<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Reason 433 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/reason-433/m-p/1290104#M816405</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most of the times we see this error message when client is unable to get an ip address from the firewall/DHCP/external AAA server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check if you have address-pool defined under the tunnel-group or group-policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to define address-pool, please visit the below listed doc:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/vpnadd.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/vpnadd.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the above suggestion doesn't work for you. Please provide us with current configuration, and following debugs,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug crypto isa 127&lt;/P&gt;&lt;P&gt;debug crypto ipsec 127&lt;/P&gt;&lt;P&gt;debug aaa authentication&lt;/P&gt;&lt;P&gt;debug aaa common 127&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz rate the helpful posts-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Oct 2009 13:13:26 GMT</pubDate>
    <dc:creator>Jatin Katyal</dc:creator>
    <dc:date>2009-10-23T13:13:26Z</dc:date>
    <item>
      <title>Reason 433</title>
      <link>https://community.cisco.com/t5/network-security/reason-433/m-p/1290103#M816401</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a problem about VPN connection on FW. The VPN client receives a message that sais: " Secure VPN Connection terminated by peer Reason 433: (reason not specified by peer)".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could anyone help me?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 16:30:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reason-433/m-p/1290103#M816401</guid>
      <dc:creator>gpangallo</dc:creator>
      <dc:date>2019-03-11T16:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: Reason 433</title>
      <link>https://community.cisco.com/t5/network-security/reason-433/m-p/1290104#M816405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most of the times we see this error message when client is unable to get an ip address from the firewall/DHCP/external AAA server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please check if you have address-pool defined under the tunnel-group or group-policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to define address-pool, please visit the below listed doc:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/vpnadd.html" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa70/configuration/guide/vpnadd.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the above suggestion doesn't work for you. Please provide us with current configuration, and following debugs,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;debug crypto isa 127&lt;/P&gt;&lt;P&gt;debug crypto ipsec 127&lt;/P&gt;&lt;P&gt;debug aaa authentication&lt;/P&gt;&lt;P&gt;debug aaa common 127&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;JK&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plz rate the helpful posts-&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Oct 2009 13:13:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reason-433/m-p/1290104#M816405</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2009-10-23T13:13:26Z</dc:date>
    </item>
    <item>
      <title>Re: Reason 433</title>
      <link>https://community.cisco.com/t5/network-security/reason-433/m-p/1290105#M816412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi JK,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you for your answer. I have another doubt because viewing the FW configuration I noticed that there isn't configured the vpn-addr-assign command but the vpn group is defined in "tunnel-group mygroup general-attributes" and moreover there is also the authentication toward the Radius server with the command "authentication-server-group myradius" .&lt;/P&gt;&lt;P&gt;Maybe could it be this misconfiguration?&lt;/P&gt;&lt;P&gt;It could be the user credentials corruption on Radius Server,isn't it? &lt;/P&gt;&lt;P&gt;Let me know, please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Oct 2009 11:25:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reason-433/m-p/1290105#M816412</guid>
      <dc:creator>gpangallo</dc:creator>
      <dc:date>2009-10-26T11:25:09Z</dc:date>
    </item>
    <item>
      <title>Reason 433</title>
      <link>https://community.cisco.com/t5/network-security/reason-433/m-p/1290106#M816421</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my particular case it was all my users were getting error 433. It turned out to be the AAA authentication server settings on the firewall. I was authenticating against a Microsoft LDAP server. I think the Logon DN path had some characters Cisco couldn't comprehend. Here is how I fixed it.&lt;/P&gt;&lt;P&gt;&lt;A href="http://supertekboy.com/2014/01/23/cisco-vpn-reason-433-reason-not-specified-by-peer/"&gt;http://supertekboy.com/2014/01/23/cisco-vpn-reason-433-reason-not-specified-by-peer/&lt;/A&gt; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Jan 2014 14:42:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/reason-433/m-p/1290106#M816421</guid>
      <dc:creator>Gareth Gudger</dc:creator>
      <dc:date>2014-01-23T14:42:55Z</dc:date>
    </item>
  </channel>
</rss>

