:date>
    </item>
    <item>
      <title>Re: Missing crypto policy</title>
      <link>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458324#M652060</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;OK, so I tried entering the commands directly into the ASA:&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I did this with ASDM as well as through the command line.&amp;nbsp; It never showed up in the configuration when I did a "show running-config crypto isakmp". &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto isakmp policy 20 authentication pre-share&lt;/P&gt;&lt;P&gt;crypto isakmp policy 20 encryption 3des&lt;/P&gt;&lt;P&gt;crypto isakmp policy 20 hash md5&lt;/P&gt;&lt;P&gt;crypto isakmp policy 20 group 2&lt;/P&gt;&lt;P&gt;crypto isakmp policy 20 lifetime 86400&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's going on?&amp;nbsp; Thanx!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wolf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Aug 2010 18:10:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458324#M652060</guid>
      <dc:creator>pootboy69</dc:creator>
      <dc:date>2010-08-23T18:10:45Z</dc:date>
    </item>
    <item>
      <title>Re: Missing crypto policy</title>
      <link>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458325#M652071</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My apologies . . . I meant to reply to you, but wound up replying to myself.&amp;nbsp; Here's what I said:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OK, so I tried entering the commands directly into the ASA:&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;I did this with ASDM as well as through the command line.&amp;nbsp; It never showed up in the configuration when I did a "show running-config crypto isakmp".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto isakmp policy 20 authentication pre-share&lt;/P&gt;&lt;P&gt;crypto isakmp policy 20 encryption 3des&lt;/P&gt;&lt;P&gt;crypto isakmp policy 20 hash md5&lt;/P&gt;&lt;P&gt;crypto isakmp policy 20 group 2&lt;/P&gt;&lt;P&gt;crypto isakmp policy 20 lifetime 86400&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What's going on?&amp;nbsp; Thanx!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wolf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 24 Aug 2010 18:15:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458325#M652071</guid>
      <dc:creator>pootboy69</dc:creator>
      <dc:date>2010-08-24T18:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: Missing crypto policy</title>
      <link>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458326#M652080</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you send the output of "show run all crypto isakmp" and if possible a session log of when you are tryong to add this new policy? What are the other isakmp policies that you have configured? What version is your ASA running?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Aug 2010 00:33:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458326#M652080</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-08-25T00:33:23Z</dc:date>
    </item>
    <item>
      <title>Re: Missing crypto policy</title>
      <link>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458327#M652085</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Prapanch,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, again, for your respponse.&amp;nbsp; While, as a CCNA for almost ten years, I have had much experience with all manner of Cisco hardware and software, the ASA continues to challenge me, even though I have attended the first classrom course offered on the device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are running v8.2(2) at all locations.&amp;nbsp; I have added this policy to our backup ASA with no problem.&amp;nbsp; As the primary ASA is critical and a reload has to be scheduled well in advance, I cannot simply do that on a whim to test the integrity of the startup-configuration, even though I have verified that isakmp policy 20 exists there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is the file with the information you requested.&amp;nbsp; Note that the commands appear to have been accepted during input, but mysteriously disappear when a "sh run all crypto isakmp" command is issued.&amp;nbsp; Thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wolf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Aug 2010 13:07:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458327#M652085</guid>
      <dc:creator>pootboy69</dc:creator>
      <dc:date>2010-08-25T13:07:34Z</dc:date>
    </item>
    <item>
      <title>Re: Missing crypto policy</title>
      <link>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458328#M652090</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems to be a perfect match of the bug CSCtd61244. You might want to consider an upgrade to a recent release.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Prapanch&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Aug 2010 15:42:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458328#M652090</guid>
      <dc:creator>praprama</dc:creator>
      <dc:date>2010-08-25T15:42:00Z</dc:date>
    </item>
    <item>
      <title>Re: Missing crypto policy</title>
      <link>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458329#M652095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you, Prapanch!&amp;nbsp; I will read the upgrade document and look into upgrading so as not to impact out current NAT configuration.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Wolf&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 25 Aug 2010 15:51:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/missing-crypto-policy/m-p/1458329#M652095</guid>
      <dc:creator>pootboy69</dc:creator>
      <dc:date>2010-08-25T15:51:54Z</dc:date>
    </item>
  </channel>
</rss>

